AgentTesla»ùÓÚÎÞÎļþ .NET µÄ´úÂë×¢Èë¾ÙÐÐÈö²¥

Ðû²¼Ê±¼ä 2024-04-30
1. AgentTesla»ùÓÚÎÞÎļþ .NET µÄ´úÂë×¢Èë¾ÙÐÐÈö²¥


4ÔÂ29ÈÕ £¬£¬£¬£¬ £¬£¬×î½üµÄ¶ñÒâÈí¼þ»î¶¯Ê¹Óà Word ÎĵµÖÐµÄ VBA ºêÀ´ÏÂÔØ²¢Ö´ÐÐ 64 λ Rust ¶þ½øÖÆÎļþ¡£¡£ ¡£¡£¸Ã¶þ½øÖÆÎļþ½ÓÄÉÎÞÎļþ×¢ÈëÊÖÒÕ½«¶ñÒâ AgentTesla ÓÐÓøºÔؼÓÔØµ½ÆäÄÚ´æ¿Õ¼äÖС£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þʹÓà CLR Íйܣ¨Ò»ÖÖ±¾»úÀú³ÌÖ´ÐÐ .NET ´úÂëµÄ»úÖÆ£©À´ÊµÏÖ´ËÄ¿µÄ £¬£¬£¬£¬ £¬£¬²¢ÇÒ¶¯Ì¬¼ÓÔØ .NET ÔËÐÐʱ¿â £¬£¬£¬£¬ £¬£¬´Ó¶øÔÊÐí¶ñÒâÈí¼þÔÚ²»½«ÎļþдÈë¹âÅ̵ÄÇéÐÎϾÙÐвÙ×÷¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÐÞ²¹¡°EtwEventWrite¡±API À´½ûÓà Windows ÊÂÎñ¸ú×Ù (ETW) £¬£¬£¬£¬ £¬£¬È»ºó´ÓÌØ¶¨ URL ÏÂÔØ°üÀ¨ AgenetTesla ÓÐÓøºÔØµÄ shellcode¡£¡£ ¡£¡£È»ºóʹÓá°EnumSystemLocalesA¡±API Ö´ÐÐ shellcode¡£¡£ ¡£¡£ 


https://gbhackers.com/clr-hosting-used-by-agenttesla/


2. Õë¶Ô USPS µÄÍøÂç´¹ÂڻÓë USPS ×Ô¼ºÒ»Ñù¶à


4ÔÂ26ÈÕ £¬£¬£¬£¬ £¬£¬Akamai Ñо¿Ö°Ô±·¢Ã÷ÁË´ó×Ú¼«ÓпÉÄܵĶñÒâ»î¶¯ºÍÉù³ÆÓëÃÀ¹úÓÊÕþЧÀÍ (USPS) Ïà¹ØµÄÓòÃû¡£¡£ ¡£¡£Akamai Ñо¿Ö°Ô±½«Îå¸öÔµÄÕýµ±ÓòÃû usps[.]com µÄ DNS Á÷Á¿Óë²»·¨×éºÏÇÀ×¢ÓòÃûµÄ DNS Á÷Á¿¾ÙÐÐÁ˽ÏÁ¿¡£¡£ ¡£¡£¶ñÒâÓòÓë usps[.]com µÄ×ÜÅÌÎʼÆÊýÏÕЩÏàͬ £¬£¬£¬£¬ £¬£¬×ÝÈ»½öÅÌËã°üÀ¨Ã÷È· USPS Ëõд´ÊµÄÓòÒ²ÊÇÔÆÔÆ¡£¡£ ¡£¡£Ö»¹ÜÔÚ´ËÆÊÎöÖÐ £¬£¬£¬£¬ £¬£¬USPS Ó®µÃÁËÕâ 5 ¸öÔÂʱ´ú×ÜÅÌÎÊÁ¿µÄ 51% £¬£¬£¬£¬ £¬£¬µ«ÎÒÃǹýÂËÊý¾ÝµÄ·½·¨Åú×¢ £¬£¬£¬£¬ £¬£¬¶ñÒâÁ÷Á¿ÏÔ×ÅÁè¼ÝÁËÏÖʵÌìÏÂÖеÄÕýµ±Á÷Á¿¡£¡£ ¡£¡£ÎÒÃÇ¿´µ½¶ñÒâÐÐΪÕß½ÓÄÉÁËÁ½ÖÖ²î±ðµÄÒªÁ죺ËûÃÇҪô½«Á÷Á¿ÊèÉ¢µ½Ðí¶à²î±ðµÄÓòÃû £¬£¬£¬£¬ £¬£¬ÒªÃ´½öʹÓü¸¸öÓò £¬£¬£¬£¬ £¬£¬Ã¿¸öÓò¶¼Óдó×ÚÁ÷Á¿¡£¡£ ¡£¡£Õâ¿ÉÄÜÊdzöÓÚ»ìÏýÄ¿µÄ£ºÔËÓªÉÌºÍÆäËûÍйÜÌṩÉÌÒâʶµ½ÕâЩթƭµÄÆÕ±é±£´æ £¬£¬£¬£¬ £¬£¬²¢ÕýÔÚСÐĵØÊµÑéʶ±ðºÍɾ³ýÕâÐ©Ò³Ãæ¡£¡£ ¡£¡£¿£¿£¿£¿£¿£¿ £Ë¼Á¿µ½Ïû³ýÕâЩȦÌ׵ĹØ×¢Ë®Æ½ £¬£¬£¬£¬ £¬£¬ËûÃǵÄЧ¹ûºÍ¼øºÚµ£±£ÍøÊÓ²ì¸üÁîÈ˵£ÐÄ¡£¡£ ¡£¡£


https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic


3. ¹È¸èä¯ÀÀÆ÷µÄкóÁ¿×Ó¼ÓÃÜÊÖÒÕ¿ÉÄÜ»áÆÆËð TLS ÅþÁ¬


4ÔÂ28ÈÕ £¬£¬£¬£¬ £¬£¬Ò»Ð© Google Chrome Óû§±¨¸æÔÚ Chrome 124 ÉÏÖÜÐû²¼ºó £¬£¬£¬£¬ £¬£¬ÔÚĬÈÏÆôÓÃеĿ¹Á¿×Ó X25519Kyber768 ·â×°»úÖÆµÄÇéÐÎÏ £¬£¬£¬£¬ £¬£¬ÅþÁ¬µ½ÍøÕ¾¡¢Ð§ÀÍÆ÷ºÍ·À»ðǽʱ·ºÆðÎÊÌâ¡£¡£ ¡£¡£¹È¸èÒѲâÊÔÁ¿×ÓÇå¾² TLS ÃÜÔ¿·â×°»úÖÆ £¬£¬£¬£¬ £¬£¬ÏÖÒÑÔÚ×îÐ嵀 Chrome °æ±¾ÖÐΪËùÓÐÓû§ÆôÓᣡ£ ¡£¡£Ð°汾ʹÓÃÓÃÓÚ TLS 1.3 ºÍ QUIC ÅþÁ¬µÄ Kyber768 ¿¹Á¿×ÓÃÜԿЭÉÌËã·¨À´±£»£»£»£»£»£»¤ Chrome TLS Á÷Á¿ÃâÊÜÁ¿×ÓÃÜÂëÆÊÎö¡£¡£ ¡£¡£ÕâЩ¹ýʧ²»ÊÇÓÉ Google Chrome ÖеĹýʧÒýÆðµÄ £¬£¬£¬£¬ £¬£¬¶øÊÇÓÉ Web ЧÀÍÆ÷δÄÜ׼ȷʵÏÖ´«Êä²ãÇå¾²ÐÔ (TLS) ÒÔ¼°ÎÞ·¨´¦Öóͷ£ÓÃÓÚºóÁ¿×Ó¼ÓÃܵĽϴó ClientHello ÐÂÎÅÒýÆðµÄ¡£¡£ ¡£¡£ÈôÊDz»Ö§³Ö X25519Kyber768 £¬£¬£¬£¬ £¬£¬Õâ»áµ¼ÖÂËûÃǾܾøÊ¹Óà Kyber768 ¿¹Á¿×ÓÃÜԿЭÉÌËã·¨µÄÅþÁ¬ £¬£¬£¬£¬ £¬£¬¶ø²»ÊÇÇл»µ½¾­µä¼ÓÃÜ¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/google-chromes-new-post-quantum-cryptography-may-break-tls-connections/


4. Kotak Mahindra ÒøÐб»Õ¥È¡Ó¦ÓóÌÐò×¢²áпͻ§


4ÔÂ28ÈÕ £¬£¬£¬£¬ £¬£¬Ó¡¶È´¢±¸ÒøÐÐÒÑʵÑé¶Ô Kotak Mahindra ÒøÐеĽûÁî £¬£¬£¬£¬ £¬£¬Õ¥È¡Í¨¹ýÔÚÏßЧÀͺÍÓ¦ÓóÌÐò×¢²áпͻ§¡£¡£ ¡£¡£¸Ã²½·¥ÊÇÔÚITϵͳÖÎÀíÖз¢Ã÷ÖØ´óȱÏݺó½ÓÄÉµÄ £¬£¬£¬£¬ £¬£¬ÕâЩȱÏݰüÀ¨IT×ʲúÖÎÀí¡¢¸üкͱ任¡¢Óû§»á¼û¡¢¹©Ó¦ÉÌÏà¹ØÎ£º¦¡¢Êý¾ÝÇå¾²¡¢Êý¾Ýй¶Ԥ·ÀÕ½ÂÔºÍÔÖÄѻָ´Õ½ÂÔ¡£¡£ ¡£¡£Kotak Mahindra Bank ΪÁè¼Ý 4100 Íò¿Í»§ÌṩЧÀÍ £¬£¬£¬£¬ £¬£¬ÖÎÀí×ÅÁè¼Ý 5000 ÒÚÃÀÔªµÄ×ʲú £¬£¬£¬£¬ £¬£¬¸ÃÒøÐÐÔÚ 2022/2023 ²ÆÄêÄê¶È±¨¸æÖÐÌåÏÖ £¬£¬£¬£¬ £¬£¬¸ÃÒøÐÐÒ»Ö±ÖÂÁ¦ÓÚÔöÇ¿Çå¾²²½·¥¡£¡£ ¡£¡£È»¶ø £¬£¬£¬£¬ £¬£¬ÑëÐÐÒÔΪÕâЩÆð¾¢²»·ó¡£¡£ ¡£¡£ÀúʱÁ½ÄêµÄ¼ì²éÏÔʾ £¬£¬£¬£¬ £¬£¬¸ÃÐÐδÄܳä·Ö½â¾öITΣº¦ºÍÐÅÏ¢Çå¾²ÖÎÀíÎÊÌâ¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬¸ÃÒøÐл¹ÂÄÀúÁËÓ°Ïì¿Í»§µÄÊÖÒÕ¹ÊÕÏ £¬£¬£¬£¬ £¬£¬Òý·¢ÁËÈËÃÇ¶ÔÆä¼á³ÖÔËÓªµ¯ÐÔÓëÆäÔöÌíÂʼá³ÖÒ»ÖµÄÄÜÁ¦µÄµ£ÐÄ¡£¡£ ¡£¡£


https://meterpreter.org/rbi-cracks-down-on-kotak-mahindra-online-banking-halt/


5. ºÚ¿ÍÉù³ÆÒÑÉøÍ¸°×¶íÂÞ˹µÄÖ÷ÒªÇå¾²²¿·Ö


4ÔÂ28ÈÕ £¬£¬£¬£¬ £¬£¬°×¶íÂÞ˹ºÚ¿Í×éÖ¯Éù³ÆÒÑÉøÍ¸µ½¸Ã¹úÖ÷Òª¿Ë¸ñ²ªÇå¾²»ú¹¹µÄÍøÂç £¬£¬£¬£¬ £¬£¬²¢»á¼ûÁ˸Ã×éÖ¯ 8600 ¶àÃûÔ±¹¤µÄÈËʵµ°¸ £¬£¬£¬£¬ £¬£¬¸Ã×éÖ¯ÈÔÒÔÆäËÕÁªÃû³ÆÃüÃû¡£¡£ ¡£¡£ÎªÁËÖ§³ÖÆä˵·¨ £¬£¬£¬£¬ £¬£¬°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓÔÚÐÂÎÅÓ¦ÓóÌÐò Telegram µÄÒ³ÃæÉÏÐû²¼Á˸ÃÍøÕ¾ÖÎÀíÔ±¡¢Êý¾Ý¿âºÍЧÀÍÆ÷ÈÕÖ¾µÄÁÐ±í¡£¡£ ¡£¡£ÍøÂçÓλ÷¶ÓÔÚÒÑÍùËÄÄêÖж԰׶íÂÞ˹¹Ù·½Ã½Ìå¾ÙÐÐÁËÊý´Î´ó¹æÄ£¹¥»÷ £¬£¬£¬£¬ £¬£¬²¢ÔÚ 2022 Äê¶Ô°×¶íÂÞ˹Ìú·¾ÙÐÐÁË 3 ´ÎºÚ¿Í¹¥»÷ £¬£¬£¬£¬ £¬£¬Ð®ÖÆÁ˽»Í¨µÆºÍ¿ØÖÆÏµÍ³µÄ¿ØÖÆÈ¨¡£¡£ ¡£¡£


https://www.securityweek.com/hackers-claim-to-have-infiltrated-belarus-main-security-service/


6. ץȡDiscordµÄ6.2ÒÚÌõÐÅÏ¢µÄSpy.petÒѹرÕ


4ÔÂ29ÈÕ £¬£¬£¬£¬ £¬£¬¸ÃÍøÕ¾×ÔÈ¥Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚÇÔÈ¡ Discord Óû§µÄ¹«¹²Êý¾Ý £¬£¬£¬£¬ £¬£¬²¢ÓÚÉÏÖܱ»·¢Ã÷¸Ãƽ̨°üÀ¨À´×Ô 14000 ¶ą̀ Discord ЧÀÍÆ÷µÄ½ü 6.2 ÒÚÓû§µÄÐÂÎÅºó±»ÆØ¹â¡£¡£ ¡£¡£µ± Spy.pet ±»·¢Ã÷ʱ £¬£¬£¬£¬ £¬£¬Discord ÕýÔÚÆð¾¢¶ÔÈκÎÎ¥·´ÆäЧÀÍÌõ¿îµÄÈ˽ÓÄÉÐж¯ £¬£¬£¬£¬ £¬£¬µ«ÎÞ·¨Í¸Â¶¸ü¶àÐÅÏ¢¡£¡£ ¡£¡£DiscordÒѾ­½ûÓÃÓëSpy.pet ÍøÕ¾ÓйصÄÕÊ»§¡£¡£ ¡£¡£Spy.pet Éù³Æ¿ÉÒÔ»á¼ûµÄ Discord ЧÀÍÆ÷ÊýÄ¿ÉÏÖÜ×îÏÈϽµ £¬£¬£¬£¬ £¬£¬ÉÏÖÜËĽµÖÁÁã¡£¡£ ¡£¡£µ½ÖÜÎå £¬£¬£¬£¬ £¬£¬Spy.pet ÍøÕ¾×Ô¼ºÒѾ­×èÖ¹ÔËÓª¡ª¡ªÖ»¹ÜÉв»ÇåÎú¸ÃÍøÕ¾ÊÇ·ñÓÉÓÚ Discord µÄÐÐΪ¶øÀëÏß¡£¡£ ¡£¡£


https://www.theregister.com/2024/04/29/infosec_in_brief/