MikroTik¹ûÕæDDoS½©Ê¬ÍøÂ磺Unit 42Ðû²¼ÒÔÂÃÓÎÖ÷ÌâµÄ´¹ÂÚÔ˶¯
Ðû²¼Ê±¼ä 2021-09-18Anonymous³ÆÒÑÇÔÈ¡ÍйÜÔËÓªÉÌEpik½üÊ®ÄêµÄÊý¾Ý

AnonymousÔÚ9ÔÂ15ÈÕÉù³ÆÒÑÇÔÈ¡ÍйÜÔËÓªÉÌEpik½üÊ®ÄêµÄÊý¾Ý£¬²¢ÔÚDDoSecretsÉϹûÕæ¡£EpikµÄ¿Í»§°üÀ¨Parler¡¢Gab¡¢The DonaldºÍprolifewhistleblower.comµÈ¡£´Ë´Î¹¥»÷ÊÇEPIKFAILÐж¯µÄÒ»²¿·Ö£¬×ܼÆÇÔÈ¡ÁËÔ¼180GBµÄÊý¾Ý£¬°üÀ¨ÕË»§Æ¾Ö¤¡¢WHOISÀúÊ·¡¢DNS¸ü¸Ä¡¢Git´æ´¢¿âºÍ½¹µãϵͳµÄ/home/ºÍ/root/Ŀ¼µÈ¡£±ðµÄ£¬¸ÃÍÅ»ïÔøÔÚÉÏÖÜÈëÇÖÁËGOP£¨µÂ¿ËÈøË¹¹²ºÍµ³£©µÄ¹Ù·½ÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/anonymous-steals-far-right-web-host-epik-data/
ÃÀ¹úDesert WellsÒ½ÔºEHRϵͳÔâµ½¹¥»÷ÇÒÊý¾Ýɥʧ

ÃÀ¹úÑÇÀûÉ£ÄÇÖݵÄÒ½ÔºDesert Wells Family Medicine³ÆÆäµç×Ó¿µ½¡¼Í¼(EHR)ϵͳÔâµ½¹¥»÷¡£¹¥»÷±¬·¢ÔÚ5ÔÂ21ÈÕ£¬×ÝÈ»¸ÃÒ½ÔºÔÚ¹¥»÷±¬·¢Ç°±¸·ÝÁËEHRÖеÄËùÓÐÊý¾Ý£¬µ«¹¥»÷Õß¶ÔÁ½¸öϵͳÖеÄÊý¾Ý¾ù¾ÙÐÐÁ˼ÓÃÜ£¬Ê¹µÃϵͳÖеÄËùÓÐEHRÐÅÏ¢¶¼ÒÑÓÀÊÀɥʧ¡£Desert WellsÌåÏÖÒѾ¡ÆäËùÄָܻ´Êý¾Ýµ«Ã»ÓÐÈκÎ×÷Óã¬ËûÃÇÕýÔÚ¹¹½¨È«ÐµÄEHRϵͳ¡£±ðµÄ£¬ÆäÒÑ֪ͨ35000¸ö»¼ÕßËûÃǵĿµ½¡ÐÅÏ¢¿ÉÄÜÒѾй¶¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/arizona-medical-practice-loses-ehr/
MikroTik¹ûÕæDDoS½©Ê¬ÍøÂçM¨¥risÔ˶¯µÄÏêϸÐÅÏ¢

ÀÍÑάÑÇÍøÂç×°±¸ÖÆÔìÉÌMikroTikÔÚ9ÔÂ15ÈÕ¹ûÕæÁËM¨¥ris¹¥»÷Ô˶¯µÄÐÅÏ¢¡£MicroTik½²»°È˳ƣ¬´Ë´Î¹¥»÷ʹÓõÄ·ÓÉÆ÷Óë2018Äê±»ÈëÇֵķÓÉÆ÷Ïàͬ£¬ÆäʱMikroTik RouterOSÖб£´æÒ»¸öÎó²î£¬µ«¸ÃÎó²îºÜ¿ì¾Í±»ÐÞ¸´ÁË¡£²»¹ý½öÐÞ¸´Îó²î²¢²»¿É±£»¤Â·ÓÉÆ÷£¬ÓÉÓÚ¹¥»÷ÕßÔÚ2018Äê¾Í»ñµÃÁËÓû§µÄƾ֤¡£MicroTik½¨ÒéÓû§°´ÆÚÉý¼¶×°±¸£¬ÒÔ¼°Ê¹ÓÃÇ¿ÃÜÂë²¢°´ÆÚÌæ»»µÈ²½·¥¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mikrotik-shares-info-on-securing-routers-hit-by-massive-m-ris-botnet/
Çå¾²¹«Ë¾BitdefenderÐû²¼ÀÕË÷Èí¼þREvilÖ÷½âÃÜÆ÷

Çå¾²¹«Ë¾BitdefenderÐû²¼ÁËÕë¶ÔÀÕË÷Èí¼þREvilÖ÷½âÃÜÆ÷¡£Bitdefender³Æ¸Ã½âÃÜÆ÷ÊÇÓÉÆäºÍijִ·¨²¿·ÖÏàÖú¿ª·¢µÄ£¬ÊÊÓÃÓÚ7ÔÂ13ÈÕ֮ǰÔâµ½REvil¹¥»÷µÄËùÓÐÊܺ¦Õß¡£BleepingComputerÑо¿Ö°Ô±Ê¹ÓýñÄêÔçЩʱ¼äµÄREvilÑù±¾¶ÔÆä¾ÙÐÐÑéÖ¤£¬È·¶¨Ã»ÓÐÎÊÌâ¡£7Ô·Ýʱ£¬KaseyaÒ²Ôø»ñµÃÁËREvil½âÃÜÆ÷£¬µ«¸Ã¹¤¾ßÖ»ÊÊÓÃÓÚÕë¶ÔKaseyaµÄ¹¥»÷Ô˶¯µÄÊܺ¦Õß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/free-revil-ransomware-master-decrypter-released-for-past-victims/
΢ÈíÅû¶½üÆÚʹÓÃMSHTMLÎó²îµÄ´¹ÂÚ¹¥»÷Ô˶¯

΢ÈíÔÚ9ÔÂ15Èճƣ¬ÆäÍþвÇ鱨ÖÐÐÄÔÚ8Ô·ݷ¢Ã÷ÁËÉÙÁ¿Í¨¹ýÌØÖÆMicrosoftOfficeÎĵµÊ¹ÓÃMSHTMLÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40444£©µÄÔ˶¯¡£´Ë´ÎÔ˶¯Ê¹ÓÃÁ˽»¸¶»úÖÆ£¬Í¨¹ýÍйÜÔÚÎļþ¹²ÏíÕ¾µãÉϵÄÌõÔ¼ºÍÖ´·¨ÐÒ飬ÓÕʹĿµÄÏÂÔØCabinet¹éµµÎļþ£¬Æä°üÀ¨Ò»¸öÀ©Õ¹ÃûΪINFµÄDLL£¬¸ÃDLL½«¼ìË÷²¢ÏÂÔØÔ¶³ÌÍйܵÄshellcode¡£Î¢Èí½«´Ë´ÎÔ˶¯¹éÒòÓÚºÚ¿Í×éÖ¯DEV-0413ºÍDEV-0365¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/09/windows-mshtml-0-day-exploited-to.html
Unit 42Ðû²¼ÒÔÂÃÓÎΪÖ÷ÌâµÄ´¹ÂÚÔ˶¯µÄÆÊÎö±¨¸æ

Unit 42ÓÚ9ÔÂ15ÈÕÐû²¼ÁËÒÔÂÃÓÎΪÖ÷ÌâµÄ´¹ÂÚÔ˶¯µÄÆÊÎö±¨¸æ¡£Ñо¿Ö°Ô±ÆÊÎöÁË2019Äê10ÔÂÖÁ2021Äê8Ô½¨ÉèµÄÒÔÂÃÓÎΪÖ÷ÌâµÄ´¹ÂÚURL£¬·¢Ã÷ÊýÄ¿³ÊÖð½¥ÉÏÉýµÄÇ÷ÊÆ£¬²¢ÔÚ2021Äê6Ô·ºÆðÏÔÖøÔöÌí¡£±¨¸æÌṩÁËDridexÔÚ2021ÄêʹÓõĴøÓС°º½¿Õ¹«Ë¾¡±ºÍ¡°¼ÙÆÚ¡±Òªº¦´ÊµÄ´¹ÂÚÔ˶¯µÄÊÖÒÕϸ½Ú¡£±ðµÄ£¬ÆÊÎö·¢Ã÷¹¥»÷Õßͨ³£Ê¹ÓÃGoogle FirebaseÓòÀ´ÓÕÆÄ¿µÄ²¢ÈƹýÇå¾²¹ýÂËÆ÷¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/travel-themed-phishing/


¾©¹«Íø°²±¸11010802024551ºÅ