¶íÂÞ˹ÔËÓªÉÌMiranda MediaÔâµ½´ó¹æÄ£DDoS¹¥»÷

Ðû²¼Ê±¼ä 2023-10-31

1¡¢¶íÂÞ˹ÔËÓªÉÌMiranda MediaÔâµ½´ó¹æÄ£DDoS¹¥»÷


¾ÝýÌå10ÔÂ29ÈÕ±¨µÀ£¬Miranda Media ISPÔÚÉÏÖÜÎåÐû²¼ÕýÃæÁÙ´ó¹æÄ£DDoS¹¥»÷¡£IT Army of Ukraine×éÖ¯²¢³ïıÁËÕë¶Ô¶íÂÞ˹Èý´ó»¥ÁªÍøÌṩÉÌÖ´ÐÐDDoS¹¥»÷¡£Miranda Media³Æ£¬×Ô10ÔÂ27ÈÕÉÏÎç9:05ÒÔÀ´£¬ÔËÓªÉÌMiranda-Media¼Ç¼ÁËÀ´×ÔÎÚ¿ËÀ¼ÍÅ»ïµÄ´ó¹æÄ£DDoS¹¥»÷£¬Miranda-Media¡¢KrymtelecomºÍMirTelecomµÄ·þÎñÔÝʱ²»ÐÐÓ᣸Ãʼþ²»½öÓ°Ïìµ½¿ËÀïÃ×ÑÇ£¬»¹Ó°Ïìµ½ºÕ¶ûËÉ¡¢Ôú²¨ÂÞÈÈ¡¢¶ÙÄù´Ä¿ËºÍ¬¸Ê˹¿ËµØÓòµÄ²¿ÃŵØÓò¡£


https://securityaffairs.com/153192/hacktivism/it-army-of-ukraine-hit-russia-isp.html


2¡¢ÀÕË÷ÍÅ»ïRansomedVCÐû²¼½âÉ¢²¢³öÊÛÆä¹¤¾ß´úÂë


¾Ý10ÔÂ30ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïRansomedVCÐû²¼Òò¡°¸öÈËÔ­Òò¡±½âÉ¢£¬²¢½«³öÊÛÆäÕû¸öÍøÂç»ù´¡ÉèÊ©¡£RansomedVCÓÚ½ñÄê8ÔÂÊ״ηºÆð£¬Õë¶Ô¹«Ë¾¡¢Õþ¸®»ú¹¹ºÍ½ÌÓý»ú¹¹µÈ¡£´Ë´Î³öÊÛµÄ×ʲúÊýÁ¿¾ªÈË£¬°üÂÞÖÖÖÖÓòÃûºÍÂÛ̳¡¢ÀÕË÷Èí¼þÉú³ÉÆ÷¡¢Á¥ÊôÍÅ»ïµÄ·ÃÎÊȨÏÞ¡¢É罻ýÌåÕË»§¡¢TelegramƵµÀ¡¢¶à¼Ò¹«Ë¾µÄVPN·ÃÎÊȨÏ޺ͼÛÖµÁè¼Ý1000ÍòÃÀÔªµÄÊý¾Ý¿âµÈ¡£Ñо¿ÈËÔ±ÍÆ²â½âÉ¢µÄÔ­Òò£¬¿ÉÄÜÊÇÀ´×ÔÖ´·¨»ú¹¹µÄѹÁ¦£¬Ò²¿ÉÄÜÊÇÒ»¸öеĸüÅÓ´óµÄÐж¯ÕýÔÚÔÍÄðÖ®ÖС£


https://www.hackread.com/ransomedvc-ransomware-quit-sell-infrastructure/


3¡¢Elastic·¢ÏÖͨ¹ýαÔìMSIXÓ¦Ó÷ַ¢GHOSTPULSEµÄ»î¶¯


10ÔÂ27ÈÕ£¬Elastic¼ì²âµ½Ò»ÖÖÐµĹ¥»÷»î¶¯£¬Ê¹ÓÃαÔìµÄMSIX WindowsÓ¦Ó÷¨Ê½°ü£¬À´·Ö·¢ÐÂÐͶñÒâÈí¼þ¼ÓÔØ·¨Ê½GHOSTPULSE¡£¸Ã»î¶¯Ê×ÏÈÓÕʹÓû§ÏÂÔØMSIXÈí¼þ°ü£¬µ±Óû§Æô¶¯MSIXÎļþ»áµ¯³öÒ»¸ö´°¿ÚÌáʾµã»÷¡°°²×°¡±°´Å¥¡£µã»÷ºó£¬Ò»¸öPowerShell½Å±¾»áÃØÃܵØÔÚϵͳÉÏÏÂÔØ¡¢½âÃܺÍÖ´ÐÐGHOSTPULSE¡£GHOSTPULSE×÷Ϊ¼ÓÔØ·¨Ê½£¬½ÓÄÉProcess Doppelg?nging¹¥»÷·½Ê½Æô¶¯×îÖÕpayload¡£×îÖÕpayloadÒòÑù±¾¶øÒ죬°üÂÞSectopRAT¡¢Rhadamanthys¡¢Vidar¡¢LummaºÍNetSupport RAT¡£


https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks


4¡¢¼ÓÖÝijÊÐÔâµ½NoEscapeµÄÀÕË÷¹¥»÷Ô¼200GBÊý¾Ý±»µÁ


ýÌå10ÔÂ27Èճƣ¬ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝά¿Ë¶àά¶û͸¶ÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¸ÃÊÐÐû²¼Í¨Öª³Æ£¬ºÚ¿ÍÔÚ8ÔÂ12ÈÕÖÁ9ÔÂ26ÈÕÈëÇÖÁËËûÃǵÄϵͳ£¬¾ÓÃñÉç»áÄþ¾²ºÅÂëºÍÒ½ÁÆÐÅÏ¢µÈй¶¡£ÊÐÕþÔ±¹¤ÓÚ9ÔÂ25ÈÕÔÚFacebookÉϳÆ£¬ÕýÔÚ´¦ÖÃÓ°Ïìµç»°ºÍÍøÕ¾ÏµÍ³µÄÖжÏÎÊÌ⣬֮ºóÌåÏÖÒÑÓÚ10ÔÂ3ÈÕ»Ö¸´µç»°ºÍÍøÕ¾·þÎñ£¬µ«»ùÓÚÍøÂçµÄϵͳÈÔÎÞ·¨ÔËÐС£ÉÏÖܶþ£¬NoEscape½«¸ÃÊÐÌí¼Óµ½ÆäÁбíÖУ¬Éù³ÆÒÑ´ÓÊÐÕþϵͳÖÐÇÔÈ¡ÁË200GBµÄÊý¾Ý¡£


https://therecord.media/california-victorville-warns-of-data-breach-after-noescape-ransomware-claims


5¡¢Harmony EmailÐû²¼¹ØÓÚQuishing¹¥»÷µÄ·ÖÎö³ÂËß


10ÔÂ26ÈÕ£¬Check PointµÄHarmony EmailÍŶÓÐû²¼Á˹ØÓÚQuishing£¨¼´¶þάÂëµöÓ㣩¹¥»÷µÄ·ÖÎö³ÂËß¡£½ñÄê8Ôµ½9Ô£¬¶þάÂë¹¥»÷Ôö¼ÓÁË587%¡£¸Ã³ÂËß»¹¸ÅÊöÁËÒ»Æð¹¥»÷»î¶¯£¬À´ÌÖÂÛºÚ¿ÍÈçºÎÀûÓöþάÂëÇÔȡƾ֤¡£¹¥»÷Õß´´½¨ÁËÒ»¸ö½«Óû§Öض¨Ïòµ½Æ¾¾ÝÊÕ¼¯Ò³ÃæµÄ¶þάÂ룬Ȼºó·¢ËÍÒÔ¡°Microsoft MFA¼´½«¹ýÆÚ¡±ÎªÓÕ¶üµÄÓʼþ£¬ÒªÇóÊÕ¼þÈËÖØÐ½øÐÐÉí·ÝÑéÖ¤£¬Óû§É¨Ãè¶þάÂëºó½«±»Öض¨Ïòµ½Ò»¸ö¿´ÆðÀ´Ïñ΢ÈíÍøÕ¾µÄƾ¾ÝÊÕ¼¯ÍøÕ¾¡£ 


https://www.avanan.com/blog/the-rise-in-qr-code-attacks


6¡¢CloudflareÐû²¼2023ÄêQ3 DDoS¹¥»÷Ì¬ÊÆµÄ³ÂËß


10ÔÂ26ÈÕ£¬CloudflareÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ì¬ÊÆµÄ³ÂËß¡£µÚÈý¼¾¶È£¬Cloudflare½â¾öÁËÊýǧÆð´ó¹æÄ£HTTP DDoS¹¥»÷¡£ÆäÖУ¬89ÆðÁè¼ÝÿÃë1ÒÚÇëÇó (rps)£¬×î´ó·åֵΪ2.01ÒÚrps£¬ÕâÊÇ֮ǰ×î´ó¹æÄ£¹¥»÷(7100Íòrps)µÄÈý±¶£¬ÕâЩ¹¥»÷ÊÇͨ¹ýHTTP/2 Rapid ResetʵÏֵġ£ÕâÒ»¼¾¶ÈµÄHTTP DDoS¹¥»÷Á÷Á¿½ÏÉÏÒ»¼¾¶È×ÜÌåÔö³¤65%£¬L3/4 DDoS¹¥»÷Ò²Ôö¼ÓÁË14%¡£Cloudflare»¹ÊӲ쵽еÄÇ÷ÊÆ£¬mDNS¹¥»÷Ôö¼ÓÁË456%£¬CoAP DDoS¹¥»÷Ôö¼ÓÁË387%£¬ESP DDoS¹¥»÷Ôö¼ÓÁË303%£¬ÀÕË÷DDoS¹¥»÷³ÊÏÂÔØÇ÷ÊÆ¡£


https://blog.cloudflare.com/ddos-threat-report-2023-q3/