{"id":78968,"date":"2020-04-23T13:42:01","date_gmt":"2020-04-23T11:42:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-rubygems-vyyavleno-724-vredonosnyh-paketa"},"modified":"2020-04-23T13:42:01","modified_gmt":"2020-04-23T11:42:01","slug":"v-rubygems-vyyavleno-724-vredonosnyh-paketa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa","title":{"rendered":"\u00cen RubyGems au fost identificate 724 de pachete malware","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Compania ReversingLabs <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.reversinglabs.com\/blog\/mining-for-malicious-ruby-gems\">a publicat<\/a><\/noindex> rezultatele analizelor aplic\u0103rii  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=44576\">type squatting<\/a><\/noindex> \u00een depozitul RubyGems. De obicei, type squatting este utilizat pentru distribuirea unor pachete r\u0103u inten\u021bionate, av\u00e2nd \u00een vedere c\u0103 un dezvoltator neaten\u021bionat ar putea face o gre\u0219eal\u0103 de tipar sau nu ar observa diferen\u021ba. \u00cen cadrul cercet\u0103rii, s-au identificat peste 700 de pachete a c\u0103ror denumire este similar\u0103 cu cea a pachetelor populare, diferen\u021bele fiind minime, cum ar fi \u00eenlocuirea unor litere asem\u0103n\u0103toare sau utilizarea de liniu\u021be \u00een loc de cratime. <\/p>\n<p>\u00cen peste 400 de pachete au fost descoperite componente suspectate de activit\u0103\u021bi r\u0103u inten\u021bionate. \u00cen special, s-a g\u0103sit un fi\u0219ier aaa.png, care con\u021bine cod executabil \u00een format PE. Pachetele respective au fost asociate cu dou\u0103 conturi, prin intermediul c\u0103rora, \u00eentre 16 \u0219i 25 februarie 2020, au fost \u00eenc\u0103rcate \u00een RubyGems <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.reversinglabs.com\/hubfs\/Blog\/ruby_malicious_gems.txt\">724 de pachete r\u0103u inten\u021bionate<\/a><\/noindex>, care au fost desc\u0103rcate de aproximativ 95.000 de ori. Cercet\u0103torii au informat administra\u021bia RubyGems \u0219i pachetele r\u0103u inten\u021bionate identificate au fost deja \u0219terse din depozit. <\/p>\n<p>Dintre pachetele problematice identificate, cel mai popular a fost &#171;atlas-client&#187;, care la prima vedere este aproape indistinguibil de pachetul legitim &#171;<noindex><a rel=\"nofollow\" href=\"https:\/\/rubygems.org\/gems\/atlas_client\">atlas_client<\/a><\/noindex>&#171;. Pachetul respectiv a fost desc\u0103rcat de 2100 de ori (\u00een timp ce pachetul normal a fost desc\u0103rcat de 6496 de ori, adic\u0103 utilizatorii s-au \u00een\u0219elat \u00een aproape 25% din cazuri). Celelalte pachete au fost desc\u0103rcate \u00een medie de 100-150 de ori \u0219i s-au camuflat sub alte pachete folosind tehnici similare de \u00eenlocuire a subliniat \u0219i a cratimelor (de exemplu, printre <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.reversinglabs.com\/hubfs\/Blog\/ruby_malicious_gems.txt\">pachetele r\u0103u inten\u021bionate<\/a><\/noindex>: appium-lib, action-mailer_cache_delivery, activemodel_validators, asciidoctor_bibliography, assets-pipeline, apress_validators, ar_octopus-replication-tracking, aliyun-open_search, aliyun-mns, ab_split, apns-polite).<\/p>\n<p>Pachetele malware includeau un fi\u0219ier PNG, \u00een care, \u00een loc de imagine, era inclus un fi\u0219ier executabil pentru platforma Windows. Fi\u0219ierul a fost generat cu ajutorul utilitarului Ocra Ruby2Exe \u0219i con\u021binea un arhiv\u0103 auto-extractibil\u0103 cu un script Ruby \u0219i interpretul Ruby. La instalarea pachetului, fi\u0219ierul png era redenumit \u00een exe \u0219i era lansat. \u00cen timpul execu\u021biei, se crea \u0219i se ad\u0103uga \u00een autostart un fi\u0219ier VBScript. Acest VBScript mali\u021bios analiza \u00een mod ciclic con\u021binutul clipboard-ului pentru a verifica existen\u021ba unor informa\u021bii ce aminteaz\u0103 de adrese de criptomonede \u0219i, \u00een cazul detect\u0103rii, \u00eenlocuia num\u0103rul portofelului, asum\u00e2ndu-se c\u0103 utilizatorul nu va observa diferen\u021bele \u0219i va transfera fondurile c\u0103tre un portofel gre\u0219it. <\/p>\n<p>Cercetarea realizat\u0103 a ar\u0103tat c\u0103 nu este dificil s\u0103 se adauge pachete malware \u00eentr-unul dintre cele mai populare repozitorii, aceste pachete put\u00e2nd r\u0103m\u00e2ne neobservate, chiar \u0219i cu un num\u0103r semnificativ de desc\u0103rc\u0103ri. Trebuie men\u021bionat c\u0103 problema <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50462\">nu<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51056\">este specific\u0103<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51321\">pentru<\/a><\/noindex> RubyGems \u0219i afecteaz\u0103 alte repozitorii populare. De exemplu, anul trecut, aceia\u0219i cercet\u0103tori <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51336\">au identificat<\/a><\/noindex> \u00een repozitoriul NPM, un pachet malware numit bb-builder, care folosea o tehnic\u0103 similar\u0103 pentru a lansa un fi\u0219ier executabil pentru a fura parole. \u00cen trecut, un backdoor a fost <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49665\">g\u0103sit<\/a><\/noindex> \u00een dependen\u021ba de pachetul NPM event-stream, iar codul mali\u021bios a fost desc\u0103rcat de aproximativ 8 milioane de ori. Pachetele malware apar de asemenea <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49490\">periodic<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51975\">\u00een mod constant<\/a><\/noindex> \u00een repozitorul PyPI.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52785\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0442\u0430\u0439\u043f\u0441\u043a\u0432\u043e\u0442\u0442\u0438\u043d\u0433\u0430 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 RubyGems. \u041e\u0431\u044b\u0447\u043d\u043e \u0442\u0430\u0439\u043f\u0441\u043a\u0432\u043e\u0442\u0442\u0438\u043d\u0433 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0440\u0430\u0441\u0441\u0447\u0438\u0442\u0430\u043d\u043d\u044b\u0445 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e \u043d\u0435\u0432\u043d\u0438\u043c\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043f\u0440\u0438 \u043f\u043e\u0438\u0441\u043a\u0435 \u0434\u043e\u043f\u0443\u0441\u0442\u0438\u0442 \u043e\u043f\u0435\u0447\u0430\u0442\u043a\u0443 \u0438\u043b\u0438 \u043d\u0435 \u0437\u0430\u043c\u0435\u0442\u0438\u0442 \u0440\u0430\u0437\u043d\u0438\u0446\u044b. \u0412 \u0445\u043e\u0434\u0435 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 700 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0445\u043e\u0436\u0438 \u0441 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u043c\u0438 \u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438 \u0438 \u043e\u0442\u043b\u0438\u0447\u0430\u044e\u0442\u0441\u044f \u043d\u0435\u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c\u0438 \u0434\u0435\u0442\u0430\u043b\u044f\u043c\u0438, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0437\u0430\u043c\u0435\u043d\u043e\u0439 \u043f\u043e\u0445\u043e\u0436\u0438\u0445 \u0431\u0443\u043a\u0432 \u0438\u043b\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-78968","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 RubyGems \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 724 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-23T11:42:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-23T11:42:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00cen RubyGems au fost identificate 724 de pachete malware | ProHoster","description":"Compania ReversingLabs a publicat rezultatele analizei aplic\u0103rii","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 RubyGems \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 724 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u0430 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f ReversingLabs \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/v-rubygems-vyyavleno-724-vredonosnyh-paketa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-23T11:42:01+00:00","article:modified_time":"2020-04-23T11:42:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78968","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:47:25","updated":"2022-09-28 01:38:04","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/78968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=78968"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/78968\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=78968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=78968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=78968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}