¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181126
Ðû²¼Ê±¼ä 2018-11-26
2018ÄêµÄÐþÉ«ÐÇÆÚÎå´Ó11ÔÂ23ÈÕ×îÏÈ£¬¹ºÎï¼¾½Ú½«Ò»Ö±ÑÓÐøµ½Ê¥µ®½Úʱ´ú¡£Group-IBÑо¿Ö°Ô±·¢Ã÷ÁË400¶à¸öÄ£ÄâÔÚÏßÉúÒâÆ½Ì¨µÄAliExpressÍøÕ¾£¬ÒÔ¼°200¶à¸öÄ£Äâ×ÅÃûÆ·ÅÆµÄÍøÕ¾£¬ÕâЩڲÆÐÔµÄÍøÕ¾¿ÉÄÜÊÇΪÁËÏúÊÛð³äÉÌÆ·£¬Ò²¿ÉÄÜÊÇΪÁË͵ÇÔÓû§µÄÒøÐп¨Êý¾Ý¼°¿î×Ó¡£¹¥»÷Õ߸´ÖÆÁËÕæÊµÍøÕ¾µÄÆ·ÅÆ¡¢logoÒÔ¼°ÑÕÉ«£¬²¢×¢²áÏàËÆµÄÓòÃûÀ´Îóµ¼ÏûºÄÕß¡£ÕâÖÖÍøÕ¾µÄ»á¼ûÁ¿¿É´ïÿ¸öÔÂ20ÍòÈ˴Ρ£Æ¾Ö¤Group-IBµÄͳ¼Æ£¬Æ½¾ùÿ¸ö¶íÂÞ˹ÈËÔÚð³äÉÌÆ·ÉÏÆÆ·ÑÁË5300¬²¼¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.ru/blog/blackfridaysale2¡¢Çå¾²³§ÉÌ·¢Ã÷ºÚÎåʱ´úEmotetµÄ´ó¹æÄ£À¬»øÓʼþÔ˶¯
ESET·¢Ã÷ÓëºÚÎ幺Îï¼¾ÓйصÄEmotet´ó¹æÄ£À¬»øÓʼþÔ˶¯¡£Óë֮ǰµÄ¹¥»÷Ïà±È£¬EmotetÉÔ΢¸Ä±äÁËËûÃǵÄ×÷°¸ÊÖ·¨¡£ËäÈ»ÓÐÓúÉÔØÈÔÈ»ÊÇͨ¹ýÀ¬»øÓʼþÖеĸ½¼þºÍ¶ñÒâÁ´½ÓÀ´½»¸¶£¬µ«ÔÚºÚÎåʱ´ú£¬ÕâЩ¶ñÒâÎļþÊÇÀ©Õ¹ÃûΪ.docµÄXMLÎļþ£¬¶ø²»ÊÇ֮ǰµÄdocºÍpdfÎļþ¡£¸Ã¶ñÒâÔ˶¯µÄÓÐÓúÉÔØÊÇÖÖÖÖÒøÐÐľÂí£¬°üÀ¨Ursnif¡¢TrickBotºÍIcedId¡£À¶¡ÃÀÖÞÊÇÊÜÓ°Ïì×î´óµÄ¹ú¼Ò£¬Æä´ÎÊÇÄ«Î÷¸ç¡¢¶ò¹Ï¶à¶û¡¢°¢¸ùÍ¢ºÍÃÀ¹ú¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/black-friday-special-emotet-filling-inboxes-infected-xml-macros/3¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒôÀÖ·þÎñƽ̨SpotifyµÄÍøÂç´¹ÂÚ¹¥»÷
AppRiverµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶ÔÔÚÏßÒôÀÖ·þÎñSpotifyÓû§µÄÍøÂç´¹ÂÚ¹¥»÷¡£ÕâЩÀ¬»øÓʼþÊÔͼͨ¹ýÓÕÆÓû§µã»÷ÓʼþÖеĴ¹ÂÚÁ´½Ó£¬½«Óû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾£¬²¢ÒýÓÕÓû§ÊäÈëÓû§ÃûºÍÃÜÂë¡£ÈôÊÇÓû§ÔÚÆäËüÍøÕ¾ÉÏ£¨ÀýÈçÍøÉÏÒøÐУ©Ê¹ÓÃÁËÏàͬµÄƾ֤£¬ÄÇôÓû§¿ÉÄÜÔÚײ¿â¹¥»÷ÖÐÊܵ½¸ü´óµÄË𺦡£ËäÈ»´¹ÂÚÍøÕ¾µÄµÇÂ¼Ò³ÃæÓë¹ÙÍøspotify.comÏàËÆ£¬µ«Óû§ÈÔÈ»¿ÉÒÔ´ÓÓʼþµÄ·¢¼þÈË¡¢ÍøÕ¾µÄURLÖÐÇø·Ö³ö´¹ÂÚÍøÕ¾£¬×èÖ¹Êܵ½Ëðʧ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spotify-phishers-hijack-music-fans-accounts/139329/4¡¢21ËêºÚ¿ÍÈëÇÖ¹è¹È¶àÃû¸ß¹ÙµÄÊÖ»ú£¬ÇÔÈ¡¼ÛÖµ100ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò
ƾ֤ÃÀ¹ú¼ì·½±¾ÔÂÏò¼ÓÖÝ·¨ÔºÌá½»µÄÒ»·ÝÎļþ£¬21ËêµÄNicholas TrugliaʹÓÃÒ»ÖÖ±»³ÆÎªSIM¿¨½»Á÷µÄÕ½ÂÔÈëÇÖÁ˶àÃû¹è¹È¸ß¹ÜµÄÊÖ»ú£¬²¢´ÓRobert RossµÄCoinbaseºÍGeminiÕË»§Öл®·ÖÇÔÈ¡ÁË50ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¸ÃÎļþÏÔʾTrugliaÒѱ»Ö¸¿Ø21Ïî×ïÃû£¬°üÀ¨Éí·Ý͵ÇÔ¡¢Ú²Æ¡¢Å²Óù«¿î¡¢ÖØ´ó͵ÇÔδËìµÈ¡£SIM¿¨½»Á÷ÊÇÖ¸·¸·¨·Ö×Óαװ³ÉÊܺ¦Õߣ¬ÓÕÆÔËÓªÉ̽«Êܺ¦ÕßµÄÊÖ»úºÅÂëÖØÐ·ÖÅɸø¹¥»÷ÕßÓµÓеÄSIM¿¨µÄÕ½ÂÔ¡£¸ÃÀú³ÌÖз¸·¨·Ö×ÓÐèÒª»Ø¸²Ò»Ð©ÓÃÓÚÑéÖ¤Éí·ÝµÄÇå¾²ÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/new-yorker-accused-stealing-1m-sim-swap/5¡¢ÎÚ¿ËÀ¼¾¯·½¾Ð²¶ÉæÏÓÈö²¥DarkComet RATµÄÏÓÒÉ·¸
ÎÚ¿ËÀ¼¾¯·½¾Ð²¶ÁËÒ»ÃûÉæÏÓÈö²¥DarkComet RATµÄ42ËêÄÐ×Ó£¬¸ÃÄÐ×Ó±»Ö¸¿ØÊ¹ÓÃDarkCometѬȾÁË50¶à¸ö¹ú¼ÒµÄÁè¼Ý2000ÃûÊܺ¦Õß¡£¸ÃÄÐ×ÓÔÚÎÚ¿ËÀ¼Î÷²¿ÀûÎÖ·òÊеļÒÖб»²¶¡£ÎÚ¿ËÀ¼¾¯·½ÌåÏÖËûÃÇÔÚÏÓÒÉÈ˵ÄÅÌËã»úÉÏ·¢Ã÷ÁËDarkCommet RATµÄÖÎÀíÃæ°å£¬²¢ÕÒµ½ÁËDarkCommetµÄ×°ÖÃÎļþÒÔ¼°Êܺ¦ÕßÅÌËã»úµÄÆÁÄ»½ØÍ¼¡£¸ÃÏÓ·¸ÏÖʵÉÏ·¸ÁËÒ»¸öOpSec¹ýʧ£¬Ëû½«DarkCometÖÎÀíÃæ°åÖ±½Ó·ÅÔÚ¼ÒÀïµÄÅÌËã»úÉÏ£¬Ê¹µÃ¾¯·½ºÜÈÝÒ×¶¨Î»µ½ÆäÉí·Ý¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ukrainian-police-arrest-hacker-who-infected-over-2000-users-with-darkcomet-rat/6¡¢Ñо¿Ö°Ô±·¢Ã÷Ö¼ÔÚѬȾWindowsϵͳµÄжñÒâÈí¼þL0rdix
EnSiloÑо¿Ö°Ô±Ben Hunter·¢Ã÷ÔÚ°µÍøÂÛ̳ÉÏ·ºÆðÁËÒ»¸öеĶñÒâÈí¼þL0rdix£¬¸Ã¶ñÒâÈí¼þÖ÷ÒªÕë¶ÔWindowsϵͳ£¬ÍŽáÁËÊý¾ÝÇÔÈ¡ºÍ¶ñÒâÍÚ¿ó¹¦Ð§£¬²¢ÇÒ¿ÉÒÔÌӱܶñÒâÈí¼þÆÊÎö¹¤¾ß¡£L0rdixËäÈ»ÒÑÔÚ°µÍøÂÛ̳ÉϳöÊÛ£¬µ«ÈÔÓÐһЩ֤¾ÝÅú×¢¸Ã¶ñÒâÈí¼þ»¹ÔÚ¿ª·¢Àú³ÌÖС£L0rdixʹÓÃ.NET±àд£¬Ê¹ÓÃConfuserExºÍ.NETGuard¾ÙÐлìÏý£¬²¢Í¨¹ýWMIÅÌÎʺÍ×¢²á±íÏîÀ´¼ì²âÊÇ·ñɳÏäÇéÐΡ£EnSiloÔ¤¼Æ½«»á¿´µ½¸Ã¶ñÒâÈí¼þµÄ¸ü¶àÖØ´ó°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://blog.ensilo.com/l0rdix-attack-toolÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ