¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181126
Ðû²¼Ê±¼ä 2018-11-26
2018ÄêµÄÐþÉ«ÐÇÆÚÎå´Ó11ÔÂ23ÈÕ×îÏÈ£¬£¬£¬£¬£¬£¬¹ºÎï¼¾½Ú½«Ò»Ö±ÑÓÐøµ½Ê¥µ®½Úʱ´ú¡£¡£¡£¡£¡£Group-IBÑо¿Ö°Ô±·¢Ã÷ÁË400¶à¸öÄ£ÄâÔÚÏßÉúÒâÆ½Ì¨µÄAliExpressÍøÕ¾£¬£¬£¬£¬£¬£¬ÒÔ¼°200¶à¸öÄ£Äâ×ÅÃûÆ·ÅÆµÄÍøÕ¾£¬£¬£¬£¬£¬£¬ÕâЩڲÆÐÔµÄÍøÕ¾¿ÉÄÜÊÇΪÁËÏúÊÛð³äÉÌÆ·£¬£¬£¬£¬£¬£¬Ò²¿ÉÄÜÊÇΪÁË͵ÇÔÓû§µÄÒøÐп¨Êý¾Ý¼°¿î×Ó¡£¡£¡£¡£¡£¹¥»÷Õ߸´ÖÆÁËÕæÊµÍøÕ¾µÄÆ·ÅÆ¡¢logoÒÔ¼°ÑÕÉ«£¬£¬£¬£¬£¬£¬²¢×¢²áÏàËÆµÄÓòÃûÀ´Îóµ¼ÏûºÄÕß¡£¡£¡£¡£¡£ÕâÖÖÍøÕ¾µÄ»á¼ûÁ¿¿É´ïÿ¸öÔÂ20ÍòÈ˴Ρ£¡£¡£¡£¡£Æ¾Ö¤Group-IBµÄͳ¼Æ£¬£¬£¬£¬£¬£¬Æ½¾ùÿ¸ö¶íÂÞ˹ÈËÔÚð³äÉÌÆ·ÉÏÆÆ·ÑÁË5300¬²¼¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.ru/blog/blackfridaysale2¡¢Çå¾²³§ÉÌ·¢Ã÷ºÚÎåʱ´úEmotetµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯
ESET·¢Ã÷ÓëºÚÎ幺Îï¼¾ÓйصÄEmotet´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£Óë֮ǰµÄ¹¥»÷Ïà±È£¬£¬£¬£¬£¬£¬EmotetÉÔ΢¸Ä±äÁËËûÃǵÄ×÷°¸ÊÖ·¨¡£¡£¡£¡£¡£ËäÈ»ÓÐÓúÉÔØÈÔÈ»ÊÇͨ¹ýÀ¬»øÓʼþÖеĸ½¼þºÍ¶ñÒâÁ´½ÓÀ´½»¸¶£¬£¬£¬£¬£¬£¬µ«ÔÚºÚÎåʱ´ú£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâÎļþÊÇÀ©Õ¹ÃûΪ.docµÄXMLÎļþ£¬£¬£¬£¬£¬£¬¶ø²»ÊÇ֮ǰµÄdocºÍpdfÎļþ¡£¡£¡£¡£¡£¸Ã¶ñÒâ»î¶¯µÄÓÐÓúÉÔØÊÇÖÖÖÖÒøÐÐľÂí£¬£¬£¬£¬£¬£¬°üÀ¨Ursnif¡¢TrickBotºÍIcedId¡£¡£¡£¡£¡£À¶¡ÃÀÖÞÊÇÊÜÓ°Ïì×î´óµÄ¹ú¼Ò£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÄ«Î÷¸ç¡¢¶ò¹Ï¶à¶û¡¢°¢¸ùÍ¢ºÍÃÀ¹ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/black-friday-special-emotet-filling-inboxes-infected-xml-macros/3¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒôÀÖЧÀÍÆ½Ì¨SpotifyµÄÍøÂç´¹ÂÚ¹¥»÷
AppRiverµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶ÔÔÚÏßÒôÀÖЧÀÍSpotifyÓû§µÄÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£ÕâЩÀ¬»øÓʼþÊÔͼͨ¹ýÓÕÆÓû§µã»÷ÓʼþÖеĴ¹ÂÚÁ´½Ó£¬£¬£¬£¬£¬£¬½«Óû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬²¢ÒýÓÕÓû§ÊäÈëÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£ÈôÊÇÓû§ÔÚÆäËüÍøÕ¾ÉÏ£¨ÀýÈçÍøÉÏÒøÐУ©Ê¹ÓÃÁËÏàͬµÄƾ֤£¬£¬£¬£¬£¬£¬ÄÇôÓû§¿ÉÄÜÔÚײ¿â¹¥»÷ÖÐÊܵ½¸ü´óµÄË𺦡£¡£¡£¡£¡£ËäÈ»´¹ÂÚÍøÕ¾µÄµÇÂ¼Ò³ÃæÓë¹ÙÍøspotify.comÏàËÆ£¬£¬£¬£¬£¬£¬µ«Óû§ÈÔÈ»¿ÉÒÔ´ÓÓʼþµÄ·¢¼þÈË¡¢ÍøÕ¾µÄURLÖÐÇø·Ö³ö´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬×èÖ¹Êܵ½Ëðʧ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spotify-phishers-hijack-music-fans-accounts/139329/4¡¢21ËêºÚ¿ÍÈëÇÖ¹è¹È¶àÃû¸ß¹ÙµÄÊÖ»ú£¬£¬£¬£¬£¬£¬ÇÔÈ¡¼ÛÖµ100ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò
ƾ֤ÃÀ¹ú¼ì·½±¾ÔÂÏò¼ÓÖÝ·¨ÔºÌá½»µÄÒ»·ÝÎļþ£¬£¬£¬£¬£¬£¬21ËêµÄNicholas TrugliaʹÓÃÒ»ÖÖ±»³ÆÎªSIM¿¨½»Á÷µÄÕ½ÂÔÈëÇÖÁ˶àÃû¹è¹È¸ß¹ÜµÄÊÖ»ú£¬£¬£¬£¬£¬£¬²¢´ÓRobert RossµÄCoinbaseºÍGeminiÕË»§Öл®·ÖÇÔÈ¡ÁË50ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¸ÃÎļþÏÔʾTrugliaÒѱ»Ö¸¿Ø21Ïî×ïÃû£¬£¬£¬£¬£¬£¬°üÀ¨Éí·Ý͵ÇÔ¡¢Ú²Æ¡¢Å²Óù«¿î¡¢ÖØ´ó͵ÇÔδËìµÈ¡£¡£¡£¡£¡£SIM¿¨½»Á÷ÊÇÖ¸·¸·¨·Ö×Óαװ³ÉÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ÓÕÆÔËÓªÉ̽«Êܺ¦ÕßµÄÊÖ»úºÅÂëÖØÐ·ÖÅɸø¹¥»÷ÕßÓµÓеÄSIM¿¨µÄÕ½ÂÔ¡£¡£¡£¡£¡£¸ÃÀú³ÌÖз¸·¨·Ö×ÓÐèÒª»Ø¸²Ò»Ð©ÓÃÓÚÑéÖ¤Éí·ÝµÄÇå¾²ÎÊÌâ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/new-yorker-accused-stealing-1m-sim-swap/5¡¢ÎÚ¿ËÀ¼¾¯·½¾Ð²¶ÉæÏÓÈö²¥DarkComet RATµÄÏÓÒÉ·¸
ÎÚ¿ËÀ¼¾¯·½¾Ð²¶ÁËÒ»ÃûÉæÏÓÈö²¥DarkComet RATµÄ42ËêÄÐ×Ó£¬£¬£¬£¬£¬£¬¸ÃÄÐ×Ó±»Ö¸¿ØÊ¹ÓÃDarkCometѬȾÁË50¶à¸ö¹ú¼ÒµÄÁè¼Ý2000ÃûÊܺ¦Õß¡£¡£¡£¡£¡£¸ÃÄÐ×ÓÔÚÎÚ¿ËÀ¼Î÷²¿ÀûÎÖ·òÊеļÒÖб»²¶¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¾¯·½ÌåÏÖËûÃÇÔÚÏÓÒÉÈ˵ÄÅÌËã»úÉÏ·¢Ã÷ÁËDarkCommet RATµÄÖÎÀíÃæ°å£¬£¬£¬£¬£¬£¬²¢ÕÒµ½ÁËDarkCommetµÄ×°ÖÃÎļþÒÔ¼°Êܺ¦ÕßÅÌËã»úµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¸ÃÏÓ·¸ÏÖʵÉÏ·¸ÁËÒ»¸öOpSec¹ýʧ£¬£¬£¬£¬£¬£¬Ëû½«DarkCometÖÎÀíÃæ°åÖ±½Ó·ÅÔÚ¼ÒÀïµÄÅÌËã»úÉÏ£¬£¬£¬£¬£¬£¬Ê¹µÃ¾¯·½ºÜÈÝÒ×¶¨Î»µ½ÆäÉí·Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ukrainian-police-arrest-hacker-who-infected-over-2000-users-with-darkcomet-rat/6¡¢Ñо¿Ö°Ô±·¢Ã÷Ö¼ÔÚѬȾWindowsϵͳµÄжñÒâÈí¼þL0rdix
EnSiloÑо¿Ö°Ô±Ben Hunter·¢Ã÷ÔÚ°µÍøÂÛ̳ÉÏ·ºÆðÁËÒ»¸öеĶñÒâÈí¼þL0rdix£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖ÷ÒªÕë¶ÔWindowsϵͳ£¬£¬£¬£¬£¬£¬Á¬ÏµÁËÊý¾ÝÇÔÈ¡ºÍ¶ñÒâÍÚ¿ó¹¦Ð§£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÌӱܶñÒâÈí¼þÆÊÎö¹¤¾ß¡£¡£¡£¡£¡£L0rdixËäÈ»ÒÑÔÚ°µÍøÂÛ̳ÉϳöÊÛ£¬£¬£¬£¬£¬£¬µ«ÈÔÓÐһЩ֤¾ÝÅú×¢¸Ã¶ñÒâÈí¼þ»¹ÔÚ¿ª·¢Àú³ÌÖС£¡£¡£¡£¡£L0rdixʹÓÃ.NET±àд£¬£¬£¬£¬£¬£¬Ê¹ÓÃConfuserExºÍ.NETGuard¾ÙÐлìÏý£¬£¬£¬£¬£¬£¬²¢Í¨¹ýWMIÅÌÎʺÍ×¢²á±íÏîÀ´¼ì²âÊÇ·ñɳÏäÇéÐΡ£¡£¡£¡£¡£EnSiloÔ¤¼Æ½«»á¿´µ½¸Ã¶ñÒâÈí¼þµÄ¸ü¶àÖØ´ó°æ±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.ensilo.com/l0rdix-attack-toolÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ