¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181126

°ä²¼¹¦·ò 2018-11-26
1¡¢Group-IB°ä²¼ºÚÎåÍø¹ºÚ²Æ­·çÏյķÖÎö»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2018ÄêµÄÐþÉ«ÐÇÆÚÎå´Ó11ÔÂ23ÈÕÆðÍ·£¬£¬£¬£¬£¬¹ºÎï¼¾½Ú½«Ò»ÏòÒ»Á¬µ½Ê¥µ®½ÚÆÚ¼ä¡£¡£¡£¡£¡£Group-IB×êÑÐÈËÔ±·¢ÏÖÁË400¶à¸ö·ÂÕÕÔÚÏßÂòÂôƽ̨µÄAliExpressÍøÕ¾£¬£¬£¬£¬£¬ÒÔ¼°200¶à¸ö·ÂÕÕ³ÛÃûÆ·ÅÆµÄÍøÕ¾£¬£¬£¬£¬£¬ÕâЩڲƭÐÔµÄÍøÕ¾¿ÉÄÜÊÇΪÁËÏúÊÛ¼ÙðÉÌÆ·£¬£¬£¬£¬£¬Ò²¿ÉÄÜÊÇΪÁË͵ÇÔÓû§µÄÒøÐп¨Êý¾Ý¼°½ðÇ®¡£¡£¡£¡£¡£¹¥»÷Õ߸´ÔìÁËÕæÊµÍøÕ¾µÄÆ·ÅÆ¡¢logoÒÔ¼°É«²Ê£¬£¬£¬£¬£¬²¢×¢²áÀàËÆµÄÓòÃûÀ´Îóµ¼Ïû·ÑÕß¡£¡£¡£¡£¡£ÕâÖÖÍøÕ¾µÄ½Ó¼ûÁ¿¿É´ïÿ¸öÔÂ20ÍòÈ˴Ρ£¡£¡£¡£¡£Æ¾¾ÝGroup-IBµÄͳ¼Æ£¬£¬£¬£¬£¬¾ùÔÈÿ¸ö¶íÂÞ˹ÈËÔÚ¼ÙðÉÌÆ·ÉÏÆÆ·ÑÁË5300¬²¼¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.group-ib.ru/blog/blackfridaysale


2¡¢°²È«³§ÉÌ·¢ÏÖºÚÎåÆÚ¼äEmotetµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ESET·¢ÏÖÓëºÚÎ幺Îï¼¾ÓйصÄEmotet´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£Óë֮ǰµÄ¹¥»÷Ïà±È£¬£¬£¬£¬£¬EmotetÉÔ΢ŤתÁËËûÃǵÄ×÷°¸ÊÖ·¨¡£¡£¡£¡£¡£¹ÌÈ»ÓÐЧºÉÔØÒÀÈ»ÊÇͨ¹ýÀ¬»øÓʼþÖеĸ½¼þºÍ¶ñÒâÁ´½ÓÀ´½»¸¶£¬£¬£¬£¬£¬µ«ÔÚºÚÎåÆÚ¼ä£¬£¬£¬£¬£¬ÕâЩ¶ñÒâÎļþÊÇÀ©´óÃûΪ.docµÄXMLÎļþ£¬£¬£¬£¬£¬¶ø²»ÊÇ֮ǰµÄdocºÍpdfÎļþ¡£¡£¡£¡£¡£¸Ã¶ñÒâ»î¶¯µÄÓÐЧºÉÔØÊǸ÷ÀàÒøÐÐľÂí£¬£¬£¬£¬£¬Ô̺¬Ursnif¡¢TrickBotºÍIcedId¡£¡£¡£¡£¡£À­¶¡ÃÀÖÞÊÇÊÜÓ°Ïì×î´óµÄ¹ú¶È£¬£¬£¬£¬£¬Æä´ÎÊÇÄ«Î÷¸ç¡¢¶ò¹Ï¶à¶û¡¢°¢¸ùÍ¢ºÍÃÀ¹ú¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/2018/11/23/black-friday-special-emotet-filling-inboxes-infected-xml-macros/


3¡¢×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÒôÀÖ·þÎñƽ̨SpotifyµÄÍøÂç´¹µö¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


AppRiverµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶ÔÔÚÏßÒôÀÖ·þÎñSpotifyÓû§µÄÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£ÕâЩÀ¬»øÓʼþÊÔͼͨ¹ýºýŪÓû§µã»÷ÓʼþÖеĴ¹µöÁ´½Ó£¬£¬£¬£¬£¬½«Óû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾£¬£¬£¬£¬£¬²¢ÒýÓÕÓû§ÊäÈëÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£ÈôÊÇÓû§ÔÚÆäËüÍøÕ¾ÉÏ£¨ÀýÈçÍøÉÏÒøÐУ©Ê¹ÓÃÁËÒ»ÑùµÄÍ´´¦£¬£¬£¬£¬£¬ÄÇôÓû§¿ÉÄÜÔÚײ¿â¹¥»÷ÖÐÊܵ½¸ü´óµÄÇÖº¦¡£¡£¡£¡£¡£¹ÌÈ»´¹µöÍøÕ¾µÄµÇÂ¼Ò³ÃæÓë¹ÙÍøspotify.comÀàËÆ£¬£¬£¬£¬£¬µ«Óû§ÒÀÈ»Äܹ»´ÓÓʼþµÄ·¢¼þÈË¡¢ÍøÕ¾µÄURLÖзֱæ³ö´¹µöÍøÕ¾£¬£¬£¬£¬£¬Ô¤·ÀÊܵ½Ëðʧ¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/spotify-phishers-hijack-music-fans-accounts/139329/


4¡¢21ËêºÚ¿ÍÈëÇÖ¹è¹È¶àÃû¸ß¹ÙµÄÊÖ»ú£¬£¬£¬£¬£¬ÇÔÈ¡¼ÛÖµ100ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝÃÀ¹ú¼ì·½±¾ÔÂÏò¼ÓÖÝ·¨ÔºÌá½»µÄÒ»·ÝÎļþ£¬£¬£¬£¬£¬21ËêµÄNicholas TrugliaʹÓÃÒ»ÖÖ±»³ÆÎªSIM¿¨»¥»»µÄÕ½ÊõÈëÇÖÁ˶àÃû¹è¹È¸ß¹ÜµÄÊÖ»ú£¬£¬£¬£¬£¬²¢´ÓRobert RossµÄCoinbaseºÍGeminiÕË»§Æ½±ðÀëÇÔÈ¡ÁË50ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¸ÃÎļþÏÔʾTrugliaÒѱ»Ö¸¿Ø21Ïî×ïÃû£¬£¬£¬£¬£¬Ô̺¬Éí·Ý͵ÇÔ¡¢Ú²Æ­¡¢Å²Óù«¿î¡¢³Á´ó͵ÇÔδËìµÈ¡£¡£¡£¡£¡£SIM¿¨»¥»»ÊÇÖ¸·¸×ï·Ö×Ó¼Ù×°³ÉÊܺ¦Õߣ¬£¬£¬£¬£¬ºýŪÔËÓªÉ̽«Êܺ¦ÕßµÄÊÖ»úºÅÂë³ÁзÖÅ䏸¹¥»÷ÕßÕ¼ÓеÄSIM¿¨µÄÕ½Êõ¡£¡£¡£¡£¡£¸Ã¹ý³ÌÖз¸×ï·Ö×Ó±ØÒª»Ø¸²Ò»Ð©ÓÃÓÚÑéÖ¤Éí·ÝµÄ°²È«ÎÊÌâ¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/2018/11/23/new-yorker-accused-stealing-1m-sim-swap/


5¡¢ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÉæÏÓ´«²¼DarkComet RATµÄÏÓÒÉ·¸

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÁËÒ»ÃûÉæÏÓ´«²¼DarkComet RATµÄ42ËêÄÐ×Ó£¬£¬£¬£¬£¬¸ÃÄÐ×Ó±»Ö¸¿ØÊ¹ÓÃDarkCometϰȾÁË50¶à¸ö¹ú¶ÈµÄ³¬¹ý2000ÃûÊܺ¦Õß¡£¡£¡£¡£¡£¸ÃÄÐ×ÓÔÚÎÚ¿ËÀ¼Î÷²¿ÀûÎÖ·òÊеļÒÖб»²¶¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¾¯·½°µÊ¾ËûÃÇÔÚÏÓÒÉÈ˵ÄÍÆËã»úÉÏ·¢ÏÖÁËDarkCommet RATµÄÖÎÀíÃæ°å£¬£¬£¬£¬£¬²¢ÕÒµ½ÁËDarkCommetµÄ×°ÖÃÎļþÒÔ¼°Êܺ¦ÕßÍÆËã»úµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¸ÃÏÓ·¸ÏÖʵÉÏ·¸ÁËÒ»¸öOpSecÃýÎ󣬣¬£¬£¬£¬Ëû½«DarkCometÖÎÀíÃæ°åÖ±½Ó·ÅÔÚ¼ÒÀïµÄÍÆËã»úÉÏ£¬£¬£¬£¬£¬Ê¹µÃ¾¯·½ºÜÈÝÒ×¶¨Î»µ½ÆäÉí·Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ukrainian-police-arrest-hacker-who-infected-over-2000-users-with-darkcomet-rat/


6¡¢×êÑÐÈËÔ±·¢ÏÖÖ¼ÔÚϰȾWindowsϵͳµÄжñÒâÈí¼þL0rdix

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


EnSilo×êÑÐÈËÔ±Ben Hunter·¢´Ë¿Ì°µÍøÂÛ̳ÉϳöÏÖÁËÒ»¸öеĶñÒâÈí¼þL0rdix£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔWindowsϵͳ£¬£¬£¬£¬£¬½áºÏÁËÊý¾ÝÇÔÈ¡ºÍ¶ñÒâÍÚ¿óÖ°ÄÜ£¬£¬£¬£¬£¬²¢ÇÒÄܹ»ÌӱܶñÒâÈí¼þ·ÖÎö¹¤¾ß¡£¡£¡£¡£¡£L0rdix¹ÌÈ»ÒÑÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ£¬£¬£¬£¬£¬µ«ÈÔÓÐһЩ֤¾ÝÅú×¢¸Ã¶ñÒâÈí¼þ»¹ÔÚ¿ª·¢¹ý³ÌÖÓ×£¡£¡£¡£¡£L0rdixʹÓÃ.NET±àд£¬£¬£¬£¬£¬Ê¹ÓÃConfuserExºÍ.NETGuard½øÐлìºÏ£¬£¬£¬£¬£¬²¢Í¨¹ýWMI²éÎʺÍ×¢²á±íÏîÀ´¼ì²âÊÇ·ñɳÏä»·¾³¡£¡£¡£¡£¡£EnSiloÔ¤¼Æ½«»á¿´µ½¸Ã¶ñÒâÈí¼þµÄ¸ü¶à¸´ÔÓ°æ±¾¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://blog.ensilo.com/l0rdix-attack-tool


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù