ºÚ¿Íɾ³ýÊý°ÙÃûGit¿ª·¢ÕߵĴúÂë¿â£»£»£»£»£»£»200Ëù´óѧµÄУ԰É̵êϰȾMagecart£»£»£»£»£»£»AMC Networksй¶160ÍòÓû§Êý¾Ý
°ä²¼¹¦·ò 2019-05-05
ºÚ¿Í¶Ô×¼Êý°ÙÃûGitHub¡¢GitLabºÍBitbucketÓû§£¬£¬£¬£¬£¬£¬£¬£¬É¾³ýÆä´úÂë¿â²¢ÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚGitHubÉÏ·¢ÏÖ392¸ö´úÂë¿âÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬ÕâЩ´úÂë¿â¾ù±»Ò»¸öÆßÄêǰ£¨2012Äê1ÔÂ25ÈÕ£©´´½¨µÄÕ˺Ågitbackupɾ³ý¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒªÇóÖ§¸¶0.1±ÈÌØ±Ò£¨Ô¼568ÃÀÔª£©µÄÊê½ð£¬£¬£¬£¬£¬£¬£¬£¬µ«½ØÖÁĿǰ²¢Ã»ÓÐÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£StackExchange°²È«ÂÛ̳µÄ³ÉÔ±·¢ÏÖºÚ¿ÍÏÖʵÉϲ¢Î´É¾³ý´úÂë¿â£¬£¬£¬£¬£¬£¬£¬£¬½ö½öÊÇŤתÁËgit commit±êÍ·£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅijЩÇé¿öÏÂÄܹ»¸´Ô´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/attackers-wiping-github-and-gitlab-repos-leave-ransom-notes/
2¡¢³¬¹ý200Ëù´óѧµÄУ԰É̵êϰȾMagecart¶ñÒâ¾ç±¾
³¬¹ý200ËùÃÀ¹úºÍ¼ÓÄôó´óѧµÄÔÚÏßУ԰É̵êÔâµ½Magecart¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾ÓÉPrismWebµç×ÓÉÌÎñƽ̨Ìṩ֧³Ö£¬£¬£¬£¬£¬£¬£¬£¬µ«PrismWebÓÚ4ÔÂ14ÈÕ±»×¢Èë¶ñÒâµÄMagecart¾ç±¾¡£¡£¡£¡£¡£¡£¡£¡£¸ÃJavaScript¾ç±¾ÓÃÓÚÇÔÈ¡¿Í»§µÄÖ§¸¶ÐÅÏ¢ºÍÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÅÓþ¿¨ºÅ¡¢ÓÐЧÆÚ¡¢¿¨ÀàÐÍ¡¢ÑéÖ¤ºÅÂ루CVN£©ÒÔ¼°³Ö¿¨È˵ÄÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂëµÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÍøÂçÕâЩÐÅÏ¢ºó½«ÐÅÏ¢´æ´¢ÎªJSONÌåʽ£¬£¬£¬£¬£¬£¬£¬£¬¾¹ýAES¼ÓÃܺͱàÂëºó£¬£¬£¬£¬£¬£¬£¬£¬×÷ΪHTMLͼÏñÔªËØµÄURL²ÎÊý·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Ç÷Ïò¿Æ¼¼µÄ×êÑÐÍŶÓÒÔΪ¸Ã¹©¸øÁ´¹¥»÷ÊÇÓÉеķ¸×ïÍÅ»ïMirrorthiefÌáÒéµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔ¾ßÌåµÄÊÜÓ°ÏìÈËÊý¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-200-college-campus-stores-infected-with-card-stealing-scripts/
3¡¢×êÑÐÍŶӰ䲼ºóCoinhiveʱÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯·ÖÎö
Malwarebytes Labs×êÑÐÍŶӰ䲼ºóCoinhiveʱÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯·ÖÎö¡£¡£¡£¡£¡£¡£¡£¡£CoinhiveÔÚ2019Äê3ÔÂ8ÈչعØÁË·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ«´óÁ¿µÄÍøÕ¾ºÍ·ÓÉÆ÷ÈÔ´æÔÚCoinhiveÒÅÁô£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈÔ¶ÔCoinhive¿â·¢³öÒªÇ󡣡£¡£¡£¡£¡£¡£¡£ÔÚ´ÓǰһÖÜÄÚ£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӾùÔÈÿÌì¼Í¼µ½5Íò¸öÕë¶ÔCoinhiveµÄÒªÇ󡣡£¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩҪÇó½«ÎÞ·¨Ïνӵ½·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø²»ÄܽøÐÐÍÚ¿ó»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£µ«»ùÓÚÍøÂçµÄ¿ó¹¤²¢Î´ÖÕ³¡£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçCoinhiveµÄ¾ºÕùµÐÊÖCryptoLoot¡¢CoinIMP£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶÓÿÌì³ÇÊмì²âµ½³¬¹ý100Íò´ÎÕë¶ÔCryptoLootµÄÒªÇ󡣡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/
4¡¢ÒøÐÐľÂíRetefe¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÈðÊ¿ºÍµÂ¹ú
4Ô·ÝProofpoint×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíRetefeµÄ¹¥»÷ÊýÁ¿³ÊÉÏÉýÇ÷Ïò¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÆðÍ·Õë¶ÔÈðÊ¿ºÍµÂ¹úµÄÒøÐÐÓû§£¬£¬£¬£¬£¬£¬£¬£¬²»ÂÛÊÇWindows»¹ÊÇmacOSƽ̨¡£¡£¡£¡£¡£¡£¡£¡£ÐµĹ¥»÷»î¶¯ÖÐRetefeÒ²¸ü¸ÄÁËһЩְÄÜ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçʹÓÃTLS/SSLËí··þÎñStunnel´úÌæTOR×÷Ϊ´úÀí³Á¶¨ÏòºÍC&CÉèÖÃͨ·¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÒÔǰRetefe³£ÓëPowerShellÏÂÔØÆ÷sLoad¹ØÁª£¬£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÕë¶ÔÈðÊ¿µÄ¹¥»÷»î¶¯ÖиöñÒâÈí¼þʹÓÃSmoke Loader×÷ΪÖÐÑë½×¶ÎµÄÏÂÔØÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.scmagazine.com/home/security-news/__trashed/
5¡¢ÐÂÀÕË÷Èí¼þMegaCortex£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒª¶Ô×¼ÆóÒµÍøÂç
Sophos×êÑÐÍŶӷ¢ÏÖÖØÒª¶Ô×¼ÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þMegaCortex£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þÒÑϰȾÁËÃÀ¹ú¡¢Òâ´óÀû¡¢¼ÓÄô󡢷¨¹ú¡¢ºÉÀ¼ºÍ°®¶ûÀ¼µÄÓû§¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÀÕË÷Èí¼þÊÇгöÏֵ쬣¬£¬£¬£¬£¬£¬£¬Òò¶øÄ¿Ç°¶ÔÆä¼ÓÃÜËã·¨¡¢ÈôºÎ»ñµÃÆóÒµÍøÂçµÄ½Ó¼ûȨÏÞÒÔ¼°ÊÇ·ñÓÐÈËÖ§¸¶ÁËÊê½ðµÈÇé¿öÖªÖ®ÉõÉÙ¡£¡£¡£¡£¡£¡£¡£¡£Sophos·¢ÏÖϰȾÁËMegaCortexµÄÆóÒµÍøÂçÉÏ´æÔÚEmotet»òQakbotľÂí£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø¹¥»÷Õß¿ÉÄÜÊÇÏòľÂí¹¥»÷ÕßÖ§¸¶ÓöÈÒÔ»ñµÃ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©½øÈëÍøÂ磬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáͨ¹ýWindowsÓò½ÚÔìÆ÷À´´«²¼²¢Ï°È¾Õû¸öÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-megacortex-ransomware-found-targeting-business-networks/


¾©¹«Íø°²±¸11010802024551ºÅ