DarkCrewFriendsÀûÓÃÄÚÈÝÖÎÀíϵͳ¹¹½¨½©Ê¬ÍøÂ磻£»£»£»£»£»£»¶ñÒâ.slkÎļþ¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATP
°ä²¼¹¦·ò 2020-06-281.DarkCrewFriends»Ø¹é£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÄÚÈÝÖÎÀíϵͳ¹¹½¨½©Ê¬ÍøÂç
Check PointµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯DarkCrewFriends»Ø¹é£¬£¬£¬£¬£¬£¬£¬£¬²¢¶Ô×¼ÄÚÈÝÖÎÀíϵͳÀ´¹¹½¨½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯ÔÚÀûÓÃÒ»¸ö²»ÊÜÏ޶ȵÄÎļþÉÏ´«·ì϶À´·ÛËéÍøÕ¾µÄPHP·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÊܺ¦Õß·þÎñÆ÷ÉÏ·¢ÏÖÁËÏÂÔØºÍÖ´ÐÐÁ½¸ö.AFFÎļþµÄºÅÁ£¬£¬£¬£¬£¬£¬£¬µ±ËûÃÇÏÂÔØÕâÁ½¸öÎļþʱ£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖËüÃÇÏÖʵÉÏÊÇPHPºÍPerlÎļþ¡£¡£¡£¡£¡£¡£·ÖÎöÈËÔ±×ܽá·£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃIRCºÍ̸ϰȾ·þÎñÆ÷À´´´½¨½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬Õâ»á¶ÔÊܺ¦ÕߵĻù´¡ÉèÊ©²úÉúºÜÑϳÁµÄÓ°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/darkcrewfriends-returns-botnet/156963/
2.Evil Corp¹¥»÷30¶à¼ÒÃÀ¹ú¹«Ë¾²¢·Ö·¢WastedLocker
ÈüÃÅÌú¿Ë°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬°µÊ¾ºÚ¿Í×éÖ¯Evil Corp¹¥»÷ÁË30¶à¼ÒÃÀ¹ú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÊÔͼÔÚÊܺ¦ÕßϵͳÖÐ×°ÖÃÀÕË÷Èí¼þWastedLocker¡£¡£¡£¡£¡£¡£ÔÚÕâЩ±»¶Ô×¼µÄ¹«Ë¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬³ýÁËÒ»¼ÒÊǺ£±í¿ç¹ú¹«Ë¾ÔÚÃÀ¹úµÄ×Ó¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓàÈ«ÊýÊÇÃÀ¹ú¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ½ÁËÔì×÷Òµ£¨5¼Ò£©£¬£¬£¬£¬£¬£¬£¬£¬ÐÅÏ¢¼¼Êõ²¿ÃÅ£¨4¼Ò£©ºÍµçÐÅ×éÖ¯£¨3¼Ò£©¡£¡£¡£¡£¡£¡£ÈüÃÅÌú¿Ë·ÖÎö·£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ʼÓÚ»ùÓÚJavaScriptµÄ¶ñÒâ¿ò¼ÜSocGholish£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¿ò¼Ü¿É¸ú×Ù150¶à¸ö¼Ù×°³ÉÈí¼þ¸üеÄÊÜÏ°È¾ÍøÕ¾¡£¡£¡£¡£¡£¡£Ò»µ©¹¥»÷Õß»ñµÃÁËÖ¸±êÍøÕ¾µÄ½Ó¼ûȨ£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áʹÓÃCobalt StrikeÀ´ÇÔȡʹ´¦¡¢ÌáȨ²¢ºáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ×°ÖÃWastedLocker¡£¡£¡£¡£¡£¡£ÈüÃÅÌú¿Ë»ã±¨µÄĩβ»¹ÌṩÁËÓйØWastedLocker¹¥»÷µÄ·çÏÕÖ¸±ê£¨IOC£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/evil-corp-blocked-from-deploying-ransomware-on-30-major-us-firms/
3.еĶñÒâ.slkÎļþ¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATP
AvananµÄ°²È«·ÖÎöʦÒѼì²âµ½¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATPµÄеĶñÒâ.slkÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ô¤¼Æ»á¸ø2ÒÚ¶àÓû§´øÀ´·çÏÕ¡£¡£¡£¡£¡£¡£Ôڴ˹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í·¢ËÍ´øÓÐ.slk¸½¼þµÄµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¸½¼þ»¹Ô̺¬ÓÃÀ´ÏÂÔØºÍ×°ÖÃÔ¶³Ì½Ó¼ûľÂíµÄ¶ñÒâºê£¨MSI exec¾ç±¾£©¡£¡£¡£¡£¡£¡£¸Ã.slkÎļþÄܹ»Òñ±ÎµÄÔËÐÐWindows×°Ö÷¨Ê½(msiexec)£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×°ÖÃËûÃÇÔÚÆäÕ¾µãÉÏÍйܵÄMSI°ü¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓõÄÊÇÔ¶³Ì½ÚÔìÀûÓ÷¨Ê½NetSupportµÄºÚ¿Í°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì×ÀÃæ¡£¡£¡£¡£¡£¡£ºÚ¿Í»¹Ê¹ÓÃÁ˺öàÓÃÀ´ÈƹýATPµÄ»ìºÏ¼¼Êõ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬ÓʼþÊÇ´ÓÊý°Ù¸öÃâ·ÑµÄhotmailÕÊ»§·¢Ë͵컣»£»£»£»£»£»ºê¾ç±¾Ô̺¬¡°^¡±×Ö·û£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ»ìºÏATP¹ýÂËÆ÷£»£»£»£»£»£»£»¸ÃÍøÖ·±»·Ö³ÉÁ½²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øATP²»»á½«ÆäÊÓÎªÍøÂçÁ´½Ó£¬£¬£¬£¬£¬£¬£¬£¬µÈµÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.informationsecuritybuzz.com/news/200m-users-at-risk-new-malicious-slk-files-are-bypassing-microsoft-365-security/
4.½ü300¸öWindows 10¿ÉÖ´ÐÐÎļþÒ×Ôâµ½DLL½Ù³Ö¹¥»÷
ÆÕ»ªÓÀ·°²È«×êÑÐÈËÔ±°ä²¼»ã±¨°µÊ¾ £¬£¬£¬£¬£¬£¬£¬£¬½«½ü300¸öWindows 10¿ÉÖ´ÐÐÎļþÈÝÒ×Êܵ½DLL½Ù³Ö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÒ»¸öµ¥Ò»µÄVBScriptÒ²Ðí¾ÍÄܹ»»ñµÃÖÎÀíԱȨÏÞ²¢ÆëÈ«ÈÆ¹ýWindows 10ÉϵÄUAC¡£¡£¡£¡£¡£¡£ÓÉÓÚWindows 7ÒÔÉÏÔÊÐíÊÜÐÅÀµµÄϵͳDLLÄܹ»×Ô¶¯ÌáÉýÌØÈ¨£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÓÃʹÓÃUACÌáÐÑÀ´´ò½ÁÓû§£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýʹÓÃÏóÕ÷Ϊ×Ô¶¯ÌáȨµÄ¿ÉÖ´ÐÐÎļþÀ´³¢ÊÔÒÔ¸ü¸ßȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£Ò»µ©³É¹¦ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬Ôò¶ñÒâdll¿ÉÓÃÓÚ´´½¨ÌáȨµÄºÅÁîÌáÐÑ·û£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÒÔÖÎÀíȨÏÞ¶ÔÍÆËã»ú½øÐнӼû¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/almost-300-windows-10-executables-vulnerable-to-dll-hijacking/
5.¶í¾ÍÒµÍøÕ¾SuperJobµÄϵͳ´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶500Íò¹«ÃñÐÅÏ¢
DeviceLock·¢ÏÖÁ˶íÂÞ˹¾ÍÒµÍøÕ¾SuperJobÒòÆäϵͳ´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË500Íò¹«ÃñÐÅÏ¢¡£¡£¡£¡£¡£¡£Õâ´Îй¶Êý¾ÝÔ̺¬Óû§ÐÕÃûºÍÖÐÑëÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢³ÇÊÓ×¢½øÕ¹µÄнˮˮƽ¡¢Òƶ¯ÔËÓªÉ̵ÄÃû³Æ¡¢Óû§µÄµØÓòºÍÊ±Çø¡£¡£¡£¡£¡£¡£×¨¼Ò·ÖÎö£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Îй©¿ÉÄÜÊÇÓÉÓÚÊý¾Ý¿â·þÎñÆ÷Öеķì϶ÒýÆðµÄ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇSuperJob»Ø¾øÌṩÓйØÕâ´ÎÊÂÎñµÄ¾ßÌåÐÅÏ¢ÒÔ¼°Æä500ÍòÓû§Ó×ÎÒÐÅϢй¶µÄÉêÃ÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2020/06/experts-have-discovered-data-leak-of.html
6.ýÌ幫˾E27Ôâµ½Korean Hackers¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ô´´úÂëºÍÊý¾Ý¿âй¶
ÑÇÖÞµÄýÌ幫˾E27Ôâµ½×Ô³ÆÎªKorean HackersµÄºÚ¿Í¹¥»÷µ¼ÖÂÔ´´úÂëºÍÊý¾Ý¿âй¶£¬£¬£¬£¬£¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶Ò»±Ê¡°Ó×Ó׵ľè¿î¡±£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÏàʶÆäÊÇÈôºÎ±»ºÚ¿ÍÈëÇÖ²¢Ô®ÊÔì佨¸´·ì϶¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ðû³ÆËûÃÇÇÔÈ¡ÁËÊܺ¦¹«Ë¾µÄÔ´´úÂëºÍÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬µç×ÓÓʼþ¡¢ÊÖ»ú¡¢ÃÜÂë¡¢ÆäËûÎĵµ¡¢Ó×ÎÒ×ÊÁÏͼÏñµÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬E27ÒѾÏòÆäÓû§·¢³öÁËÐÅϢй¶֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬ÆäCEO Mohan BelaniÔò°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒÑÓë·¨Âɲ¿ÃÅ»ñµÃÁªÏµ£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆÚ´ýËûÃǵÄÖ§³ÖºÍÁìµ¼¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-breach-e27-want-donation-to-reveal-vulnerabilities/


¾©¹«Íø°²±¸11010802024551ºÅ