DarkCrewFriendsÀûÓÃÄÚÈÝÖÎÀíϵͳ¹¹½¨½©Ê¬ÍøÂ磻 £»£»£»£»£»£»¶ñÒâ.slkÎļþ¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATP

°ä²¼¹¦·ò 2020-06-28

1.DarkCrewFriends»Ø¹é£¬£¬£¬ £¬£¬£¬£¬£¬ÀûÓÃÄÚÈÝÖÎÀíϵͳ¹¹½¨½©Ê¬ÍøÂç


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Check PointµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯DarkCrewFriends»Ø¹é£¬£¬£¬ £¬£¬£¬£¬£¬²¢¶Ô×¼ÄÚÈÝÖÎÀíϵͳÀ´¹¹½¨½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯ÔÚÀûÓÃÒ»¸ö²»ÊÜÏ޶ȵÄÎļþÉÏ´«·ì϶À´·ÛËéÍøÕ¾µÄPHP·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÔÚÊܺ¦Õß·þÎñÆ÷ÉÏ·¢ÏÖÁËÏÂÔØºÍÖ´ÐÐÁ½¸ö.AFFÎļþµÄºÅÁ£¬£¬ £¬£¬£¬£¬£¬µ±ËûÃÇÏÂÔØÕâÁ½¸öÎļþʱ£¬£¬£¬ £¬£¬£¬£¬£¬·¢ÏÖËüÃÇÏÖʵÉÏÊÇPHPºÍPerlÎļþ¡£¡£¡£¡£¡£¡£·ÖÎöÈËÔ±×ܽá·£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃIRCºÍ̸ϰȾ·þÎñÆ÷À´´´½¨½©Ê¬ÍøÂ磬£¬£¬ £¬£¬£¬£¬£¬Õâ»á¶ÔÊܺ¦ÕߵĻù´¡ÉèÊ©²úÉúºÜÑϳÁµÄÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/darkcrewfriends-returns-botnet/156963/


2.Evil Corp¹¥»÷30¶à¼ÒÃÀ¹ú¹«Ë¾²¢·Ö·¢WastedLocker


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÈüÃÅÌú¿Ë°ä²¼»ã±¨£¬£¬£¬ £¬£¬£¬£¬£¬°µÊ¾ºÚ¿Í×éÖ¯Evil Corp¹¥»÷ÁË30¶à¼ÒÃÀ¹ú¹«Ë¾£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÊÔͼÔÚÊܺ¦ÕßϵͳÖÐ×°ÖÃÀÕË÷Èí¼þWastedLocker¡£¡£¡£¡£¡£¡£ÔÚÕâЩ±»¶Ô×¼µÄ¹«Ë¾ÖУ¬£¬£¬ £¬£¬£¬£¬£¬³ýÁËÒ»¼ÒÊǺ£±í¿ç¹ú¹«Ë¾ÔÚÃÀ¹úµÄ×Ó¹«Ë¾£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÓàÈ«ÊýÊÇÃÀ¹ú¹«Ë¾£¬£¬£¬ £¬£¬£¬£¬£¬Éæ¼°µ½ÁËÔì×÷Òµ£¨5¼Ò£©£¬£¬£¬ £¬£¬£¬£¬£¬ÐÅÏ¢¼¼Êõ²¿ÃÅ£¨4¼Ò£©ºÍµçÐÅ×éÖ¯£¨3¼Ò£©¡£¡£¡£¡£¡£¡£ÈüÃÅÌú¿Ë·ÖÎö·£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ʼÓÚ»ùÓÚJavaScriptµÄ¶ñÒâ¿ò¼ÜSocGholish£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã¿ò¼Ü¿É¸ú×Ù150¶à¸ö¼Ù×°³ÉÈí¼þ¸üеÄÊÜÏ°È¾ÍøÕ¾¡£¡£¡£¡£¡£¡£Ò»µ©¹¥»÷Õß»ñµÃÁËÖ¸±êÍøÕ¾µÄ½Ó¼ûȨ£¬£¬£¬ £¬£¬£¬£¬£¬¾Í»áʹÓÃCobalt StrikeÀ´ÇÔȡʹ´¦¡¢ÌáȨ²¢ºáÏòÒÆ¶¯£¬£¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚ×°ÖÃWastedLocker¡£¡£¡£¡£¡£¡£ÈüÃÅÌú¿Ë»ã±¨µÄĩβ»¹ÌṩÁËÓйØWastedLocker¹¥»÷µÄ·çÏÕÖ¸±ê£¨IOC£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/evil-corp-blocked-from-deploying-ransomware-on-30-major-us-firms/


3.еĶñÒâ.slkÎļþ¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATP


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


AvananµÄ°²È«·ÖÎöʦÒѼì²âµ½¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATPµÄеĶñÒâ.slkÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¤¼Æ»á¸ø2ÒÚ¶àÓû§´øÀ´·çÏÕ¡£¡£¡£¡£¡£¡£Ôڴ˹¥»÷ÖУ¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿Í·¢ËÍ´øÓÐ.slk¸½¼þµÄµç×ÓÓʼþ£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã¸½¼þ»¹Ô̺¬ÓÃÀ´ÏÂÔØºÍ×°ÖÃÔ¶³Ì½Ó¼ûľÂíµÄ¶ñÒâºê£¨MSI exec¾ç±¾£©¡£¡£¡£¡£¡£¡£¸Ã.slkÎļþÄܹ»Òñ±ÎµÄÔËÐÐWindows×°Ö÷¨Ê½(msiexec)£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ×°ÖÃËûÃÇÔÚÆäÕ¾µãÉÏÍйܵÄMSI°ü¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿ÍʹÓõÄÊÇÔ¶³Ì½ÚÔìÀûÓ÷¨Ê½NetSupportµÄºÚ¿Í°æ±¾£¬£¬£¬ £¬£¬£¬£¬£¬ËüÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì×ÀÃæ¡£¡£¡£¡£¡£¡£ºÚ¿Í»¹Ê¹ÓÃÁ˺öàÓÃÀ´ÈƹýATPµÄ»ìºÏ¼¼Êõ£¬£¬£¬ £¬£¬£¬£¬£¬ÀýÈ磬£¬£¬ £¬£¬£¬£¬£¬ÓʼþÊÇ´ÓÊý°Ù¸öÃâ·ÑµÄhotmailÕÊ»§·¢Ë͵ģ» £»£»£»£»£»£»ºê¾ç±¾Ô̺¬¡°^¡±×Ö·û£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ»ìºÏATP¹ýÂËÆ÷£» £»£»£»£»£»£»¸ÃÍøÖ·±»·Ö³ÉÁ½²¿ÃÅ£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶øATP²»»á½«ÆäÊÓÎªÍøÂçÁ´½Ó£¬£¬£¬ £¬£¬£¬£¬£¬µÈµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.informationsecuritybuzz.com/news/200m-users-at-risk-new-malicious-slk-files-are-bypassing-microsoft-365-security/


4.½ü300¸öWindows 10¿ÉÖ´ÐÐÎļþÒ×Ôâµ½DLL½Ù³Ö¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÆÕ»ªÓÀ·°²È«×êÑÐÈËÔ±°ä²¼»ã±¨°µÊ¾ £¬£¬£¬ £¬£¬£¬£¬£¬½«½ü300¸öWindows 10¿ÉÖ´ÐÐÎļþÈÝÒ×Êܵ½DLL½Ù³Ö¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÒ»¸öµ¥Ò»µÄVBScriptÒ²Ðí¾ÍÄܹ»»ñµÃÖÎÀíԱȨÏÞ²¢ÆëÈ«ÈÆ¹ýWindows 10ÉϵÄUAC¡£¡£¡£¡£¡£¡£ÓÉÓÚWindows 7ÒÔÉÏÔÊÐíÊÜÐÅÀµµÄϵͳDLLÄܹ»×Ô¶¯ÌáÉýÌØÈ¨£¬£¬£¬ £¬£¬£¬£¬£¬¶ø²»ÓÃʹÓÃUACÌáÐÑÀ´´ò½ÁÓû§£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýʹÓÃÏóÕ÷Ϊ×Ô¶¯ÌáȨµÄ¿ÉÖ´ÐÐÎļþÀ´³¢ÊÔÒÔ¸ü¸ßȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£Ò»µ©³É¹¦ÀûÓ㬣¬£¬ £¬£¬£¬£¬£¬Ôò¶ñÒâdll¿ÉÓÃÓÚ´´½¨ÌáȨµÄºÅÁîÌáÐÑ·û£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÒÔÖÎÀíȨÏÞ¶ÔÍÆËã»ú½øÐнӼû¡£¡£¡£¡£¡£¡£  


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/almost-300-windows-10-executables-vulnerable-to-dll-hijacking/


5.¶í¾ÍÒµÍøÕ¾SuperJobµÄϵͳ´æÔÚ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬Ð¹Â¶500Íò¹«ÃñÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


DeviceLock·¢ÏÖÁ˶íÂÞ˹¾ÍÒµÍøÕ¾SuperJobÒòÆäϵͳ´æÔÚ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬Ð¹Â¶ÁË500Íò¹«ÃñÐÅÏ¢¡£¡£¡£¡£¡£¡£Õâ´Îй¶Êý¾ÝÔ̺¬Óû§ÐÕÃûºÍÖÐÑëÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢³ÇÊÓ×¢½øÕ¹µÄнˮˮƽ¡¢Òƶ¯ÔËÓªÉ̵ÄÃû³Æ¡¢Óû§µÄµØÓòºÍÊ±Çø¡£¡£¡£¡£¡£¡£×¨¼Ò·ÖÎö£¬£¬£¬ £¬£¬£¬£¬£¬Õâ´Îй©¿ÉÄÜÊÇÓÉÓÚÊý¾Ý¿â·þÎñÆ÷Öеķì϶ÒýÆðµÄ£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÊÇSuperJob»Ø¾øÌṩÓйØÕâ´ÎÊÂÎñµÄ¾ßÌåÐÅÏ¢ÒÔ¼°Æä500ÍòÓû§Ó×ÎÒÐÅϢй¶µÄÉêÃ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/06/experts-have-discovered-data-leak-of.html


6.ýÌ幫˾E27Ôâµ½Korean Hackers¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô´´úÂëºÍÊý¾Ý¿âй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÑÇÖÞµÄýÌ幫˾E27Ôâµ½×Ô³ÆÎªKorean HackersµÄºÚ¿Í¹¥»÷µ¼ÖÂÔ´´úÂëºÍÊý¾Ý¿âй¶£¬£¬£¬ £¬£¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶Ò»±Ê¡°Ó×Ó׵ľè¿î¡±£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔÏàʶÆäÊÇÈôºÎ±»ºÚ¿ÍÈëÇÖ²¢Ô®ÊÔì佨¸´·ì϶¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ðû³ÆËûÃÇÇÔÈ¡ÁËÊܺ¦¹«Ë¾µÄÔ´´úÂëºÍÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÖÐÔ̺¬µç×ÓÓʼþ¡¢ÊÖ»ú¡¢ÃÜÂë¡¢ÆäËûÎĵµ¡¢Ó×ÎÒ×ÊÁÏͼÏñµÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬£¬£¬£¬E27ÒѾ­ÏòÆäÓû§·¢³öÁËÐÅϢй¶֪ͨ£¬£¬£¬ £¬£¬£¬£¬£¬ÆäCEO Mohan BelaniÔò°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬ËûÃÇÒÑÓë·¨Âɲ¿ÃÅ»ñµÃÁªÏµ£¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ÆÚ´ýËûÃǵÄÖ§³ÖºÍÁìµ¼¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-breach-e27-want-donation-to-reveal-vulnerabilities/