¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181126
°ä²¼¹¦·ò 2018-11-26
2018ÄêµÄÐþÉ«ÐÇÆÚÎå´Ó11ÔÂ23ÈÕÆðÍ·£¬¹ºÎï¼¾½Ú½«Ò»ÏòÒ»Á¬µ½Ê¥µ®½ÚÆÚ¼ä¡£Group-IB×êÑÐÈËÔ±·¢ÏÖÁË400¶à¸ö·ÂÕÕÔÚÏßÂòÂôƽ̨µÄAliExpressÍøÕ¾£¬ÒÔ¼°200¶à¸ö·ÂÕÕ³ÛÃûÆ·ÅÆµÄÍøÕ¾£¬ÕâЩڲÆÐÔµÄÍøÕ¾¿ÉÄÜÊÇΪÁËÏúÊÛ¼ÙðÉÌÆ·£¬Ò²¿ÉÄÜÊÇΪÁË͵ÇÔÓû§µÄÒøÐп¨Êý¾Ý¼°½ðÇ®¡£¹¥»÷Õ߸´ÔìÁËÕæÊµÍøÕ¾µÄÆ·ÅÆ¡¢logoÒÔ¼°É«²Ê£¬²¢×¢²áÀàËÆµÄÓòÃûÀ´Îóµ¼Ïû·ÑÕß¡£ÕâÖÖÍøÕ¾µÄ½Ó¼ûÁ¿¿É´ïÿ¸öÔÂ20ÍòÈ˴Ρ£Æ¾¾ÝGroup-IBµÄͳ¼Æ£¬¾ùÔÈÿ¸ö¶íÂÞ˹ÈËÔÚ¼ÙðÉÌÆ·ÉÏÆÆ·ÑÁË5300¬²¼¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.ru/blog/blackfridaysale2¡¢°²È«³§ÉÌ·¢ÏÖºÚÎåÆÚ¼äEmotetµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯
ESET·¢ÏÖÓëºÚÎ幺Îï¼¾ÓйصÄEmotet´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£Óë֮ǰµÄ¹¥»÷Ïà±È£¬EmotetÉÔ΢ŤתÁËËûÃǵÄ×÷°¸ÊÖ·¨¡£¹ÌÈ»ÓÐЧºÉÔØÒÀÈ»ÊÇͨ¹ýÀ¬»øÓʼþÖеĸ½¼þºÍ¶ñÒâÁ´½ÓÀ´½»¸¶£¬µ«ÔÚºÚÎåÆÚ¼ä£¬ÕâЩ¶ñÒâÎļþÊÇÀ©´óÃûΪ.docµÄXMLÎļþ£¬¶ø²»ÊÇ֮ǰµÄdocºÍpdfÎļþ¡£¸Ã¶ñÒâ»î¶¯µÄÓÐЧºÉÔØÊǸ÷ÀàÒøÐÐľÂí£¬Ô̺¬Ursnif¡¢TrickBotºÍIcedId¡£À¶¡ÃÀÖÞÊÇÊÜÓ°Ïì×î´óµÄ¹ú¶È£¬Æä´ÎÊÇÄ«Î÷¸ç¡¢¶ò¹Ï¶à¶û¡¢°¢¸ùÍ¢ºÍÃÀ¹ú¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/black-friday-special-emotet-filling-inboxes-infected-xml-macros/3¡¢×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÒôÀÖ·þÎñƽ̨SpotifyµÄÍøÂç´¹µö¹¥»÷
AppRiverµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶ÔÔÚÏßÒôÀÖ·þÎñSpotifyÓû§µÄÍøÂç´¹µö¹¥»÷¡£ÕâЩÀ¬»øÓʼþÊÔͼͨ¹ýºýŪÓû§µã»÷ÓʼþÖеĴ¹µöÁ´½Ó£¬½«Óû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾£¬²¢ÒýÓÕÓû§ÊäÈëÓû§ÃûºÍÃÜÂë¡£ÈôÊÇÓû§ÔÚÆäËüÍøÕ¾ÉÏ£¨ÀýÈçÍøÉÏÒøÐУ©Ê¹ÓÃÁËÒ»ÑùµÄÍ´´¦£¬ÄÇôÓû§¿ÉÄÜÔÚײ¿â¹¥»÷ÖÐÊܵ½¸ü´óµÄÇÖº¦¡£¹ÌÈ»´¹µöÍøÕ¾µÄµÇÂ¼Ò³ÃæÓë¹ÙÍøspotify.comÀàËÆ£¬µ«Óû§ÒÀÈ»Äܹ»´ÓÓʼþµÄ·¢¼þÈË¡¢ÍøÕ¾µÄURLÖзֱæ³ö´¹µöÍøÕ¾£¬Ô¤·ÀÊܵ½Ëðʧ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spotify-phishers-hijack-music-fans-accounts/139329/4¡¢21ËêºÚ¿ÍÈëÇÖ¹è¹È¶àÃû¸ß¹ÙµÄÊÖ»ú£¬ÇÔÈ¡¼ÛÖµ100ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò
ƾ¾ÝÃÀ¹ú¼ì·½±¾ÔÂÏò¼ÓÖÝ·¨ÔºÌá½»µÄÒ»·ÝÎļþ£¬21ËêµÄNicholas TrugliaʹÓÃÒ»ÖÖ±»³ÆÎªSIM¿¨»¥»»µÄÕ½ÊõÈëÇÖÁ˶àÃû¹è¹È¸ß¹ÜµÄÊÖ»ú£¬²¢´ÓRobert RossµÄCoinbaseºÍGeminiÕË»§Æ½±ðÀëÇÔÈ¡ÁË50ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¸ÃÎļþÏÔʾTrugliaÒѱ»Ö¸¿Ø21Ïî×ïÃû£¬Ô̺¬Éí·Ý͵ÇÔ¡¢Ú²Æ¡¢Å²Óù«¿î¡¢³Á´ó͵ÇÔδËìµÈ¡£SIM¿¨»¥»»ÊÇÖ¸·¸×ï·Ö×Ó¼Ù×°³ÉÊܺ¦Õߣ¬ºýŪÔËÓªÉ̽«Êܺ¦ÕßµÄÊÖ»úºÅÂë³ÁзÖÅ䏸¹¥»÷ÕßÕ¼ÓеÄSIM¿¨µÄÕ½Êõ¡£¸Ã¹ý³ÌÖз¸×ï·Ö×Ó±ØÒª»Ø¸²Ò»Ð©ÓÃÓÚÑéÖ¤Éí·ÝµÄ°²È«ÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/new-yorker-accused-stealing-1m-sim-swap/5¡¢ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÉæÏÓ´«²¼DarkComet RATµÄÏÓÒÉ·¸
ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÁËÒ»ÃûÉæÏÓ´«²¼DarkComet RATµÄ42ËêÄÐ×Ó£¬¸ÃÄÐ×Ó±»Ö¸¿ØÊ¹ÓÃDarkCometϰȾÁË50¶à¸ö¹ú¶ÈµÄ³¬¹ý2000ÃûÊܺ¦Õß¡£¸ÃÄÐ×ÓÔÚÎÚ¿ËÀ¼Î÷²¿ÀûÎÖ·òÊеļÒÖб»²¶¡£ÎÚ¿ËÀ¼¾¯·½°µÊ¾ËûÃÇÔÚÏÓÒÉÈ˵ÄÍÆËã»úÉÏ·¢ÏÖÁËDarkCommet RATµÄÖÎÀíÃæ°å£¬²¢ÕÒµ½ÁËDarkCommetµÄ×°ÖÃÎļþÒÔ¼°Êܺ¦ÕßÍÆËã»úµÄÆÁÄ»½ØÍ¼¡£¸ÃÏÓ·¸ÏÖʵÉÏ·¸ÁËÒ»¸öOpSecÃýÎó£¬Ëû½«DarkCometÖÎÀíÃæ°åÖ±½Ó·ÅÔÚ¼ÒÀïµÄÍÆËã»úÉÏ£¬Ê¹µÃ¾¯·½ºÜÈÝÒ×¶¨Î»µ½ÆäÉí·Ý¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ukrainian-police-arrest-hacker-who-infected-over-2000-users-with-darkcomet-rat/6¡¢×êÑÐÈËÔ±·¢ÏÖÖ¼ÔÚϰȾWindowsϵͳµÄжñÒâÈí¼þL0rdix
EnSilo×êÑÐÈËÔ±Ben Hunter·¢´Ë¿Ì°µÍøÂÛ̳ÉϳöÏÖÁËÒ»¸öеĶñÒâÈí¼þL0rdix£¬¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔWindowsϵͳ£¬½áºÏÁËÊý¾ÝÇÔÈ¡ºÍ¶ñÒâÍÚ¿óÖ°ÄÜ£¬²¢ÇÒÄܹ»ÌӱܶñÒâÈí¼þ·ÖÎö¹¤¾ß¡£L0rdix¹ÌÈ»ÒÑÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ£¬µ«ÈÔÓÐһЩ֤¾ÝÅú×¢¸Ã¶ñÒâÈí¼þ»¹ÔÚ¿ª·¢¹ý³ÌÖС£L0rdixʹÓÃ.NET±àд£¬Ê¹ÓÃConfuserExºÍ.NETGuard½øÐлìºÏ£¬²¢Í¨¹ýWMI²éÎʺÍ×¢²á±íÏîÀ´¼ì²âÊÇ·ñɳÏä»·¾³¡£EnSiloÔ¤¼Æ½«»á¿´µ½¸Ã¶ñÒâÈí¼þµÄ¸ü¶à¸´ÔÓ°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://blog.ensilo.com/l0rdix-attack-toolÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ