×êÑÐÈËÔ±°ä²¼¹¥»÷Ó¡¶ÈºËµçÕ¾µÄ¶ñÒâÑù±¾·ÖÎö»ã±¨ £»¼ÓÄôóÒþÖÔ± £»¤·¨°ä²¼Ò»ÄêºóÊÂÎñ»ã±¨Ôö³¤ÖÁÁù±¶

°ä²¼¹¦·ò 2019-11-05
1¡¢×êÑÐÈËÔ±°ä²¼¹¥»÷Ó¡¶ÈºËµçÕ¾µÄ¶ñÒâÑù±¾·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°²È«×¨¼ÒMarco Ramilli¼°ÆäÍŶӷÖÎöÁËϰȾӡ¶ÈKudankulamºËµçÕ¾µÄ¶ñÒâÑù±¾¡£¸ÃÑù±¾ÓÚ10ÔÂ28ÈÕ±»ÉÏ´«ÖÁVirus Total£¬ÊÇÒ»¸ö±àÒëÓÚ2019-07-29 13:36:26µÄ32λPEÎļþ£¬ËüÔÚÔËÐкóÖ´ÐÐÈý¸öÖØÒª²Ù×÷£¬Ô̺¬µ¼ÈëÖ°ÄÜÄ £¿é¡¢ÍøÂç±¾µØÐÅÏ¢¼°·¢ËÍÖÁÖÐÑë½Úµã¡£¸ÃÑù±¾ÍøÂçµÄÐÅÏ¢Ô̺¬±¾µØIPµØÖ·¡¢¹¤×÷ÁÐ±í¡¢Â·ÓɺͽӿÚÐÅÏ¢ÒÔ¼°Ô¤Éè´æ´¢ÔÚϵͳijЩ¾íÖеÄÈí¼þ¡£ÕâЩÐÅÏ¢×îºó±»·¢Ë͵½10.38.1.35£¬ÔÚ´úÂëÖгÆÎªcontroller5kk¡£RamilliÈ·ÈϸÃÑù±¾ÊǶ¨Ô컯µÄDTrack¶ñÒâÈí¼þ¡£
   ¡¢Ô­ÎÄÁ´½Ó£º
https://marcoramilli.com/2019/11/04/is-lazarus-apt38-targeting-critical-infrastructures/

2¡¢Î÷°àÑÀÁ½¼Ò¹«Ë¾ÔâÕë¶ÔÐÔÀÕË÷Èí¼þ¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Î÷°àÑÀ×î´óµÄÎÞÏßµçÍøÂçCadena SERºÍITÕ÷ѯ¹«Ë¾EverisÔâÀÕË÷Èí¼þ¹¥»÷¡£Î÷°àÑÀ¹ú¶È°²È«¾ÖÔÚÊÂÎñ²úÉúºóÊýÓ×ʱÄÚ°ä²¼Á˰²È«²¼¸æ£¬ÖҸ湫˾¸ÄÉÆÍøÂ簲ȫ´ëÊ©²¢¶½´ÙÆäËûÊܺ¦ÕßÏòINCIBE×·ÇóÔ®ÊÖ¡£¾ÝÎ÷°àÑÀÍøÂ簲ȫÕÕ·÷³Æ£¬Everis±»¼ÓÃܵÄÎļþÀ©´óÃûΪ.3v3r1s£¬ÕâÅú×¢¸Ã¹¥»÷ÓµÓкÜÇ¿µÄÕë¶ÔÐÔ¡£¹¥»÷ÕßÒªÇóEverisÖ§¸¶75ÍòÅ·Ôª£¨83.5ÍòÃÀÔª£©µÄÊê½ð¡£VirusTotalÊ×´´ÈËÖ¸³ö¸ÃÀÕË÷Èí¼þ¿ÉÄÜÊÇBitPaymer/IEncrypt¡£Ä¿Ç°Éв»Ã÷ÏÔCadena SERÊÇ·ñΪͳһÀÕË÷Èí¼þµÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/everis-spain-ransomware-attack.html

3¡¢·ðÂÞÀï´ïÖݰ¿¨À­ÊÐÊÜBECÚ¿Æ­Ëðʧ74.2ÍòÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

·ðÂÞÀï´ïÖݵİ¿¨À­ÊгÉΪBECÚ¿Æ­µÄ×îÐÂÊܺ¦Õߣ¬Ú²Æ­Õß´Ó¸ÃÊÐÆ­×ßÁ˳¬¹ý74.2ÍòÃÀÔª¡£¸ÃÊÂÎñ²úÉúÔÚ9Ô·Ý£¬Ú²Æ­Õß¼Ù×°³ÉÔڰ¿¨À­¹ú¼Ê»ú³¡½¨Ôìк½Õ¾Â¥µÄ¹¹Öþ¹«Ë¾Ausley ConstructionµÄÒ»ÃûÔ±¹¤£¬Ïò¸ÃÊеĸ߼¶¹ÜÕÊÈËÔ±·¢ËÍÁËÔ̺¬Â·ÓɺÅÂë¡¢ÒøÐÐÕË»§ÒÔ¼°Ò»ÕÅÎÞЧ֧Ʊ¸±±¾µÄµç×ÓÓʼþ¡£¸ÃÓʼþÀ´×ÔÓÚausleyconstructions.com£¬¶øÕæÊµµÄµØÖ·Ä©Î²Ã»ÓÐs¡£µ±Ausley ConstructionÔÚ10ÔÂ22ÈÕ֪ͨ¸ÃÊиÿî×ÓÉÐδ֧¸¶Ê±£¬°Â¿¨À­Êвŷ¢ÏÖÇ®±»»ãÈëÁËڲƭÕßµÄÒøÐÐÕË»§¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bec-fraudsters-divert-742-000-from-ocala-city-in-florida/

4¡¢NunavutÔâÀÕË÷Èí¼þ¹¥»÷£¬ËùÓе±¾Öµ¥Ôª¾ùÊÜÓ°Ïì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôóNunavutÔâÀÕË÷Èí¼þ¹¥»÷£¬ËùÓе±¾Öµ¥Ôª¾ùÊÜÓ°Ï죬µ±¾Ö¹ÙÔ±°µÊ¾ÉÐÎÞ·¨Ô¤¼Æ·þÎñºÎʱ¸´Ô­ÉÏÏß¡£¸ÃÊÂÎñ²úÉúÔÚÖÜÁùÔ糿£¬±¾µØµ±¾ÖµÄËùÓеç×ÓÐÅϢϵͳ¾ùÊÜÓ°Ï죬Ա¹¤ÎÞ·¨µÇ¼Æäµ±¾ÖÕË»§£¬µç»°ÏµÍ³Ò²ÎÞ·¨Ê¹Ó㬵«¸ÃµØÓòµÄѧÌÃδÊÜÓ°Ïì¡£µ±¾Ö¹ÙÔ±°µÊ¾µ±Ç°ÉÐûÓжÔÓ×ÎÒÐÅÏ¢»òÒþÖÔÊý¾Ýй¶µÄÓÇÓô¡£

Ô­ÎÄÁ´½Ó£º
https://www.cbc.ca/news/canada/north/nunavut-government-ransomware-1.5346144

5¡¢¼ÓÄôóÒþÖÔ± £»¤·¨°ä²¼Ò»ÄêºóÊÂÎñ»ã±¨Ôö³¤ÖÁÁù±¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôó¡¶Ó×ÎÒÐÅÏ¢± £»¤ºÍµç×ÓÎļþ·¨¡·£¨PIPEDA£©ÓÚ2018Äê11ÔÂ1ÈÕÆðÖ´ÐУ¬Æ¾¾Ý¸Ã˾·¨£¬ÊÜÔ¼ÊøµÄÆóÒµ±ØÐëÏòÒþÖÔרԱ°ì¹«ÊÒ£¨OPC£©»ã±¨Êý¾Ýй¶ÊÂÎñ²¢Í¨ÖªÊÜÓ°ÏìµÄÓ×ÎÒ¡£ÔÚ´ÓǰµÄ12¸öÔÂÖУ¬¼ÓÄôóÊý¾Ýй¶»ã±¨µÄÊýÁ¿ÃÍÔö£¬OPC¹²ÊÕµ½ÁË680·Ý»ã±¨£¬ÊǸÃ˾·¨ÉúЧǰ12¸öÔÂÄÚÌá½»»ã±¨ÊýÁ¿µÄÁù±¶¡£Æ¾¾ÝÕâЩ»ã±¨£¬ÊÜÊý¾Ýй¶ӰÏìµÄ¼ÓÄôó¹«ÃñÊýÁ¿Ô¶Ô¶³¬¹ý2800Íò£¬»ã±¨µÄ´óÎÞÊýÎ¥¹æÊÂÎñ£¨58£¥£©É漰δ¾­ÊÚȨµÄ½Ó¼û¡£

Ô­ÎÄÁ´½Ó£º
https://www.priv.gc.ca/en/blog/20191031/

6¡¢2019ÄêÖÁÉÙ13¼ÒÍйܷþÎñÉ̱»ÓÃÓÚÍÆËÍÀÕË÷Èí¼þ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÍþвµý±¨³§ÉÌArmor°ä²¼µÄÒ»·Ýл㱨£¬2019ÄêÖÁÉÙÓÐ13¼ÒÍйܷþÎñÉÌ£¨MSP£©±»ºÚ¿ÍÓÃÓÚÍÆËÍÀÕË÷Èí¼þ¡£Ò»µ©ºÚ¿ÍÈëÇÖMSPµÄÍøÂ磬ËûÃǾÍÄܹ»Ê¹ÓÃÔ¶³Ì½Ó¼û¹¤¾ß½«ÀÕË÷Èí¼þ²¿Êðµ½Êý°Ù¼Ò¹«Ë¾/ÊýÇ§Ì¨ÍÆËã»úÉÏ¡£¸ÃÁбíÔ̺¬ApexÈËÁ¦×ÊÔ´ÖÎÀí¡¢CloudJumper¡¢IT By Design¡¢MetroList¡¢CorVel¡¢PM Consultants¡¢iNSYNQ¡¢TSM Consulting¡¢PerCSoft¡¢SCHOOLinSITES¡¢TrialWorks¡¢BillTrustÒÔ¼°Ò»¼Òδ֪µÄMSP¡£Armor°µÊ¾¿ÉÄÜ»¹Óиü¶àµÄMSPÈëÇÖÊÂÎñδ±»»ã±¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/at-least-13-managed-service-providers-were-used-to-push-ransomware-this-year/