¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»IT·þÎñ¹«Ë¾CognizantÔâMaze¹¥»÷£¬¿Í»§Êý¾Ý¿ÉÄÜй¶

°ä²¼¹¦·ò 2020-04-20

1.¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôó³ÛÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ ¡£¾ÝZDNet±¨Â·£¬ºÚ¿ÍÊÇÀûÓÃÍøÕ¾ÖеÄSQL×¢Èë·ì϶ÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬¾Ý³Æ¸Ã·ì϶µÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳Öд«²¼Á˼¸¸öÔ ¡£ºÚ¿Í¿ÉÄÜ»¹µÁÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØÖ· ¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­½¨¸´Á˺ڿÍʹÓõķì϶£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ½øÐлØÓ¦ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2.ºÚ¿ÍÀûÓÃCOVID-19ÓïÒô´¹µöÓʼþ¹¥»÷Office 365Óû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝPhishLabs×êÑз¢ÏÖ£¬ºÚ¿ÍÔÚÀûÓÃÒÔ COVID-19ΪÖ÷ÌâµÄÓïÒôÓʼþ¶ÔOffice 365Óû§ÌáÒéÍøÂç´¹µö¹¥»÷£¬ÒÔÇÔÈ¡Óû§µÄµÇ½ƾ֤ ¡£¸ÃÓʼþÔ̺¬Ò»¸öÃûΪATT30406µÄÐéαÒôƵÎļþ£¬ÎļþÖаµ²ØÓÐÒ»¸öÁ´½Ó£¬¶øµ±Óû§µã»÷´ËÎļþʱ£¬½«±»¶¨Ïòµ½±ØÒªµÇ¼ʹ´¦µÄMicrosoft Office 365£¨O365£©ÍøÂç´¹µöÒ³Ãæ ¡£²¢ÇÒ£¬ºÚ¿ÍÀûÓÃ.htmµÄÎļþÌåʽÀ´°µ²Ø¸Ã¶ñÒâÁ´½Ó£¬¼Ù×°³ÉÓïÒôÓʼþµÄ³£¼ûÒôƵ¸½¼þÓÕʹÓû§´ò¿ª ¡£


Ô­ÎÄÁ´½Ó£º

https://securityboulevard.com/2020/04/covid-19-phishing-update-voicemail-attacks-surface-targeting-office-365-users/


3.IT·þÎñ¹«Ë¾CognizantÔâMaze¹¥»÷£¬¿Í»§Êý¾Ý¿ÉÄÜй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


IT·þÎñ¹«Ë¾CognizantÓÚÉÏÖÜÎåÍíÉÏÔâµ½ÁËMaze RansomwareÍÅ»ïµÄ¹¥»÷£¬Æä¿Í»§Êý¾Ý¿ÉÄÜй¶ ¡£Cognizant°µÊ¾£¬Õâ´Î¹¥»÷µ¼ÖÂijЩ¿Í»§µÄ·þÎñ±»ÖжÏ£¬¶ø¹«Ë¾Ò²ÔÚ»ý¼«²ÉÈ¡´ëÊ©½â¾ö´ËÊ ¡£¹ÌÈ»MazeÍÅ»ïÁÙʱ·ñ¶¨ÁËÕâÒ»¹¥»÷ÊÂÎñ£¬µ«Æ¾¾ÝCognizant¹«Ë¾Ïò¿Í»§°ä²¼µÄIoCÁбí£¬Äܹ»È·ÈÏÕâЩIoCÓëMazeÓйØ ¡£¸ÃIoCÁбíÔ̺¬C2·þÎñÆ÷µÄIPµØÖ·ÒÔ¼°kepstl32.dll¡¢memes.tmpºÍmaze.dllÎļþµÄÎļþ¹þÏ£ ¡£×êÑÐÈËÔ±ÒÔΪ£¬MazeºÚ¿Í¿ÉÄÜÒѾ­ÔÚCognizantµÄÍøÂçÖÐÂñ·üÁËÊýÖÜÖ®¾Ã£¬²¢ÇÒÔÚµÁÈ¡Îļþºó²ÅʹÓÃPowerShell EmpireµÈ¹¤¾ß²¿ÊðÀÕË÷Èí¼þ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/it-services-giant-cognizant-suffers-maze-ransomware-cyber-attack/


4.ÃÀ¹ú°ÂÀû°²ÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬ÊÐÕþϵͳÈÔδ¸´Ô­


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜÎåÔçÉÏ£¬ÃÀ¹ú°ÂÀû°²Êе±¾Ö°ä·¢ÆäÊÐÕþϵͳÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬´ó²¿ÃÅÍÆËã»úϵͳÀëÏßÔ¼ÎåÓ×ʱ£¬µ«Ä¿Ç°ÏµÍ³ÈÔδÆëÈ«½¨¸´ ¡£¸ÃÊÐÊг¤Bill Aiello°µÊ¾£¬ºÚ¿ÍÊÇͨ¹ýһ̨ÀϾɵġ¢Ã»ÓÐʵʱ¸üÐÂÉý¼¶µÄ·þÎñÆ÷ÌáÒé¹¥»÷µÄ ¡£AielloÖ¸³öºÚ¿ÍûÓдӸÃÊеÄϵͳÖнӼû»òÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬²¢ÇÒË®Îñ·þÎñµÄÃÅ»§Ö§¸¶ÍøÕ¾ÈÔÔÚÕý³£ÔËÓª ¡£¸ÃÊÐÔ±¹¤µÄµç×ÓÓʼþ¾ùÒѱ¸·Ý£¬ÊÐÕþϵͳԤ¼ÆÔÚ±¾ÖܻᱻÆëÈ«½¨¸´ ¡£


Ô­ÎÄÁ´½Ó£º

http://www.oleantimesherald.com/news/ransomware-attack-temporarily-knocks-out-olean-city-systems/article_2fdf240f-4e44-54bb-af36-65d5fbc730c8.html


5.ÒøÐÐľÂíUrsnifбäÖÖ£¬ÖØÒªÕë¶ÔÒâ´óÀûÆóÒµ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Yoroi×êÑз¢ÏÖÁËÒ»ÖÖÕë¶ÔÒâ´óÀûÆóÒµµÄÒøÐÐľÂíUrsnifбäÖÖ ¡£´Ë±äÖÖÖØÒªÊÇʹÓÃÍøÂç´¹µöÕ½Êõ£¬·¢ËÍ´øÓÓ×°Avviso di Pagamento_xxxx_date¡±¸½¼þµÄÀ¬»øÓʼþ ¡£Ïà±ÈUrsnif¼Ò×åµÄÆäËû±äÖÖ£¬Ð±äÖÖ¹²ÓÐÁ½¸ö³ÁÒªµÄÉý¼¶£¬Ê×ÏÈËüʹÓÃ΢ÈíExcel 4.0ºêÀ´Ìӱܲ¡¶¾¼à²âºÍ·ÖÎö£¬Áí±í£¬ËüÓµÓÐÁ½¸ö·ÖÆçµÄC2£¬ÆäÖÐÒ»¸öC2Ö»ÓÃÓÚ×¢²áUUIDÀ´±êʶºÍ¸ú×ÙÖ¸±ê»úе ¡£


Ô­ÎÄÁ´½Ó£º

https://yoroi.company/research/a-brand-new-ursnif-isfb-campaign-targets-italian-organizations/


6.΢Èíµ·»ÙÒÑϰȾ40ÍòÉ豸µÄ½©Ê¬ÍøÂç



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí°µÊ¾ÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©·¢ÏÖ²¢Ô®ÊÖ·ÛËéÁËÒÑϰȾ40Íǫ̀É豸µÄ½©Ê¬ÍøÂ磬¸Ã½©Ê¬ÍøÂçµÄC2·þÎñÆ÷ÊÇLEDµÆµÄ½ÚÔį̀ ¡£¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚ¸÷ÀàÖ÷ÕÅ£¬Ô̺¬´¹µö¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢ÀÕË÷Èí¼þpayload½»¸¶ÒÔ¼°ÌáÒéDDoS¹¥»÷µÈ ¡£Î¢Èí°µÊ¾¸Ã½©Ê¬ÍøÂçÿÖÜ·¢Ë͵ĶñÒâÄÚÈݶà´ï1TB ¡£×Ô2010ÄêÒÔÀ´£¬Î¢ÈíDCUÍŶÓÒÑÔÚÈ«ÇòISP¡¢ÓòÃû×¢²á»ú¹¹¡¢CERTºÍ·¨ÂÉ»ú¹¹µÄÔ®ÊÖϹعØÁË22¸ö½©Ê¬ÍøÂç ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-helped-stop-a-botnet-controlled-via-an-led-light-console/