Õë¶Ô¶à¹úµ±¾ÖÍøÂçµÄ´¹µö»î¶¯ÊÂÎñ·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-16

ÊÂÎñ¸ÅÊö


½üÈÕ£¬Òì³£Íþв×êÑÐÓ××é·¢ÏÖÁËÒ»ÏîеÄÍøÂç´¹µö»î¶¯£¬Ö¼ÔÚ´ÓÃÀ¡¢Å·ÖÞºÍÑÇÖÞÈ·µ±²¿ÃÅÃÅÇÔÈ¡µÇ¼ʹ´¦£¬Ä¿Ç°Éв»Ã÷ÏÔÄ»ºóºÚÊÖÊÇË­£¬µ«¿´À´µÄÈ·ÊdzÖÐøµÄ¹¥»÷¡£ºýŪÐÔÍøÂç´¹µöÕ¾µãÓòÍйÜÔÚÍÁ¶úÆäºÍÂÞÂíÄáÑÇ£¬¸Ã»î¶¯Ä¿Ç°´¦ÓÚÐÝÃß״̬¡£


×ÜÌå¶øÑÔ£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Öйú¡¢°Ä´óÀûÑÇ¡¢ÈðµäµÈ¹ú¶ÈÖеÄ22¸ö×éÖ¯ÒѾ­Ã÷È·Ôâ·êÕâ´ÎÍøÂç´¹µö¹¥»÷¡£¹¥»÷·½Ê½¶¼²î²»¶à£¬Éæ¼°ÓëÖ¸±êµ±¾Ö»ú¹¹Óйصĵç×ÓÓʼþ£¬ºýŪÊܺ¦Õßµã»÷µç×ÓÓʼþÁ´½Ó£¬¶øºóÊäÈëÆäÓû§ÃûºÍÃÜÂë¡£


Òì³£Íþв×êÑÐÓ××éÈ·¶¨ÁËÒ»ÏîÆ¾Ö¤ÍøÂç»î¶¯£¬Ö¼ÔÚ´Ó¶à¸öµ±¾Ö²É¹º·þÎñÖÐÇÔÈ¡µÇ¼¾ßÌåÐÅÏ¢¡£ºÜ¶à¹«¹²ºÍ˽Ӫ²¿ÃÅ×éÖ¯¶¼Ê¹Óòɹº·þÎñÀ´Æ¥ÅäÂò¼ÒºÍ¹©¸øÉÌ¡£Ôڴ˻ÖУ¬¹¥»÷ÕߺýŪÁ˶à¸ö¹ú¼Êµ±²¿ÃÅÃÅ£¬µç×ÓÓʼþ·þÎñºÍÁ½¸ö¿ìµÝ·þÎñµÄÕ¾µã¡£·¢ÏÖͨ¹ýÍøÂç´¹µöµç×ÓÓʼþ·¢Ë͵ĵö¶üÎĵµÔ̺¬Ö¸ÏòºýŪÐÔÍøÂç´¹µöÕ¾µãµÄÁ´½Ó£¬ÕâЩÁ´½Ó¼Ù×°³ÉÓëºýŪÐÔµ±¾Ö»ú¹¹ÓйصĺϷ¨µÇÂ¼Ò³Ãæ¡£¶øºó£¬ÓÕʹ±»ÓÕÆ­Õß×·×ÙÍøÂç´¹µöµç×ÓÓʼþÁ´½ÓµÄÊܺ¦ÕߵǼ¡£³ÉΪµÐÊÖÊܺ¦ÕßµÄÈκÎÈ˶¼½«ÏòËûÃÇÌṩʹ´¦¡£


ÊÂÎñÓ°Ïì


   ÊÜÓ°ÏìµÄ×éÖ¯Ô̺¬£º

ÃÀ¹ú-ÃÀ¹úÄÜÔ´²¿

ÃÀ¹ú-ÃÀ¹úÉÌÎñ²¿

ÃÀ¹ú-ÃÀ¹úÍËÒÛÎäÊ¿ÊÂÎñ²¿

ÃÀ¹ú-ÐÂÔóÎ÷ÖÝ·¿Îݼ°µÖѺ½ðÈÚ¾Ö

ÃÀ¹ú-ÂíÀïÀ¼Öݵ±¾Ö²É¹º·þÎñ

ÃÀ¹ú-·ðÂÞÀï´ïÖÎÀí·þÎñ²¿

ÃÀ¹ú-½»Í¨²¿

ÃÀ¹ú-ס·¿ºÍ³ÇÊз¢Õ¹²¿

DHL¹ú¼Ê¿ìµÝ·þÎñ

¼ÓÄôó-µ±¾Öµç×Ӳɹº·þÎñ

Ä«Î÷¸ç-µ±¾Öµç×Ӳɹº·þÎñ

ÃØÂ³-¹«¹²²É¹ºÖÐÐÄ

Öйú-˳·á¿ìµÝ·þÎñ

Öйú-½»Í¨ÔËÊ䲿

ÈÕ±¾-¾­¼Ã²úҵʡ

ÐÂ¼ÓÆÂ-¹¤ÒµºÍÒµÎñ²¿

ÂíÀ´Î÷ÑÇ-¹ú¼ÊÒµÎñºÍ¹¤Òµ²¿

°Ä´óÀûÑÇ-µ±¾Öµç×ӲɹºÃÅ»§

Èðµä-µ±¾Ö»ú¹Ø¹ú¶È¹«¹²²É¹º¾Ö

²¨À¼-ÒµÎñºÍͶ×ÊÊð


Ö¸±ê¹ú¶È£º

   Í¼1ÖеÄÈÈͼÏÔʾ£¬ÃÀ¹úÖØÒªÊÇÕë¶ÔÐԵģ¬ÓÐ50¶à¸ö´¹µöÍøÕ¾Ö¼ÔÚÇÔÈ¡ºýŪÃÀ¹ú×éÖ¯µÄÍ´´¦¡£¼ÓÄôó£¬ÈÕ±¾ºÍ²¨À¼±ðÀë½ôËæÆäºóµÄ±ðÀëÊÇ7¡¢6ºÍ6¸ö´¹µöÍøÕ¾¡£´Ë»î¶¯µÄÖ¸±ê¹ú¶ÈÊÇ£º

ÃÀ¹ú

Öйú

ÐÂ¼ÓÆÂ

Èðµä

ÄÏ·Ç

Ä«Î÷¸ç

ÈÕ±¾

ÂíÀ´Î÷ÑÇ

²¨À¼

ÃØÂ³

¼ÓÄôó

°Ä´óÀûÑÇ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ1.ÒÔµ±¾Ö²É¹ºÕ¾µãΪָ±êµÄÍøÂç´¹µöÕ¾µãµÄ¹ú¶ÈÈÈͼ


Ö¸±êÐÐÒµ£º

´Ë»î¶¯Õë¶ÔÒÔÏÂÐÐÒµ£ºÍ¼2ÏÔʾ£¬µ±¾ÖÃÅ»§ÍøÕ¾ÖÐרÃÅÓÃÓÚÇÔȡʹ´¦µÄ´¹µöÍøÕ¾ÊýÁ¿×î¶à¡£

µ±¾Ö

µçÓÊ·þÎñ

ËÍ»õ£¬ÓʷѺÍÔËÊä


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ2.±ýͼÏÔʾÁ˰´ÐÐÒµ»®·ÖµÄºýŪ×éÖ¯µÄÊýÁ¿


ÊÂÎñ·ÖÎö


µö¶üÎļþ£º


´Ë»î¶¯µÄÖ¸±êÊܺ¦ÕߺܿÉÄÜÔÚÍøÂç´¹µöµç×ÓÓʼþÖз¢ËÍÁ˵ö¶üÎļþ¡£µö¶üÎļþÖ¼ÔÚͶºÏÆäÖ¸±êµ±¾ÖµØµã¹ú¶È/µØÓòµÄ˵»°¡£ÄϷǵö¶üÎļþÊÇÓÃÓ¢ÓïдµÄ£¬µ«ÄÏ·ÇÊǶàÖÖ˵»°£¨Ô̺¬Ó¢ÓµÄµØµãµØ¡£Í¼3ÏÔʾÁË·¢Ïֵĵö¶üÎļþµÄһЩʾÀý¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ3.¸Ã»î¶¯Öй۲쵽µÄµö¶üÎļþ


ÉÏÃæµÄµö¶üÎĵµÔ̺¬Ò»¸öǶÈëʽÁ´½Ó£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4. pdfÎĵµÖеÄǶÈëʽÁ´½ÓÓÕÆ­ÁËÃÀ¹úÉÌÎñ²¿


ÉÏÃæµÄPDFÎļþÃûITB_USDOC.pdfÖеÄÁ´½Ó£¨Í¼4£©ÓµÓÐÒ»¸öǶÈëʽÁ´½Ó£¬¸ÃÁ´½Ó½«Êܺ¦Õß¶¨Ïòµ½ÍйÜÔÚ¶ñÒâÓò¡°40-71.xyz¡±ÉϵÄÍøÂç´¹µöÒ³Ãæ¡£¸ÃÎĵµÒÑÌá½»¸øÃÀ¹úºÍ·¨¹úµÄVirusTotal£¨×÷Ϊµç×ÓÓʼþµÄÒ»²¿ÃÅ£¬µ«¸Ãµç×ÓÓʼþ²»³ÉÓã©¡£


Æ¾Ö¤ÍøÂçÕ¾µã


ËùÓÐÕ¾µã¶¼Ê¹Óá°cPanel£¬Inc¡±Ðû¸æµÄÓòÑéÖ¤£¨DV£©Ö¤Êé¡£×ÓÓòÓµÓÐÀàËÆµÄ¶¨ÃûÔ¼¶¨£¬ÒÔÔÚÏßÍ´´¦ÎªÖ¸±ê£¬²¢Ô̺¬°²È«£¬ÑéÖ¤£¬³ö¼Û»ò½»¸¶Ö÷Ì⡣ͼ5ÏÔʾÁ˹¥»÷Õß´´½¨µÄÆ¾Ö¤ÍøÂçÒ³ÃæµÄʾÀý¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5.ÔڸûÖй۲쵽µÄÆ¾Ö¤ÍøÂçÕ¾µã


ÍøÒ³ÉÏÓÐÇ峺µÄ±êÖ¾ºÍ±êÇ©£¬¾ßÌå˵ÁËÈ»¹¥»÷ÕßÊÔͼ·ÂÕÕµÄ×éÖ¯¡£¹¥»÷ÕßʹÓÃÁ˺Ϸ¨ÓòÒÔ¼°×Ô¼ºµÄ»ù´¡½á¹¹¡£ÃÀ¹úÄÜÔ´²¿µÄÍøÒ³ÍйÜÔÚ¡°https£º//energy.gov.secure.server-bidsync.best/auth/login.html¡±ÉÏ£¬²¢´ÓÒÔÏÂÍøÖ·³Á¶¨Ïò£º


¡°http://energy.gov.secure.bidsync.newnepaltreks.com¡±¡£³Á¶¨ÏòURL»ùÓںϷ¨ÓòÃû¡°newnepaltreks.com¡±£¬¸ÃÓòÃûºÜ¿ÉÄÜÒѱ»Ð¹ÃÜ£¬ÒÔÖúÓÚ½øÐд˹¥»÷¡£


Íþв»ù´¡¼Ü¹¹


ÔÚµ÷²é¹ý³ÌÖУ¬·¢ÏÖÁË62¸öÓòºÍԼĪ122¸öÍøÂç´¹µöÕ¾µã¡£ÓòÉÏÍйܵÄËùÓÐÍøÂç´¹µöÕ¾µã¶¼ÓµÓÐÀàËÆµÄ¶¨ÃûÔ¼¶¨£º

Ö¸±êÓò»ò·þÎñдΪ×ÓÓò£¬ºó¸ú¶ñÒâÓò»òÊÜϰȾµÄ·þÎñÆ÷¡£


Éí·ÝÑéÖ¤£¬³ö¼Ûͬ²½£¬²É¹º»ò½»¸¶Ö÷Ìâ


ÍøÂç´¹µöÕ¾µãÖØÒªÍйÜÔÚÒÔÏÂËĸöIPµØÖ·ÉϵÄ×âÓûù´¡½á¹¹ÉÏ£º


31.210.96.221

193.29.187.173

91.235.116.146

188.241.58.170


¶Ô×î³õÈ·¶¨µÄÓò¡°server-bidsync.best¡±µÄµ÷²éÈ·¶¨ÁË´Ó¿Í»§¶Ëä¯ÀÀÆ÷µ½¶ñÒâÓòµÄͨѶÖеÄ×ÊÔ´¹þÏ£¡£µ÷²éÁ˶Ôhttps£º//energy.gov.secure.server-bidsync.best/auth/alter.cssµÄGETÒªÇó£¬ÐÎ×´´ó¾Ö¡°alter.css¡±£¬²¢ÇÒCSS¾ç±¾cd9dcb1922df26eb999a4405b282809051a18f8aa6e68edb71d619c92ebcf82dµÄ×ÊÔ´¹þÏ£Öµµ¼ÖÂ14ÍйÜÀàËÆÍøÂç´¹µöÕ¾µãµÄÐÂÓò¡£ÔںܶàÇé¿öÏ£¬×ÓÓòµÄ±àд·½Ê½ÆëȫһÑù£¬´Ó¶øºýŪÁ˸ոÕÍйÜÔÚ·ÖÆçÓòÖеÄͳһ×éÖ¯¡£Ê¹Óö¨ÃûÔ¼¶¨Ä£Ê½ºÍÐÂÓò×÷Ϊ½øÒ»²½µÄÊàŦµã£¬µ¼Ö·¢ÏÖÁËÕë¶Ô½øÒ»²½µ±¾Ö²É¹º·þÎñµÄÍøÂç´¹µöÕ¾µã¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ6.ºýŪ×éÖ¯µÄ»ù´¡½á¹¹¸ÅÊö


IPµØÖ·Îª31.210.96.221Íйܴ˻µÄÍøÂç´¹µöÍøÕ¾µÄÓòÓÚ2019Äê10ÔÂ28ÈÕ³õ´Î×¢²á£¬ÓòÃûÒÔserver-bidsync.bestÆðÍ·¡£¸ÃIPµØÖ·ÒÑÔÚÍÁ¶úÆä×¢²á£¬²¢ÇÒ´ÓÇ°Ôø²Î¼Ó¶ñÒâ»î¶¯¡£ÆäÖÐ×î͹ÆðµÄÊÇ¡°leastinfo.com¡±Óò£¬¸ÃÓòÔÚÒ»´ÎÕë¶ÔÑÇÖÞ½ðÈÚ»ú¹¹ÒÔ¼°ÎÚ¶û¶¼ÓïºÍ°¢À­²®ÓïʹÓÃÕßʹÓõÄÈí¼þµÄÁãÈÕ·ì϶¹¥»÷»î¶¯ÖгöÏÖ¡£ÆäËûÈý¸öIPµØÖ·¶¼ÔÚÂÞÂíÄáÑÇ×¢²á¡£×éÖ¯»¹±»¼ÙðÔںϷ¨Óò¡°newnepaltreks.com¡±£¬¡°lazapateriadematilda.cl¡±ºÍ¡°onsearch¡±ÖеÄÍøÂç´¹µöÍøÕ¾ËùºýŪ£¬ÕâÐ©ÍøÕ¾¿ÉÄÜÒѾ­Êܵ½·ÛËé¡£


ÊÂÎñ½áÂÛ


ÕâÏîÆ¾Ö¤ÍøÂç»î¶¯ÖØÒªÕë¶Ôµ±¾ÖÕбêºÍ²É¹º·þÎñ¡£¶ÔÕâЩ·þÎñµÄ¹Ø×¢Åú×¢£¬ÍþвÐÐΪÕß¶ÔÖ¸±êµ±¾ÖµÄDZÔڳаüÉ̺Í/¹©¸øÉ̸ÐÐËÖ¡£¸Ã¶´²ìÁ¦µÄÖ÷ÕÅ¿ÉÄÜÊÇΪÁËʹ¾ºÕùµÐÊÖʤ³ö¶ø²ÉÈ¡µÄ¾­¼Ã¼¤Àø´ëÊ©£¬»òÕßÊÇÓйØÇ±ÔÚ¹©¸øÉÌÓëÓйص±¾ÖÖ®¼äµÄÐÅÀµ¹ØÏµµÄ¸ü³Ö¾Ã¶´²ìÁ¦¡£ÖîÈç´ËÀàµÄ»î¶¯ºÜÄÑ·À±¸£¬ÓÉÓÚ³ý·ÇÍйÜÍøÂç´¹µöÒ³ÃæµÄÓò±»ÒÔΪÊǶñÒâµÄ£¬²»È»×éÖ¯·À»ðǽ½«²»»á×èÖ¹Ëü¡£ºÏ·¨Õ¾µã»¹ÍйÜÁË´¹µöÒ³Ãæ£¬²¢ÇÒ¿ÉÄÜÔÚ¾ºÑ¡»î¶¯ÖÐÔâµ½·ÛËé¡£


²Î¿¼Á´½Ó


https://www.anomali.com/resources/whitepapers/phishing-campaign-targets-login-credentials-of-multiple-us-international-government-procurement-services