ºÚ¿Íɾ³ýÊý°ÙÃûGit¿ª·¢ÕߵĴúÂë¿â£»200Ëù´óѧµÄУ԰É̵êϰȾMagecart£»AMC Networksй¶160ÍòÓû§Êý¾Ý

°ä²¼¹¦·ò 2019-05-05
1¡¢ºÚ¿Íɾ³ýÊý°ÙÃûGit¿ª·¢ÕߵĴúÂë¿â£¬ÓûÀÕË÷Êê½ð

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ºÚ¿Í¶Ô×¼Êý°ÙÃûGitHub¡¢GitLabºÍBitbucketÓû§£¬É¾³ýÆä´úÂë¿â²¢ÀÕË÷Êê½ð¡£×êÑÐÈËÔ±ÔÚGitHubÉÏ·¢ÏÖ392¸ö´úÂë¿âÊܵ½Ó°Ï죬ÕâЩ´úÂë¿â¾ù±»Ò»¸öÆßÄêǰ£¨2012Äê1ÔÂ25ÈÕ£©´´½¨µÄÕ˺Ågitbackupɾ³ý¡£¹¥»÷ÕßÒªÇóÖ§¸¶0.1±ÈÌØ±Ò£¨Ô¼568ÃÀÔª£©µÄÊê½ð£¬µ«½ØÖÁĿǰ²¢Ã»ÓÐÊܺ¦ÕßÖ§¸¶Êê½ð¡£StackExchange°²È«ÂÛ̳µÄ³ÉÔ±·¢ÏÖºÚ¿ÍÏÖʵÉϲ¢Î´É¾³ý´úÂë¿â£¬½ö½öÊÇŤתÁËgit commit±êÍ·£¬ÕâÒâζ×ÅijЩÇé¿öÏÂÄܹ»¸´Ô­´úÂë¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/attackers-wiping-github-and-gitlab-repos-leave-ransom-notes/

2¡¢³¬¹ý200Ëù´óѧµÄУ԰É̵êϰȾMagecart¶ñÒâ¾ç±¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
³¬¹ý200ËùÃÀ¹úºÍ¼ÓÄôó´óѧµÄÔÚÏßУ԰É̵êÔâµ½Magecart¹¥»÷£¬ÕâÐ©ÍøÕ¾ÓÉPrismWebµç×ÓÉÌÎñƽ̨Ìṩ֧³Ö£¬µ«PrismWebÓÚ4ÔÂ14ÈÕ±»×¢Èë¶ñÒâµÄMagecart¾ç±¾¡£¸ÃJavaScript¾ç±¾ÓÃÓÚÇÔÈ¡¿Í»§µÄÖ§¸¶ÐÅÏ¢ºÍÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÅÓþ¿¨ºÅ¡¢ÓÐЧÆÚ¡¢¿¨ÀàÐÍ¡¢ÑéÖ¤ºÅÂ루CVN£©ÒÔ¼°³Ö¿¨È˵ÄÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂëµÈÓ×ÎÒÐÅÏ¢¡£¹¥»÷ÕßÍøÂçÕâЩÐÅÏ¢ºó½«ÐÅÏ¢´æ´¢ÎªJSONÌåʽ£¬¾­¹ýAES¼ÓÃܺͱàÂëºó£¬×÷ΪHTMLͼÏñÔªËØµÄURL²ÎÊý·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£Ç÷Ïò¿Æ¼¼µÄ×êÑÐÍŶÓÒÔΪ¸Ã¹©¸øÁ´¹¥»÷ÊÇÓÉеķ¸×ïÍÅ»ïMirrorthiefÌáÒéµÄ£¬Ä¿Ç°Éв»Ã÷ÏÔ¾ßÌåµÄÊÜÓ°ÏìÈËÊý¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-200-college-campus-stores-infected-with-card-stealing-scripts/

3¡¢×êÑÐÍŶӰ䲼ºóCoinhiveʱÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯·ÖÎö

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Malwarebytes Labs×êÑÐÍŶӰ䲼ºóCoinhiveʱÆÚµÄ¶ñÒâÍÚ¿ó»î¶¯·ÖÎö¡£CoinhiveÔÚ2019Äê3ÔÂ8ÈչعØÁË·þÎñ£¬µ«´óÁ¿µÄÍøÕ¾ºÍ·ÓÉÆ÷ÈÔ´æÔÚCoinhiveÒÅÁô£¬µ¼ÖÂÈÔ¶ÔCoinhive¿â·¢³öÒªÇó¡£ÔÚ´ÓǰһÖÜÄÚ£¬×êÑÐÍŶӾùÔÈÿÌì¼Í¼µ½5Íò¸öÕë¶ÔCoinhiveµÄÒªÇ󡣺ÃÐÂÎÅÊÇ£¬ÕâЩҪÇó½«ÎÞ·¨Ïνӵ½·þÎñÆ÷£¬´Ó¶ø²»ÄܽøÐÐÍÚ¿ó»î¶¯¡£µ«»ùÓÚÍøÂçµÄ¿ó¹¤²¢Î´ÖÕ³¡£¬ÀýÈçCoinhiveµÄ¾ºÕùµÐÊÖCryptoLoot¡¢CoinIMP£¬×êÑÐÍŶÓÿÌì³ÇÊмì²âµ½³¬¹ý100Íò´ÎÕë¶ÔCryptoLootµÄÒªÇó¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/

4¡¢ÒøÐÐľÂíRetefe¾íÍÁ³ÁÀ´£¬ÖØÒªÕë¶ÔÈðÊ¿ºÍµÂ¹ú

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
4Ô·ÝProofpoint×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíRetefeµÄ¹¥»÷ÊýÁ¿³ÊÉÏÉýÇ÷Ïò¡£¸Ã¶ñÒâÈí¼þÆðÍ·Õë¶ÔÈðÊ¿ºÍµÂ¹úµÄÒøÐÐÓû§£¬²»ÂÛÊÇWindows»¹ÊÇmacOSƽ̨¡£ÐµĹ¥»÷»î¶¯ÖÐRetefeÒ²¸ü¸ÄÁËһЩְÄÜ£¬ÀýÈçʹÓÃTLS/SSLËí··þÎñStunnel´úÌæTOR×÷Ϊ´úÀí³Á¶¨ÏòºÍC&CÉèÖÃͨ·¡£´Ë±í£¬ÒÔǰRetefe³£ÓëPowerShellÏÂÔØÆ÷sLoad¹ØÁª£¬µ«ÔÚÕë¶ÔÈðÊ¿µÄ¹¥»÷»î¶¯ÖиöñÒâÈí¼þʹÓÃSmoke Loader×÷ΪÖÐÑë½×¶ÎµÄÏÂÔØÆ÷¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.scmagazine.com/home/security-news/__trashed/

5¡¢ÐÂÀÕË÷Èí¼þMegaCortex£¬ÖØÒª¶Ô×¼ÆóÒµÍøÂç

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Sophos×êÑÐÍŶӷ¢ÏÖÖØÒª¶Ô×¼ÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þMegaCortex£¬¸ÃÀÕË÷Èí¼þÒÑϰȾÁËÃÀ¹ú¡¢Òâ´óÀû¡¢¼ÓÄô󡢷¨¹ú¡¢ºÉÀ¼ºÍ°®¶ûÀ¼µÄÓû§¡£ÓÉÓÚ¸ÃÀÕË÷Èí¼þÊÇгöÏֵģ¬Òò¶øÄ¿Ç°¶ÔÆä¼ÓÃÜËã·¨¡¢ÈôºÎ»ñµÃÆóÒµÍøÂçµÄ½Ó¼ûȨÏÞÒÔ¼°ÊÇ·ñÓÐÈËÖ§¸¶ÁËÊê½ðµÈÇé¿öÖªÖ®ÉõÉÙ¡£Sophos·¢ÏÖϰȾÁËMegaCortexµÄÆóÒµÍøÂçÉÏ´æÔÚEmotet»òQakbotľÂí£¬Òò¶ø¹¥»÷Õß¿ÉÄÜÊÇÏòľÂí¹¥»÷ÕßÖ§¸¶ÓöÈÒÔ»ñµÃ½Ó¼ûȨÏÞ¡£Ò»µ©½øÈëÍøÂ磬¹¥»÷Õ߾ͻáͨ¹ýWindowsÓò½ÚÔìÆ÷À´´«²¼²¢Ï°È¾Õû¸öÍøÂç¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-megacortex-ransomware-found-targeting-business-networks/