DarkCrewFriendsÀûÓÃÄÚÈÝÖÎÀíϵͳ¹¹½¨½©Ê¬ÍøÂ磻¶ñÒâ.slkÎļþ¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATP
°ä²¼¹¦·ò 2020-06-281.DarkCrewFriends»Ø¹é£¬ÀûÓÃÄÚÈÝÖÎÀíϵͳ¹¹½¨½©Ê¬ÍøÂç
Check PointµÄ×êÑÐÈËÔ±·¢ÏÖ£¬ºÚ¿Í×éÖ¯DarkCrewFriends»Ø¹é£¬²¢¶Ô×¼ÄÚÈÝÖÎÀíϵͳÀ´¹¹½¨½©Ê¬ÍøÂç¡£×êÑÐÈËÔ±·¢ÏÖ£¬¸ÃºÚ¿Í×éÖ¯ÔÚÀûÓÃÒ»¸ö²»ÊÜÏ޶ȵÄÎļþÉÏ´«·ì϶À´·ÛËéÍøÕ¾µÄPHP·þÎñÆ÷£¬²¢ÔÚÊܺ¦Õß·þÎñÆ÷ÉÏ·¢ÏÖÁËÏÂÔØºÍÖ´ÐÐÁ½¸ö.AFFÎļþµÄºÅÁµ±ËûÃÇÏÂÔØÕâÁ½¸öÎļþʱ£¬·¢ÏÖËüÃÇÏÖʵÉÏÊÇPHPºÍPerlÎļþ¡£·ÖÎöÈËÔ±×ܽá·£¬¹¥»÷ÕßÀûÓÃIRCºÍ̸ϰȾ·þÎñÆ÷À´´´½¨½©Ê¬ÍøÂ磬Õâ»á¶ÔÊܺ¦ÕߵĻù´¡ÉèÊ©²úÉúºÜÑϳÁµÄÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/darkcrewfriends-returns-botnet/156963/
2.Evil Corp¹¥»÷30¶à¼ÒÃÀ¹ú¹«Ë¾²¢·Ö·¢WastedLocker
ÈüÃÅÌú¿Ë°ä²¼»ã±¨£¬°µÊ¾ºÚ¿Í×éÖ¯Evil Corp¹¥»÷ÁË30¶à¼ÒÃÀ¹ú¹«Ë¾£¬²¢ÊÔͼÔÚÊܺ¦ÕßϵͳÖÐ×°ÖÃÀÕË÷Èí¼þWastedLocker¡£ÔÚÕâЩ±»¶Ô×¼µÄ¹«Ë¾ÖУ¬³ýÁËÒ»¼ÒÊǺ£±í¿ç¹ú¹«Ë¾ÔÚÃÀ¹úµÄ×Ó¹«Ë¾£¬ÆäÓàÈ«ÊýÊÇÃÀ¹ú¹«Ë¾£¬Éæ¼°µ½ÁËÔì×÷Òµ£¨5¼Ò£©£¬ÐÅÏ¢¼¼Êõ²¿ÃÅ£¨4¼Ò£©ºÍµçÐÅ×éÖ¯£¨3¼Ò£©¡£ÈüÃÅÌú¿Ë·ÖÎö·£¬¹¥»÷ʼÓÚ»ùÓÚJavaScriptµÄ¶ñÒâ¿ò¼ÜSocGholish£¬¸Ã¿ò¼Ü¿É¸ú×Ù150¶à¸ö¼Ù×°³ÉÈí¼þ¸üеÄÊÜÏ°È¾ÍøÕ¾¡£Ò»µ©¹¥»÷Õß»ñµÃÁËÖ¸±êÍøÕ¾µÄ½Ó¼ûȨ£¬¾Í»áʹÓÃCobalt StrikeÀ´ÇÔȡʹ´¦¡¢ÌáȨ²¢ºáÏòÒÆ¶¯£¬Ö¼ÔÚ×°ÖÃWastedLocker¡£ÈüÃÅÌú¿Ë»ã±¨µÄĩβ»¹ÌṩÁËÓйØWastedLocker¹¥»÷µÄ·çÏÕÖ¸±ê£¨IOC£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/evil-corp-blocked-from-deploying-ransomware-on-30-major-us-firms/
3.еĶñÒâ.slkÎļþ¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATP
AvananµÄ°²È«·ÖÎöʦÒѼì²âµ½¿ÉÈÆ¹ýMicrosoft 365 EOPºÍATPµÄеĶñÒâ.slkÎļþ£¬Ô¤¼Æ»á¸ø2ÒÚ¶àÓû§´øÀ´·çÏÕ¡£Ôڴ˹¥»÷ÖУ¬ºÚ¿Í·¢ËÍ´øÓÐ.slk¸½¼þµÄµç×ÓÓʼþ£¬¸Ã¸½¼þ»¹Ô̺¬ÓÃÀ´ÏÂÔØºÍ×°ÖÃÔ¶³Ì½Ó¼ûľÂíµÄ¶ñÒâºê£¨MSI exec¾ç±¾£©¡£¸Ã.slkÎļþÄܹ»Òñ±ÎµÄÔËÐÐWindows×°Ö÷¨Ê½(msiexec)£¬ÒÔ×°ÖÃËûÃÇÔÚÆäÕ¾µãÉÏÍйܵÄMSI°ü¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬ºÚ¿ÍʹÓõÄÊÇÔ¶³Ì½ÚÔìÀûÓ÷¨Ê½NetSupportµÄºÚ¿Í°æ±¾£¬ËüÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì×ÀÃæ¡£ºÚ¿Í»¹Ê¹ÓÃÁ˺öàÓÃÀ´ÈƹýATPµÄ»ìºÏ¼¼Êõ£¬ÀýÈ磬ÓʼþÊÇ´ÓÊý°Ù¸öÃâ·ÑµÄhotmailÕÊ»§·¢Ë͵ģ»ºê¾ç±¾Ô̺¬¡°^¡±×Ö·û£¬ÒÔ»ìºÏATP¹ýÂËÆ÷£»¸ÃÍøÖ·±»·Ö³ÉÁ½²¿ÃÅ£¬Òò¶øATP²»»á½«ÆäÊÓÎªÍøÂçÁ´½Ó£¬µÈµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.informationsecuritybuzz.com/news/200m-users-at-risk-new-malicious-slk-files-are-bypassing-microsoft-365-security/
4.½ü300¸öWindows 10¿ÉÖ´ÐÐÎļþÒ×Ôâµ½DLL½Ù³Ö¹¥»÷
ÆÕ»ªÓÀ·°²È«×êÑÐÈËÔ±°ä²¼»ã±¨°µÊ¾ £¬½«½ü300¸öWindows 10¿ÉÖ´ÐÐÎļþÈÝÒ×Êܵ½DLL½Ù³Ö¹¥»÷£¬¹¥»÷ÕßʹÓÃÒ»¸öµ¥Ò»µÄVBScriptÒ²Ðí¾ÍÄܹ»»ñµÃÖÎÀíԱȨÏÞ²¢ÆëÈ«ÈÆ¹ýWindows 10ÉϵÄUAC¡£ÓÉÓÚWindows 7ÒÔÉÏÔÊÐíÊÜÐÅÀµµÄϵͳDLLÄܹ»×Ô¶¯ÌáÉýÌØÈ¨£¬¶ø²»ÓÃʹÓÃUACÌáÐÑÀ´´ò½ÁÓû§£¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýʹÓÃÏóÕ÷Ϊ×Ô¶¯ÌáȨµÄ¿ÉÖ´ÐÐÎļþÀ´³¢ÊÔÒÔ¸ü¸ßȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£Ò»µ©³É¹¦ÀûÓã¬Ôò¶ñÒâdll¿ÉÓÃÓÚ´´½¨ÌáȨµÄºÅÁîÌáÐÑ·û£¬´Ó¶øÒÔÖÎÀíȨÏÞ¶ÔÍÆËã»ú½øÐнӼû¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/almost-300-windows-10-executables-vulnerable-to-dll-hijacking/
5.¶í¾ÍÒµÍøÕ¾SuperJobµÄϵͳ´æÔÚ·ì϶£¬Ð¹Â¶500Íò¹«ÃñÐÅÏ¢
DeviceLock·¢ÏÖÁ˶íÂÞ˹¾ÍÒµÍøÕ¾SuperJobÒòÆäϵͳ´æÔÚ·ì϶£¬Ð¹Â¶ÁË500Íò¹«ÃñÐÅÏ¢¡£Õâ´Îй¶Êý¾ÝÔ̺¬Óû§ÐÕÃûºÍÖÐÑëÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢³ÇÊÓ×¢½øÕ¹µÄнˮˮƽ¡¢Òƶ¯ÔËÓªÉ̵ÄÃû³Æ¡¢Óû§µÄµØÓòºÍÊ±Çø¡£×¨¼Ò·ÖÎö£¬Õâ´Îй©¿ÉÄÜÊÇÓÉÓÚÊý¾Ý¿â·þÎñÆ÷Öеķì϶ÒýÆðµÄ£¬µ«ÊÇSuperJob»Ø¾øÌṩÓйØÕâ´ÎÊÂÎñµÄ¾ßÌåÐÅÏ¢ÒÔ¼°Æä500ÍòÓû§Ó×ÎÒÐÅϢй¶µÄÉêÃ÷¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2020/06/experts-have-discovered-data-leak-of.html
6.ýÌ幫˾E27Ôâµ½Korean Hackers¹¥»÷£¬Ô´´úÂëºÍÊý¾Ý¿âй¶
ÑÇÖÞµÄýÌ幫˾E27Ôâµ½×Ô³ÆÎªKorean HackersµÄºÚ¿Í¹¥»÷µ¼ÖÂÔ´´úÂëºÍÊý¾Ý¿âй¶£¬²¢±»ÒªÇóÖ§¸¶Ò»±Ê¡°Ó×Ó׵ľè¿î¡±£¬ÒÔÏàʶÆäÊÇÈôºÎ±»ºÚ¿ÍÈëÇÖ²¢Ô®ÊÔì佨¸´·ì϶¡£¸ÃºÚ¿Í×éÖ¯Ðû³ÆËûÃÇÇÔÈ¡ÁËÊܺ¦¹«Ë¾µÄÔ´´úÂëºÍÊý¾Ý¿â£¬ÆäÖÐÔ̺¬µç×ÓÓʼþ¡¢ÊÖ»ú¡¢ÃÜÂë¡¢ÆäËûÎĵµ¡¢Ó×ÎÒ×ÊÁÏͼÏñµÈ¡£Ä¿Ç°£¬E27ÒѾÏòÆäÓû§·¢³öÁËÐÅϢй¶֪ͨ£¬ÆäCEO Mohan BelaniÔò°µÊ¾£¬ËûÃÇÒÑÓë·¨Âɲ¿ÃÅ»ñµÃÁªÏµ£¬²¢½«ÆÚ´ýËûÃǵÄÖ§³ÖºÍÁìµ¼¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-breach-e27-want-donation-to-reveal-vulnerabilities/


¾©¹«Íø°²±¸11010802024551ºÅ