ºÚ¿ÍÇÔÈ¡Áè¼Ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý £»£»£»£»£»£»GAOÈ·ÈÏÃÀ¹úµçÍøÃæÁÙÖØ´óÍøÂçÇ徲Σº¦

Ðû²¼Ê±¼ä 2019-09-30
1.ºÚ¿ÍÇÔÈ¡Áè¼Ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ºÚ¿ÍGnosticplayers´ÓÒÆ¶¯Éç½»ÓÎÏ·¹«Ë¾Zynga Inc¿ª·¢µÄWords With FriendsÖÐÇÔÈ¡ÁËÁè¼Ý2.18ÒÚÌõÍæ¼Ò¼Í¼¡£¡£¡£¡£¡£¡£¡£GnosticplayersÔøÔÚ2ÔÂÖÁ4ÔÂʱ´ú³öÊÛÁË´Ó45¼Ò¹«Ë¾ÇÔÈ¡µÄ½ü10ÒÚÌõÓû§ÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬ÕâÒ»´ÎËûÃé×¼ÁËÃÀ¹úÉç½»ÓÎÏ·¿ª·¢ÉÌZynga¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Gnosticplayers·ÖÏíµÄ¼Í¼£¬£¬£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¼¯°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µÇ¼ID¡¢¼ÓÑιþÏ£ÃÜÂë¡¢ÃÜÂëÖØÖÃÁîÅÆ¡¢µç»°ºÅÂë¡¢Facebook IDÒÔ¼°ZyngaÕÊ»§ID¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓû§Îª2019Äê9ÔÂ2ÈÕ֮ǰװÖò¢×¢²á¸ÃÓÎÏ·µÄAndroidºÍiOSÍæ¼Ò¡£¡£¡£¡£¡£¡£¡£ZyngaÈ·ÈÏÁËÕâÒ»ÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬µ«ÌåÏÖûÓвÆÎñÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/91850/data-breach/zynga-game-data-breach.html

2.ÐÂWhiteShadowÏÂÔØÆ÷ʹÓÃSQL Server·Ö·¢¶ñÒâÈí¼þ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ProofpointÑо¿ÍŶӷ¢Ã÷жñÒâÈí¼þÏÂÔØÆ÷WhiteShadowʹÓù¥»÷Õß¿ØÖƵÄMicrosoft SQL ServerÀ´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£WhiteShadowÒÔÒ»×éOfficeºêµÄÐÎʽ·ºÆð£¬£¬£¬ £¬£¬£¬£¬Ö÷Ҫͨ¹ý°üÀ¨¶ñÒâURL»ò¶ñÒ⸽¼þµÄÀ¬»øÓʼþ·Ö·¢¡£¡£¡£¡£¡£¡£¡£×Ô8Ô·ݸÃÏÂÔØÆ÷Ê״α»·¢Ã÷ÒÔÀ´£¬£¬£¬ £¬£¬£¬£¬Ñо¿ÍŶÓÒѾ­·¢Ã÷Á˽ü12¸öʹÓøÃÏÂÔØÆ÷µÄ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼¶ñÒâ»î¶¯¶¼·Ö·¢Á˶ñÒâÈí¼þCrimson£¬£¬£¬ £¬£¬£¬£¬ÆäËüpayloadÒ²°üÀ¨Agent Tesla¡¢AZORult¡¢Nanocore¡¢njRat¡¢Orion Logger¡¢Remcos¼°Formbook RATsµÈ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-whiteshadow-downloader-uses-mssql-servers-for-malware-delivery/

3.Ñо¿ÍŶÓÐû²¼NodeJSÎÞÎļþ¶ñÒâÈí¼þDivergentµÄÆÊÎö±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

˼¿ÆTalosÐû²¼¹ØÓÚÎÞÎļþ¶ñÒâÈí¼þDivergentµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹÓÃNodeJS¼°Õýµ±¿ªÔ´¹¤¾ßWinDivertÀ´ÊµÑ鲿·Ö¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÔÚ¶ñÒâÈí¼þ¼Ò×åÖУ¬£¬£¬ £¬£¬£¬£¬Ê¹ÓÃNodeJS²¢²»³£¼û¡£¡£¡£¡£¡£¡£¡£DivergentµÄÖ÷ҪĿµÄÊǾÙÐеã»÷ڲƭ£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÀ´Õë¶Ô¹«Ë¾ÍøÂç¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓëÁíÒ»ÖÖÊ¢ÐеÄÎÞÎļþ¶ñÒâÈí¼þ¼Ò×åKovter¾ßÓÐÐí¶àÏàËÆÖ®´¦£¬£¬£¬ £¬£¬£¬£¬°üÀ¨¶¼ÒÀÀµÓÚ×¢²á±íÀ´ÉèÖúʹ洢Êý¾Ý¡¢×èÖ¹¶Ô´ÅÅÌÉϵÄÎļþ¾ÙÐйŰåµÄɨÃè¡¢ÒÀÀµPowerShell×ÔÐÐ×°Öõȡ£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÉÐÎÞ·¨È·¶¨Æä·Ö·¢»úÖÆ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2019/09/divergent-analysis.html

4.Ñо¿Ö°Ô±·¢Ã÷½©Ê¬ÍøÂçChameleonµÄÐÂÀ¬»øÓʼþÀ˳±

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

TrustwaveÑо¿Ö°Ô±ÊӲ쵽À´×Ôͳһ½©Ê¬ÍøÂçµÄÀ¬»øÓʼþ»î¶¯ÐÂÀ˳±£¬£¬£¬ £¬£¬£¬£¬ÓÉÓڸù¥»÷»î¶¯¾­³£¸ü¸ÄÆäµç×ÓÓʼþÄ£°å£¬£¬£¬ £¬£¬£¬£¬Òò´Ë±»³ÆÎªChameleon£¨±äÉ«Áú£©¡£¡£¡£¡£¡£¡£¡£×Ô8ÔÂ14ÈÕÒÔÀ´£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±×îÏÈÊӲ쵽¸Ã½©Ê¬ÍøÂç·¢Ë͵ÄÀ¬»øÓʼþ£¬£¬£¬ £¬£¬£¬£¬ÓʼþÖ÷Ìâ°üÀ¨ÐéαµÄÊÂÇéʱ»ú¡¢Î±ÔìµÄGoogle˽ÈËÐÂÎÅ¡¢ÐéαµÄÓÊÏäÕË»§¾¯±¨¡¢ÐéαµÄ¿ìµÝ֪ͨµÈ¡£¡£¡£¡£¡£¡£¡£ÕâЩÀ¬»øÓʼþÖÐǶÈëµÄ´ó´ó¶¼¶ñÒâURLËÆºõ¶¼ÊÇÊÜѬȾµÄWordPressÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕâÐ©ÍøÕ¾ÉϵÄjs½«Óû§Öض¨ÏòÖÁ¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/tracking-the-chameleon-spam-campaign/

5.ÃÀWallenpaupack AreaÑ§Çø³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃÀ¹úWallenpaupack AreaÑ§ÇøÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬£¬µ¼ÖÂѧУ±»ÆÈÔÚ9ÔÂ5ÈչرÕÁË3000̨ÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£ÕâÊǸÃÑ§ÇøÔÚ½ñÄê¶ÈÔâÓöµÄµÚ¶þ´ÎÖØ´óÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£WallenpaupackÐÅϢЧÀͲ¿×ܼàSteven NalesnikÌåÏÖ£¬£¬£¬ £¬£¬£¬£¬ÎªÕû¸öÑ§ÇøÐ§À͵ÄÁ½Ì¨ÖÐÑëЧÀÍÆ÷ÔÚÕâ´Î¹¥»÷ÖÐÊܵ½Ó°Ï죬£¬£¬ £¬£¬£¬£¬µ«¾¯³¤SilsbyÌåÏÖ¸ÃÑ§ÇøºÜÐÒÔË£¬£¬£¬ £¬£¬£¬£¬ÏÕЩËùÓб»¼ÓÃܵÄÎļþ¶¼Óб¸·Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÑ§ÇøµÄÊÖÒÕÍŶÓÕýÔÚÆð¾¢»Ö¸´ÏµÍ³µÄÕý³£ÔËÓª¡£¡£¡£¡£¡£¡£¡£Silsby»¹Ö¸³öÊÖÒÕÍŶӯÀ¹ÀÒÔΪѧÉúºÍÔ±¹¤µÄÐÅϢûÓÐÊÕµ½Ë𺦡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
http://www.spamfighter.com/News-22436-Wallenpaupack-Area-School-District-became-victim-of-a-ransomware-attack.htm

6.GAOÈ·ÈÏÃÀ¹úµçÍøÃæÁÙÖØ´óÍøÂçÇ徲Σº¦

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃÀ¹úÕþ¸®ÎÊÔð¾Ö£¨GAO£©ÔÚÒ»·Ýб¨¸æÖÐÈ·ÈÏÃÀ¹úµçÍøÃæÁÙÖØ´óÍøÂçÇ徲Σº¦£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒÔ½À´Ô½ÈÝÒ×Ôâµ½¹¥»÷Õߺͷ¸·¨¼¯ÍŵÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£GAOÉó²éÁËÃÀ¹úµçÍøµÄÍøÂçÇå¾²ÐÔ£¬£¬£¬ £¬£¬£¬£¬ÆÊÎöÁËÄÜÔ´²¿£¨DOE£©½â¾öÍøÂçÇ徲Σº¦Ê±½ÓÄɵÄÕ½ÂÔ£¬£¬£¬ £¬£¬£¬£¬²¢ÆÀ¹ÀÁËFERCÅú×¼µÄ±ê×¼£¬£¬£¬ £¬£¬£¬£¬×îÖÕÈ·ÈÏÁ˵çÍøÖпɱ»Ê¹ÓõÄÒªº¦×é¼þºÍÁ÷³Ì£¬£¬£¬ £¬£¬£¬£¬°üÀ¨Ô½À´Ô½¶àµØÊ¹ÓÃIoT×°±¸¡¢Ê¹ÓÃGPSͬ²½µçÍøÔËÓªµÈ¡£¡£¡£¡£¡£¡£¡£GAO»¹È·ÈÏÁËÍøÂç¹¥»÷¶ÔÃÀ¹úµçÍøÔì³ÉµÄDZÔÚÓ°Ï죬£¬£¬ £¬£¬£¬£¬°üÀ¨Ôì³ÉÆÕ±éµÄµçÁ¦ÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.gao.gov/assets/710/701079.pdf