Heritage¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷ÔÝʱ×èÖ¹ÔËÓª£»£» £»£»FBIÐû²¼ÀÕË÷Èí¼þLockerGogaºÍMegaCortexµÄͨ¸æ

Ðû²¼Ê±¼ä 2019-12-26


1.¹ã²¥¹«Ë¾Entercom½ñÄêµÚ¶þ´ÎÔâµ½ÍøÂç¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÍâý±¨µÀ£¬£¬£¬£¬£¬£¬¹ã²¥¹«Ë¾EntercomÔÚÖÜÈÕÔâµ½Ò»´ÎеÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ê¹µÃ¸Ã¹«Ë¾µÄµç×ÓÓʼþͨѶ¡¢Êý×ÖÆ½Ì¨µÄÎļþºÍÄÚÈݾùÎÞ·¨»á¼û£¬£¬£¬£¬£¬£¬Ä³Ð©µç̨±»ÆÈ²¥·ÅÂ¼ÖÆµÄ½ÚÄ¿¡£¡£¡£¡£¡£¡£ÕâÊÇEntercomÔÚ½ñÄêÔâµ½µÄµÚ¶þ´ÎÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ÉÏÒ»´Î¹¥»÷±¬·¢ÔÚ9Ô·Ý£¬£¬£¬£¬£¬£¬¹¥»÷ÀàÐÍΪÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬Æäʱ¹¥»÷ÕßÏòEntercomÀÕË÷50ÍòÃÀÔª£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúEntercomÊÇ·ñÖ§¸¶Á˸ñÊÊê½ð¡£¡£¡£¡£¡£¡£ÖÜÒ»EntercomÌåÏÖÒÑ´Ó×îÐµĹ¥»÷Öлָ´£¬£¬£¬£¬£¬£¬µ«Î´Åû¶´Ë´Î¹¥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/entercom-radio-network-hit-by-second-cyber-attack-this-year/


2.ÓªÏú¹«Ë¾HeritageÔâÀÕË÷Èí¼þ¹¥»÷ÔÝʱ×èÖ¹ÔËÓª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


HeritageÊ×ϯִÐйÙSandra FraneckeÏòÔ±¹¤·¢ËÍÓʼþ³Æ£¬£¬£¬£¬£¬£¬Ô¼Á½¸öÔÂǰHeritageЧÀÍÆ÷Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬¸ø¹«Ë¾Ôì³ÉÁËÊýÊ®ÍòÃÀÔªµÄËðʧ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½«ÔÝʱ×èÖ¹ÔËÓª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ïò¹¥»÷ÕßÖ§¸¶ÁËÊê½ð£¬£¬£¬£¬£¬£¬µ«ITÍŶÓÈÔÔÚ»Ö¸´ÏµÍ³Àú³ÌÖÐÓöµ½ÄÑÌ⣬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄ300¶àÃûÔ±¹¤¿ÉÄÜÒò´Ëʧҵ¡£¡£¡£¡£¡£¡£Õâ²»ÊǵÚÒ»¼ÒÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö¹ØÃŵįóÒµ£¬£¬£¬£¬£¬£¬ÔçÔÚ2019Äê4Ô·ÝBrookside¶ú±ÇºíºÍÌýÁ¦ÖоÍÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö»¼Õ߼ͼ¡¢Ô¤Ô¼Ê±¼ä±íºÍÖ§¸¶ÐÅÏ¢¾ùÎÞ·¨»á¼û£¬£¬£¬£¬£¬£¬×îÖÕÓÀÊÀ¹Ø±Õ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/marketing-agency-temporarily-halts-operations-after-ransomware-attack/


3.FBIÐû²¼ÀÕË÷Èí¼þLockerGogaºÍMegaCortexµÄͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


FBIÕë¶ÔÀÕË÷Èí¼þLockerGogaºÍMegaCortexÏò˽Ӫ²¿·ÖÐû²¼ÖÒÑÔ£¬£¬£¬£¬£¬£¬²¢ÌṩÁËÖ¸µ¼»ººÍ½â½¨Òé²½·¥¡£¡£¡£¡£¡£¡£×Ô2019Äê1ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬LockerGogaÒÑÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Å²ÍþºÍºÉÀ¼µÄ´óÐ͹«Ë¾ºÍ×éÖ¯Ìᳫ¶à¸ö¹¥»÷£¬£¬£¬£¬£¬£¬¶øMegaCortexÓÚ2019Äê5ÔÂÊ״ηºÆð£¬£¬£¬£¬£¬£¬ËüÔÚIOC¡¢C2»ù´¡¼Ü¹¹ºÍÄ¿µÄÑ¡Ôñ·½Ãæ¾ùÀàËÆÓÚLockerGoga¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¾¯±¨£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ҪʹÓÃÎó²î¡¢ÍøÂç´¹ÂÚ¹¥»÷¡¢SQL×¢ÈëºÍ±»µÁµÄµÇ¼ƾ֤ÈëÇÖÆóÒµÍøÂ磬£¬£¬£¬£¬£¬²¢¿ÉÄÜDZÔÚÊýÔµÄʱ¼ä¡£¡£¡£¡£¡£¡£FBI½¨ÒéÆóҵȷ±£°´ÆÚ±¸·ÝÊý¾Ý£¬£¬£¬£¬£¬£¬±£´æÍÑ»ú±¸·Ý²¢ÑéÖ¤±¸·ÝÀú³ÌµÄÍêÕûÐÔ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-issues-alert-for-lockergoga-and-megacortex-ransomware/


4.EmotetÔÚ2019ÄêTop¶ñÒâÈí¼þÍþвÖÐÕ¼ÓÐÖ÷µ¼Ö°Î»


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


½»»¥Ê½¶ñÒâÈí¼þÆÊÎöɳºÐЧÀÍAny.RunÌåÀýÁË2019Äê¶¥¼¶¶ñÒâÈí¼þÍþвÁбí£¬£¬£¬£¬£¬£¬ÆäÖÐEmotetÕ¼ÓÐÖ÷µ¼Ö°Î»¡£¡£¡£¡£¡£¡£ÅÅÔÚǰÏßµÄÍþв»¹°üÀ¨ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢£¨°üÀ¨ÒøÐÐÕË»§ÐÅÏ¢£©µÄ¶ñÒâÈí¼þ¡¢RATµÈ¡£¡£¡£¡£¡£¡£ÏêϸÁбíΪ£ºEmotet-36026¸öÑù±¾¡¢Agent Tesla-10324¸öÑù±¾¡¢NanoCore-6527¸öÑù±¾¡¢LokiBot-5693¸öÑù±¾¡¢Ursnif-4185¸öÑù±¾¡¢FormBook-3548¸öÑù±¾¡¢HawkEye-3388¸öÑù±¾¡¢AZORult-2898¸öÑù±¾¡¢rickBot-2510¸öÑù±¾ÒÔ¼°njRAT-2355¸öÑù±¾¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-reigns-in-sandboxs-top-malware-threats-of-2019/


5.GartnerÊӲ췢Ã÷Ö»ÓÐ65£¥µÄÆóÒµÓµÓÐÍøÂçÇ徲ר¼Ò


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤GartnerµÄÊӲ챨¸æ£¬£¬£¬£¬£¬£¬Ö»¹Ü95£¥µÄCIOÔ¤¼ÆÎ´À´ÈýÄêÄÚÍøÂçÍþв»á¼ÌÐøÔöÌí£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÖ»ÓÐ65£¥µÄÆóÒµÓµÓÐÍøÂçÇ徲ר¼Ò¡£¡£¡£¡£¡£¡£¸ÃÊӲ컹Åú×¢£¬£¬£¬£¬£¬£¬ÊÖÒÕ·½ÃæµÄÌôÕ½ÈÔÈ»À§ÈÅ×ÅÂÄÀúÊý×Ö»¯Àú³ÌµÄÆóÒµ£¬£¬£¬£¬£¬£¬²¢ÇÒÊý×ÖÇ徲ְԱǷȱ±»ÒÔΪÊÇÁ¢ÒìµÄÖ÷ÒªÕϰ­¡£¡£¡£¡£¡£¡£35£¥µÄÊÓ²ìÊÜ·ÃÕßÌåÏÖËûÃÇµÄÆóÒµÒѾ­Í¶×ʲ¢°²ÅÅÁËijЩ·½ÃæµÄÊý×ÖÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬ÉÐÓÐ36£¥µÄÊÜ·ÃÕßÕýÔÚÆð¾¢ÊµÑé»òÍýÏëÔÚ¶ÌÆÚÄÚʵÑéÊý×ÖÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£GartnerÕ¹Íûµ½2020ÄêÇå¾²Ô¤ËãÖеÄ60£¥½«ÓÃÓÚÖ§³Ö¼ì²âºÍÏìÓ¦¹¦Ð§¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.gartner.com/en/newsroom/press-releases/2018-07-17-gartner-survey-finds-only-65-percent-of-organizations-have-a-cybersecurity-expert


6.Ç÷ÊÆ¿Æ¼¼Ðû²¼Õë¶ÔWordPressÍøÕ¾¹¥»÷ÊÖÒյįÊÎö±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶÓÐû²¼¹ØÓÚÕë¶ÔWordPressÍøÕ¾¹¥»÷ÊÖÒÕµÄÊӲ챨¸æ£¬£¬£¬£¬£¬£¬ ¸Ã±¨¸æÖ¸³öÓÉÓÚWordPressÒѱ»µ±½ñËùÓÐÍøÕ¾µÄÔ¼35£¥Ê¹Ó㬣¬£¬£¬£¬£¬Ê¹Æä³ÉΪ¹¥»÷ÕßµÄÀíÏëÄ¿µÄ¡£¡£¡£¡£¡£¡£»£» £»£»ùÓÚÇ÷ÊÆ¿Æ¼¼ÔÚÒ°ÍâÊӲ쵽µÄpayloadÑù±¾£¬£¬£¬£¬£¬£¬Ñо¿ÍŶӯÊÎöÁËÕë¶ÔWordPressµÄ²î±ðÀàÐ͵Ĺ¥»÷£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃÎó²î»òͨ¹ýй¶µÄ»òÈõÖÎÀíԱƾ֤¹¥»÷WordPressÍøÕ¾¡¢ÔÚÊÜѬȾµÄWordPressÍøÕ¾Öа²ÅÅAlfa-Shell¡¢Ê¹ÓÃÊÜѬȾµÄÍøÕ¾ÎÛȾËÑË÷ÒýÇæµÄËÑË÷Ч¹ûÒÔ¼°É¢²¼Ðéα»òÎóµ¼ÐÔÎÄյȡ£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/looking-into-attacks-and-techniques-used-against-wordpress-sites/