Õë¶Ô¶à¹úÕþ¸®ÍøÂçµÄ´¹ÂڻÊÂÎñΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-16

ÊÂÎñ¸ÅÊö


¿ËÈÕ£¬£¬ £¬£¬Òì³£ÍþвÑо¿Ð¡×é·¢Ã÷ÁËÒ»ÏîеÄÍøÂç´¹Âڻ£¬£¬ £¬£¬Ö¼ÔÚ´ÓÃÀ¡¢Å·ÖÞºÍÑÇÖÞµÄÕþ¸®²¿·ÖÇÔÈ¡µÇ¼ƾ֤£¬£¬ £¬£¬ÏÖÔÚÉв»ÇåÎúÄ»ºóºÚÊÖÊÇË­£¬£¬ £¬£¬µ«¿´À´È·ÊµÊÇÒ»Á¬µÄ¹¥»÷¡£¡£¡£¡£¡£ÓÕÆ­ÐÔÍøÂç´¹ÂÚÕ¾µãÓòÍйÜÔÚÍÁ¶úÆäºÍÂÞÂíÄáÑÇ£¬£¬ £¬£¬¸Ã»î¶¯ÏÖÔÚ´¦ÓÚÐÝÃß״̬¡£¡£¡£¡£¡£


×ÜÌå¶øÑÔ£¬£¬ £¬£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Öйú¡¢°Ä´óÀûÑÇ¡¢ÈðµäµÈ¹ú¼ÒÖеÄ22¸ö×éÖ¯ÒѾ­Ã÷È·ÔâÊÜ´Ë´ÎÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¹¥»÷·½·¨¶¼²îδ¼¸£¬£¬ £¬£¬Éæ¼°ÓëÄ¿µÄÕþ¸®»ú¹¹Óйصĵç×ÓÓʼþ£¬£¬ £¬£¬ÓÕÆ­Êܺ¦Õßµã»÷µç×ÓÓʼþÁ´½Ó£¬£¬ £¬£¬È»ºóÊäÈëÆäÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£


Òì³£ÍþвÑо¿Ð¡×éÈ·¶¨ÁËÒ»ÏîÆ¾Ö¤ÍøÂç»î¶¯£¬£¬ £¬£¬Ö¼ÔÚ´Ó¶à¸öÕþ¸®²É¹ºÐ§ÀÍÖÐÇÔÈ¡µÇ¼ÏêϸÐÅÏ¢¡£¡£¡£¡£¡£Ðí¶à¹«¹²ºÍ˽Ӫ²¿·Ö×éÖ¯¶¼Ê¹ÓòɹºÐ§ÀÍÀ´Æ¥ÅäÂò¼ÒºÍ¹©Ó¦ÉÌ¡£¡£¡£¡£¡£ÔÚ´ËÔ˶¯ÖУ¬£¬ £¬£¬¹¥»÷ÕßÓÕÆ­Á˶à¸ö¹ú¼ÊÕþ¸®²¿·Ö£¬£¬ £¬£¬µç×ÓÓʼþЧÀͺÍÁ½¸ö¿ìµÝЧÀ͵ÄÕ¾µã¡£¡£¡£¡£¡£·¢Ã÷ͨ¹ýÍøÂç´¹ÂÚµç×ÓÓʼþ·¢Ë͵ÄÓÕ¶üÎĵµ°üÀ¨Ö¸ÏòÓÕÆ­ÐÔÍøÂç´¹ÂÚÕ¾µãµÄÁ´½Ó£¬£¬ £¬£¬ÕâЩÁ´½Óαװ³ÉÓëÓÕÆ­ÐÔÕþ¸®»ú¹¹ÓйصÄÕýµ±µÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£È»ºó£¬£¬ £¬£¬ÓÕʹ±»ÓÕÆ­Õß×·×ÙÍøÂç´¹ÂÚµç×ÓÓʼþÁ´½ÓµÄÊܺ¦ÕߵǼ¡£¡£¡£¡£¡£³ÉΪµÐÊÖÊܺ¦ÕßµÄÈκÎÈ˶¼½«ÏòËûÃÇÌṩƾ֤¡£¡£¡£¡£¡£


ÊÂÎñÓ°Ïì


   ÊÜÓ°ÏìµÄ×éÖ¯°üÀ¨£º

ÃÀ¹ú-ÃÀ¹úÄÜÔ´²¿

ÃÀ¹ú-ÃÀ¹úÉÌÎñ²¿

ÃÀ¹ú-ÃÀ¹úÍËÎéÎäÊ¿ÊÂÎñ²¿

ÃÀ¹ú-ÐÂÔóÎ÷ÖݺâÓî¼°µäÖʽðÈÚ¾Ö

ÃÀ¹ú-ÂíÀïÀ¼ÖÝÕþ¸®²É¹ºÐ§ÀÍ

ÃÀ¹ú-·ðÂÞÀï´ïÖÎÀíЧÀͲ¿

ÃÀ¹ú-½»Í¨²¿

ÃÀ¹ú-ס·¿ºÍ¶¼»áÉú³¤²¿

DHL¹ú¼Ê¿ìµÝЧÀÍ

¼ÓÄôó-Õþ¸®µç×ӲɹºÐ§ÀÍ

Ä«Î÷¸ç-Õþ¸®µç×ӲɹºÐ§ÀÍ

ÃØÂ³-¹«¹²²É¹ºÖÐÐÄ

Öйú-˳·á¿ìµÝЧÀÍ

Öйú-½»Í¨ÔËÊ䲿

ÈÕ±¾-¾­¼Ã¹¤ÒµÊ¡

ÐÂ¼ÓÆÂ-¹¤ÒµºÍÉÌÒµ²¿

ÂíÀ´Î÷ÑÇ-¹ú¼ÊÉÌÒµºÍ¹¤Òµ²¿

°Ä´óÀûÑÇ-Õþ¸®µç×ӲɹºÃÅ»§

Èðµä-Õþ¸®»ú¹Ø¹ú¼Ò¹«¹²²É¹º¾Ö

²¨À¼-ÉÌÒµºÍͶ×ÊÊð


Ä¿µÄ¹ú¼Ò£º

   Í¼1ÖеÄÈÈͼÏÔʾ£¬£¬ £¬£¬ÃÀ¹úÖ÷ÒªÊÇÕë¶ÔÐԵ쬣¬ £¬£¬ÓÐ50¶à¸ö´¹ÂÚÍøÕ¾Ö¼ÔÚÇÔÈ¡ÓÕÆ­ÃÀ¹ú×éÖ¯µÄƾ֤¡£¡£¡£¡£¡£¼ÓÄô󣬣¬ £¬£¬ÈÕ±¾ºÍ²¨À¼»®·Ö½ôËæØÊºóµÄ»®·ÖÊÇ7¡¢6ºÍ6¸ö´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£´ËÔ˶¯µÄÄ¿µÄ¹ú¼ÒÊÇ£º

ÃÀ¹ú

Öйú

ÐÂ¼ÓÆÂ

Èðµä

ÄÏ·Ç

Ä«Î÷¸ç

ÈÕ±¾

ÂíÀ´Î÷ÑÇ

²¨À¼

ÃØÂ³

¼ÓÄôó

°Ä´óÀûÑÇ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ1.ÒÔÕþ¸®²É¹ºÕ¾µãΪĿµÄµÄÍøÂç´¹ÂÚÕ¾µãµÄ¹ú¼ÒÈÈͼ


Ä¿µÄÐÐÒµ£º

´Ë»î¶¯Õë¶ÔÒÔÏÂÐÐÒµ£ºÍ¼2ÏÔʾ£¬£¬ £¬£¬Õþ¸®ÃÅ»§ÍøÕ¾ÖÐרÃÅÓÃÓÚÇÔȡƾ֤µÄ´¹ÂÚÍøÕ¾ÊýÄ¿×î¶à¡£¡£¡£¡£¡£

Õþ¸®

µçÓÊЧÀÍ

ËÍ»õ£¬£¬ £¬£¬ÓʷѺÍÔËÊä


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ2.±ýͼÏÔʾÁ˰´ÐÐÒµ»®·ÖµÄÓÕÆ­×éÖ¯µÄÊýÄ¿


ÊÂÎñÆÊÎö


ÓÕ¶üÎļþ£º


´ËÔ˶¯µÄÄ¿µÄÊܺ¦ÕߺܿÉÄÜÔÚÍøÂç´¹ÂÚµç×ÓÓʼþÖз¢ËÍÁËÓÕ¶üÎļþ¡£¡£¡£¡£¡£ÓÕ¶üÎļþÖ¼ÔÚÓ­ºÏÆäÄ¿µÄÕþ¸®ËùÔÚ¹ú¼Ò/µØÇøµÄÓïÑÔ¡£¡£¡£¡£¡£ÄÏ·ÇÓÕ¶üÎļþÊÇÓÃÓ¢ÓïдµÄ£¬£¬ £¬£¬µ«ÄÏ·ÇÊǶàÖÖÓïÑÔ£¨°üÀ¨Ó¢ÓµÄËùÔڵء£¡£¡£¡£¡£Í¼3ÏÔʾÁË·¢Ã÷µÄÓÕ¶üÎļþµÄһЩʾÀý¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ3.¸Ã»î¶¯ÖÐÊӲ쵽µÄÓÕ¶üÎļþ


ÉÏÃæµÄÓÕ¶üÎĵµ°üÀ¨Ò»¸öǶÈëʽÁ´½Ó£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ4. pdfÎĵµÖеÄǶÈëʽÁ´½ÓÓÕÆ­ÁËÃÀ¹úÉÌÎñ²¿


ÉÏÃæµÄPDFÎļþÃûITB_USDOC.pdfÖеÄÁ´½Ó£¨Í¼4£©¾ßÓÐÒ»¸öǶÈëʽÁ´½Ó£¬£¬ £¬£¬¸ÃÁ´½Ó½«Êܺ¦Õß¶¨Ïòµ½ÍйÜÔÚ¶ñÒâÓò¡°40-71.xyz¡±ÉϵÄÍøÂç´¹ÂÚÒ³Ãæ¡£¡£¡£¡£¡£¸ÃÎĵµÒÑÌá½»¸øÃÀ¹úºÍ·¨¹úµÄVirusTotal£¨×÷Ϊµç×ÓÓʼþµÄÒ»²¿·Ö£¬£¬ £¬£¬µ«¸Ãµç×ÓÓʼþ²»¿ÉÓã©¡£¡£¡£¡£¡£


Æ¾Ö¤ÍøÂçÕ¾µã


ËùÓÐÕ¾µã¶¼Ê¹Óá°cPanel£¬£¬ £¬£¬Inc¡±½ÒÏþµÄÓòÑéÖ¤£¨DV£©Ö¤Êé¡£¡£¡£¡£¡£×ÓÓò¾ßÓÐÀàËÆµÄÃüÃûÔ¼¶¨£¬£¬ £¬£¬ÒÔÔÚÏ߯¾Ö¤ÎªÄ¿µÄ£¬£¬ £¬£¬²¢°üÀ¨Çå¾²£¬£¬ £¬£¬ÑéÖ¤£¬£¬ £¬£¬³ö¼Û»ò½»¸¶Ö÷Ìâ¡£¡£¡£¡£¡£Í¼5ÏÔʾÁ˹¥»÷Õß½¨ÉèµÄÆ¾Ö¤ÍøÂçÒ³ÃæµÄʾÀý¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ5.ÔڸûÖÐÊӲ쵽µÄÆ¾Ö¤ÍøÂçÕ¾µã


ÍøÒ³ÉÏÓÐÇåÎúµÄ±ê¼ÇºÍ±êÇ©£¬£¬ £¬£¬Ïêϸ˵Ã÷Îú¹¥»÷ÕßÊÔͼģÄâµÄ×éÖ¯¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÕýµ±ÓòÒÔ¼°×Ô¼ºµÄ»ù´¡½á¹¹¡£¡£¡£¡£¡£ÃÀ¹úÄÜÔ´²¿µÄÍøÒ³ÍйÜÔÚ¡°https£º//energy.gov.secure.server-bidsync.best/auth/login.html¡±ÉÏ£¬£¬ £¬£¬²¢´ÓÒÔÏÂÍøÖ·ÖØ¶¨Ïò£º


¡°http://energy.gov.secure.bidsync.newnepaltreks.com¡±¡£¡£¡£¡£¡£Öض¨ÏòURL»ùÓÚÕýµ±ÓòÃû¡°newnepaltreks.com¡±£¬£¬ £¬£¬¸ÃÓòÃûºÜ¿ÉÄÜÒѱ»Ð¹ÃÜ£¬£¬ £¬£¬ÒÔÖúÓÚ¾ÙÐд˹¥»÷¡£¡£¡£¡£¡£


Íþв»ù´¡¼Ü¹¹


ÔÚÊÓ²ìÀú³ÌÖУ¬£¬ £¬£¬·¢Ã÷ÁË62¸öÓòºÍԼĪ122¸öÍøÂç´¹ÂÚÕ¾µã¡£¡£¡£¡£¡£ÓòÉÏÍйܵÄËùÓÐÍøÂç´¹ÂÚÕ¾µã¶¼¾ßÓÐÏàËÆµÄÃüÃûÔ¼¶¨£º

Ä¿µÄÓò»òЧÀÍдΪ×ÓÓò£¬£¬ £¬£¬ºó¸ú¶ñÒâÓò»òÊÜѬȾµÄЧÀÍÆ÷¡£¡£¡£¡£¡£


Éí·ÝÑéÖ¤£¬£¬ £¬£¬³ö¼Ûͬ²½£¬£¬ £¬£¬²É¹º»ò½»¸¶Ö÷Ìâ


ÍøÂç´¹ÂÚÕ¾µãÖ÷ÒªÍйÜÔÚÒÔÏÂËĸöIPµØµãÉϵÄ×âÓûù´¡½á¹¹ÉÏ£º


31.210.96.221

193.29.187.173

91.235.116.146

188.241.58.170


¶Ô×î³õÈ·¶¨µÄÓò¡°server-bidsync.best¡±µÄÊÓ²ìÈ·¶¨ÁË´Ó¿Í»§¶Ëä¯ÀÀÆ÷µ½¶ñÒâÓòµÄͨѶÖеÄ×ÊÔ´¹þÏ£¡£¡£¡£¡£¡£ÊÓ²ìÁ˶Ôhttps£º//energy.gov.secure.server-bidsync.best/auth/alter.cssµÄGETÇëÇ󣬣¬ £¬£¬ÑùʽÐÎʽ¡°alter.css¡±£¬£¬ £¬£¬²¢ÇÒCSS¾ç±¾cd9dcb1922df26eb999a4405b282809051a18f8aa6e68edb71d619c92ebcf82dµÄ×ÊÔ´¹þÏ£Öµµ¼ÖÂ14ÍйÜÀàËÆÍøÂç´¹ÂÚÕ¾µãµÄÐÂÓò¡£¡£¡£¡£¡£ÔÚÐí¶àÇéÐÎÏ£¬£¬ £¬£¬×ÓÓòµÄ±àд·½·¨ÍêÈ«Ïàͬ£¬£¬ £¬£¬´Ó¶øÓÕÆ­Á˸ոÕÍйÜÔÚ²î±ðÓòÖеÄͳһ×éÖ¯¡£¡£¡£¡£¡£Ê¹ÓÃÃüÃûÔ¼¶¨Ä£Ê½ºÍÐÂÓò×÷Ϊ½øÒ»²½µÄÊàŦµã£¬£¬ £¬£¬µ¼Ö·¢Ã÷ÁËÕë¶Ô½øÒ»²½Õþ¸®²É¹ºÐ§À͵ÄÍøÂç´¹ÂÚÕ¾µã¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ͼ6.ÓÕÆ­×éÖ¯µÄ»ù´¡½á¹¹¸ÅÊö


IPµØµãΪ31.210.96.221Íйܴ˻µÄÍøÂç´¹ÂÚÍøÕ¾µÄÓòÓÚ2019Äê10ÔÂ28ÈÕÊ×´Î×¢²á£¬£¬ £¬£¬ÓòÃûÒÔserver-bidsync.best×îÏÈ¡£¡£¡£¡£¡£¸ÃIPµØµãÒÑÔÚÍÁ¶úÆä×¢²á£¬£¬ £¬£¬²¢ÇÒÒÑÍùÔø¼ÓÈë¶ñÒâ»î¶¯¡£¡£¡£¡£¡£ÆäÖÐ×îÍ»³öµÄÊÇ¡°leastinfo.com¡±Óò£¬£¬ £¬£¬¸ÃÓòÔÚÒ»´ÎÕë¶ÔÑÇÖÞ½ðÈÚ»ú¹¹ÒÔ¼°ÎÚ¶û¶¼ÓïºÍ°¢À­²®ÓïʹÓÃÕßʹÓõÄÈí¼þµÄÁãÈÕÎó²î¹¥»÷»î¶¯ÖзºÆð¡£¡£¡£¡£¡£ÆäËûÈý¸öIPµØµã¶¼ÔÚÂÞÂíÄáÑÇ×¢²á¡£¡£¡£¡£¡£×éÖ¯»¹±»Ã°³äÔÚÕýµ±Óò¡°newnepaltreks.com¡±£¬£¬ £¬£¬¡°lazapateriadematilda.cl¡±ºÍ¡°onsearch¡±ÖеÄÍøÂç´¹ÂÚÍøÕ¾ËùÓÕÆ­£¬£¬ £¬£¬ÕâÐ©ÍøÕ¾¿ÉÄÜÒѾ­Êܵ½ÆÆË𡣡£¡£¡£¡£


ÊÂÎñ½áÂÛ


ÕâÏîÆ¾Ö¤ÍøÂç»î¶¯Ö÷ÒªÕë¶ÔÕþ¸®ÕбêºÍ²É¹ºÐ§ÀÍ¡£¡£¡£¡£¡£¶ÔÕâЩЧÀ͵ĹØ×¢Åú×¢£¬£¬ £¬£¬ÍþвÐÐΪÕß¶ÔÄ¿µÄÕþ¸®µÄDZÔڳаüÉ̺Í/¹©Ó¦É̸ÐÐËȤ¡£¡£¡£¡£¡£¸Ã¶´²ìÁ¦µÄÄ¿µÄ¿ÉÄÜÊÇΪÁËʹ¾ºÕùµÐÊÖʤ³ö¶ø½ÓÄɵľ­¼Ã¼¤Àø²½·¥£¬£¬ £¬£¬»òÕßÊÇÓйØÇ±ÔÚ¹©Ó¦ÉÌÓëÏà¹ØÕþ¸®Ö®¼äµÄÐÅÈιØÏµµÄ¸üºã¾Ã¶´²ìÁ¦¡£¡£¡£¡£¡£ÖîÔÆÔÆÀàµÄ»î¶¯ºÜÄÑÌá·À£¬£¬ £¬£¬ÓÉÓÚ³ý·ÇÍйÜÍøÂç´¹ÂÚÒ³ÃæµÄÓò±»ÒÔΪÊǶñÒâµÄ£¬£¬ £¬£¬²»È»×éÖ¯·À»ðǽ½«²»»á×èÖ¹Ëü¡£¡£¡£¡£¡£Õýµ±Õ¾µã»¹ÍйÜÁË´¹ÂÚÒ³Ãæ£¬£¬ £¬£¬²¢ÇÒ¿ÉÄÜÔÚ¾ºÑ¡»î¶¯ÖÐÔâµ½ÆÆË𡣡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.anomali.com/resources/whitepapers/phishing-campaign-targets-login-credentials-of-multiple-us-international-government-procurement-services