ºÚ¿Íɾ³ýÊý°ÙÃûGit¿ª·¢ÕߵĴúÂë¿â£»£»£» £»£»200Ëù´óѧµÄУ԰ÊÐËÁѬȾMagecart£»£»£» £»£»AMC Networksй¶160ÍòÓû§Êý¾Ý

Ðû²¼Ê±¼ä 2019-05-05
1¡¢ºÚ¿Íɾ³ýÊý°ÙÃûGit¿ª·¢ÕߵĴúÂë¿â£¬£¬£¬£¬£¬£¬£¬ÓûÀÕË÷Êê½ð

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ºÚ¿ÍÃé×¼Êý°ÙÃûGitHub¡¢GitLabºÍBitbucketÓû§£¬£¬£¬£¬£¬£¬£¬É¾³ýÆä´úÂë¿â²¢ÀÕË÷Êê½ð¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGitHubÉÏ·¢Ã÷392¸ö´úÂë¿âÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÕâЩ´úÂë¿â¾ù±»Ò»¸öÆßÄêǰ£¨2012Äê1ÔÂ25ÈÕ£©½¨ÉèµÄÕ˺Ågitbackupɾ³ý¡£¡£¡£¡£¡£¹¥»÷ÕßÒªÇóÖ§¸¶0.1±ÈÌØ±Ò£¨Ô¼568ÃÀÔª£©µÄÊê½ð£¬£¬£¬£¬£¬£¬£¬µ«×èÖ¹ÏÖÔÚ²¢Ã»ÓÐÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£StackExchangeÇå¾²ÂÛ̳µÄ³ÉÔ±·¢Ã÷ºÚ¿ÍÏÖʵÉϲ¢Î´É¾³ý´úÂë¿â£¬£¬£¬£¬£¬£¬£¬½ö½öÊǸıäÁËgit commit±êÍ·£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅijЩÇéÐÎÏ¿ÉÒÔ»Ö¸´´úÂë¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/attackers-wiping-github-and-gitlab-repos-leave-ransom-notes/

2¡¢Áè¼Ý200Ëù´óѧµÄУ԰ÊÐËÁѬȾMagecart¶ñÒâ¾ç±¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Áè¼Ý200ËùÃÀ¹úºÍ¼ÓÄôó´óѧµÄÔÚÏßУ԰ÊÐËÁÔâµ½Magecart¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾ÓÉPrismWebµç×ÓÉÌÎñƽ̨Ìṩ֧³Ö£¬£¬£¬£¬£¬£¬£¬µ«PrismWebÓÚ4ÔÂ14ÈÕ±»×¢Èë¶ñÒâµÄMagecart¾ç±¾¡£¡£¡£¡£¡£¸ÃJavaScript¾ç±¾ÓÃÓÚÇÔÈ¡¿Í»§µÄÖ§¸¶ÐÅÏ¢ºÍСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÅÓÿ¨ºÅ¡¢ÓÐÓÃÆÚ¡¢¿¨ÀàÐÍ¡¢ÑéÖ¤ºÅÂ루CVN£©ÒÔ¼°³Ö¿¨È˵ÄÐÕÃû¡¢µØµãºÍµç»°ºÅÂëµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¹¥»÷ÕßÍøÂçÕâЩÐÅÏ¢ºó½«ÐÅÏ¢´æ´¢ÎªJSONÃûÌ㬣¬£¬£¬£¬£¬£¬¾­ÓÉAES¼ÓÃܺͱàÂëºó£¬£¬£¬£¬£¬£¬£¬×÷ΪHTMLͼÏñÔªËØµÄURL²ÎÊý·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ç÷ÊÆ¿Æ¼¼µÄÑо¿ÍŶÓÒÔΪ¸Ã¹©Ó¦Á´¹¥»÷ÊÇÓÉÐµķ¸·¨ÍÅ»ïMirrorthiefÌᳫµÄ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÏêϸµÄÊÜÓ°ÏìÈËÊý¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-200-college-campus-stores-infected-with-card-stealing-scripts/

3¡¢Ñо¿ÍŶÓÐû²¼ºóCoinhiveʱ´úµÄ¶ñÒâÍÚ¿ó»î¶¯ÆÊÎö

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Malwarebytes LabsÑо¿ÍŶÓÐû²¼ºóCoinhiveʱ´úµÄ¶ñÒâÍÚ¿ó»î¶¯ÆÊÎö¡£¡£¡£¡£¡£CoinhiveÔÚ2019Äê3ÔÂ8ÈչرÕÁËЧÀÍ£¬£¬£¬£¬£¬£¬£¬µ«´ó×ÚµÄÍøÕ¾ºÍ·ÓÉÆ÷ÈÔ±£´æCoinhiveÒÅÁô£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈÔ¶ÔCoinhive¿â·¢³öÇëÇ󡣡£¡£¡£¡£ÔÚÒÑÍùÒ»ÖÜÄÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿ÍŶӯ½¾ùÌìÌì¼Í¼µ½5Íò¸öÕë¶ÔCoinhiveµÄÇëÇ󡣡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬£¬ÕâЩÇëÇó½«ÎÞ·¨ÅþÁ¬µ½Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬´Ó¶ø²»¿É¾ÙÐÐÍÚ¿ó»î¶¯¡£¡£¡£¡£¡£µ«»ùÓÚÍøÂçµÄ¿ó¹¤²¢Î´×èÖ¹£¬£¬£¬£¬£¬£¬£¬ÀýÈçCoinhiveµÄ¾ºÕùµÐÊÖCryptoLoot¡¢CoinIMP£¬£¬£¬£¬£¬£¬£¬Ñо¿ÍŶÓÌìÌì¶¼»á¼ì²âµ½Áè¼Ý100Íò´ÎÕë¶ÔCryptoLootµÄÇëÇ󡣡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/

4¡¢ÒøÐÐľÂíRetefe¾íÍÁÖØÀ´£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÈðÊ¿ºÍµÂ¹ú

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
4Ô·ÝProofpointÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíRetefeµÄ¹¥»÷ÊýÄ¿³ÊÉÏÉýÇ÷ÊÆ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×îÏÈÕë¶ÔÈðÊ¿ºÍµÂ¹úµÄÒøÐÐÓû§£¬£¬£¬£¬£¬£¬£¬²»¹ÜÊÇWindowsÕÕ¾ÉmacOSƽ̨¡£¡£¡£¡£¡£ÐµĹ¥»÷»î¶¯ÖÐRetefeÒ²¸ü¸ÄÁËһЩ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÀýÈçʹÓÃTLS/SSLËíµÀЧÀÍStunnelÌæ»»TOR×÷ΪÊðÀíÖØ¶¨ÏòºÍC&CÉèÖÃͨµÀ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÒÔǰRetefe³£ÓëPowerShellÏÂÔØÆ÷sLoad¹ØÁª£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÕë¶ÔÈðÊ¿µÄ¹¥»÷»î¶¯ÖиöñÒâÈí¼þʹÓÃSmoke Loader×÷ΪÖÐÐĽ׶εÄÏÂÔØÆ÷¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.scmagazine.com/home/security-news/__trashed/

5¡¢ÐÂÀÕË÷Èí¼þMegaCortex£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÃé×¼ÆóÒµÍøÂç

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
SophosÑо¿ÍŶӷ¢Ã÷Ö÷ÒªÃé×¼ÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þMegaCortex£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þÒÑѬȾÁËÃÀ¹ú¡¢Òâ´óÀû¡¢¼ÓÄô󡢷¨¹ú¡¢ºÉÀ¼ºÍ°®¶ûÀ¼µÄÓû§¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÀÕË÷Èí¼þÊÇзºÆðµÄ£¬£¬£¬£¬£¬£¬£¬Òò´ËÏÖÔÚ¶ÔÆä¼ÓÃÜËã·¨¡¢ÔõÑù»ñµÃÆóÒµÍøÂçµÄ»á¼ûȨÏÞÒÔ¼°ÊÇ·ñÓÐÈËÖ§¸¶ÁËÊê½ðµÈÇéÐÎÖªÖ®ÉõÉÙ¡£¡£¡£¡£¡£Sophos·¢Ã÷ѬȾÁËMegaCortexµÄÆóÒµÍøÂçÉϱ£´æEmotet»òQakbotľÂí£¬£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÄÜÊÇÏòľÂí¹¥»÷ÕßÖ§¸¶ÓöÈÒÔ»ñµÃ»á¼ûȨÏÞ¡£¡£¡£¡£¡£Ò»µ©½øÈëÍøÂ磬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáͨ¹ýWindowsÓò¿ØÖÆÆ÷À´Èö²¥²¢Ñ¬È¾Õû¸öÍøÂç¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-megacortex-ransomware-found-targeting-business-networks/