AMCAÊý¾Ýй¶»¹²¨¼°Ô¼770ÍòLabCorp¿Í»§£»£»£»£»£»£»ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë
Ðû²¼Ê±¼ä 2019-06-06
1.AMCAÊý¾Ýй¶»¹²¨¼°Ô¼770ÍòLabCorp¿Í»§
2.UChicago MedicineÒâÍâй¶150Íò¾èÔùÕßÐÅÏ¢
ÓÉÓÚElasticSearchЧÀÍÆ÷δÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬UChicago MedicineÒâÍâй¶Áè¼Ý150Íò¾èÔùÕßµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ÕâÒ»ÊÂÎñÊÇÓÉÇå¾²Ñо¿Ô±Bob DiachenkoÔÚ5ÔÂ28ÈÕ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÔÚ½Óµ½±¨¸æºó£¬£¬£¬£¬£¬£¬£¬¸Ã´óѧÔÚ48СʱÄÚ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»£»¤²½·¥¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý¿â¾ÞϸΪ34GB£¬£¬£¬£¬£¬£¬£¬°üÀ¨¾èÔùÕßµÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢ÐԱ𡢻éÒö״̬¡¢¹¤ÒµÐÅÏ¢µÈ¡£¡£¡£¡£
3.ÓÌÌ«ÉçÇøÔ¼»áAPP JCrushÒâÍâй¶20ÍòÓû§¼Í¼
רΪÓÌÌ«ÉçÇøÌṩЧÀ͵ÄÔ¼»áAPP JCrushÒòÊý¾Ý¿âδÉèÃÜÂëÒâÍâй¶½ü20ÍòÓû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢ÐÔ±ð¡¢ÓÊÏ䵨µã¡¢IPµØµã¡¢µØÀíλÖᢳöÉúÈÕÆÚ¡¢×Ú½ÌÐÅÑöÒÔ¼°ÕÕÆ¬µÈ¡£¡£¡£¡£Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷ÁËÕâһй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â´æ´¢µÄÄÚÈݾùδ¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐһЩÓû§¼Í¼¿ÉÖ±½ÓÓëFacebook ID¹ØÁª¡£¡£¡£¡£JCrushĸ¹«Ë¾Northsight CapitalÒѶԸÃÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»£»¤²½·¥¡£¡£¡£¡£
4.ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë
ƾ֤Malwarebytes LabsÐû²¼µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·µÄCloudFront CDN±»¹¥»÷Õß×¢ÈëÖ¼ÔÚÇÔÈ¡ÒøÐп¨ÐÅÏ¢µÄMagecart¶ñÒâ´úÂë¡£¡£¡£¡£ÕâЩ¶ñÒâJavaScript¾ç±¾Ê¹ÓÃBase64ºÍhex±àÂëÀ´Òþ²ØÆäpayload£¬£¬£¬£¬£¬£¬£¬²¢½«ÇÔÈ¡µÄÐÅÏ¢±àÂëºó·¢Ëͻع¥»÷ÕߵĻù´¡ÉèÊ©¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ê¹ÓõÄһЩÓòÃû£¨ÀýÈçfont-assets[.]com£©Óë֮ǰRiskIQ±¨¸æµÄһЩ¹©Ó¦Á´¹¥»÷Ïàͬ¡£¡£¡£¡£
5.APT×éÖ¯Gamaredonй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼
Cybaze-Yoroi ZLABÑо¿Ö°Ô±·¢Ã÷APT×éÖ¯Gamaredon GroupµÄз¸·¨»î¶¯£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼µÄÕþ¸®»ú¹¹¡¢¾ü¶Ó¼°Ö´·¨²¿·ÖµÄ¹ÙÔ±¡£¡£¡£¡£¹¥»÷Õß·¢Ë͵Ĵ¹ÂÚÓʼþÖаüÀ¨¶ñÒâµÄRAR¸½¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã¸½¼þÖаüÀ¨¡°.scr¡±ÃûÌõĶñÒâÎĵµ£¬£¬£¬£¬£¬£¬£¬ÆäÏÂÔØ²¢Ö´ÐеÄpayloadÓÃÓÚÇÔȡϵͳÐÅÏ¢¼°ÊÍ·ÅÔ¶¿ØÄ¾ÂíUltraVNC¡£¡£¡£¡£¸ÃscrÎļþÔÚVirusTotalÉϵļì²âÂʽϵͣ¬£¬£¬£¬£¬£¬£¬Ö»ÓÐ4¸öɱÈí½«Æäʶ±ðΪ¶ñÒâÎļþ¡£¡£¡£¡£
6.Ðéα¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Cryptohopper£¬£¬£¬£¬£¬£¬£¬·Ö·¢VidarľÂí
Ñо¿Ö°Ô±Fumik0_·¢Ã÷¹¥»÷ÕßÒѾ½¨ÉèÁËÒ»¸öÐéαµÄ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Cryptohopper£¬£¬£¬£¬£¬£¬£¬µ±Óû§»á¼û¸Ãƽ̨ʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØÒ»¸öSetup.exe£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÎļþʹÓÃCryptoHopperµÄlogo£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÊÇVidarľÂíµÄ±äÌå¡£¡£¡£¡£¸Ã±äÌå»áÔÚÊÜѬȾµÄ»úеÉϼÓÔØÒ»¸ö¶ñÒâ¿ó¹¤ºÍÒ»¸ö¼ôÌù°åÐ®ÖÆ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄƾ֤ºÍ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/around-77-million-labcorp-customers-impacted-from-amca-data-breach-c3edd7542.UChicago MedicineÒâÍâй¶150Íò¾èÔùÕßÐÅÏ¢
ÓÉÓÚElasticSearchЧÀÍÆ÷δÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬UChicago MedicineÒâÍâй¶Áè¼Ý150Íò¾èÔùÕßµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ÕâÒ»ÊÂÎñÊÇÓÉÇå¾²Ñо¿Ô±Bob DiachenkoÔÚ5ÔÂ28ÈÕ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÔÚ½Óµ½±¨¸æºó£¬£¬£¬£¬£¬£¬£¬¸Ã´óѧÔÚ48СʱÄÚ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»£»¤²½·¥¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý¿â¾ÞϸΪ34GB£¬£¬£¬£¬£¬£¬£¬°üÀ¨¾èÔùÕßµÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢ÐԱ𡢻éÒö״̬¡¢¹¤ÒµÐÅÏ¢µÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/private-info-of-over-15m-donors-exposed-by-uchicago-medicine/3.ÓÌÌ«ÉçÇøÔ¼»áAPP JCrushÒâÍâй¶20ÍòÓû§¼Í¼
רΪÓÌÌ«ÉçÇøÌṩЧÀ͵ÄÔ¼»áAPP JCrushÒòÊý¾Ý¿âδÉèÃÜÂëÒâÍâй¶½ü20ÍòÓû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢ÐÔ±ð¡¢ÓÊÏ䵨µã¡¢IPµØµã¡¢µØÀíλÖᢳöÉúÈÕÆÚ¡¢×Ú½ÌÐÅÑöÒÔ¼°ÕÕÆ¬µÈ¡£¡£¡£¡£Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷ÁËÕâһй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â´æ´¢µÄÄÚÈݾùδ¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐһЩÓû§¼Í¼¿ÉÖ±½ÓÓëFacebook ID¹ØÁª¡£¡£¡£¡£JCrushĸ¹«Ë¾Northsight CapitalÒѶԸÃÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»£»¤²½·¥¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/06/04/jcrush-exposed-data-messages/4.ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë
ƾ֤Malwarebytes LabsÐû²¼µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·µÄCloudFront CDN±»¹¥»÷Õß×¢ÈëÖ¼ÔÚÇÔÈ¡ÒøÐп¨ÐÅÏ¢µÄMagecart¶ñÒâ´úÂë¡£¡£¡£¡£ÕâЩ¶ñÒâJavaScript¾ç±¾Ê¹ÓÃBase64ºÍhex±àÂëÀ´Òþ²ØÆäpayload£¬£¬£¬£¬£¬£¬£¬²¢½«ÇÔÈ¡µÄÐÅÏ¢±àÂëºó·¢Ëͻع¥»÷ÕߵĻù´¡ÉèÊ©¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ê¹ÓõÄһЩÓòÃû£¨ÀýÈçfont-assets[.]com£©Óë֮ǰRiskIQ±¨¸æµÄһЩ¹©Ó¦Á´¹¥»÷Ïàͬ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/06/magecart-skimmers-found-on-amazon-cloudfront-cdn/5.APT×éÖ¯Gamaredonй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼
Cybaze-Yoroi ZLABÑо¿Ö°Ô±·¢Ã÷APT×éÖ¯Gamaredon GroupµÄз¸·¨»î¶¯£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼µÄÕþ¸®»ú¹¹¡¢¾ü¶Ó¼°Ö´·¨²¿·ÖµÄ¹ÙÔ±¡£¡£¡£¡£¹¥»÷Õß·¢Ë͵Ĵ¹ÂÚÓʼþÖаüÀ¨¶ñÒâµÄRAR¸½¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã¸½¼þÖаüÀ¨¡°.scr¡±ÃûÌõĶñÒâÎĵµ£¬£¬£¬£¬£¬£¬£¬ÆäÏÂÔØ²¢Ö´ÐеÄpayloadÓÃÓÚÇÔȡϵͳÐÅÏ¢¼°ÊÍ·ÅÔ¶¿ØÄ¾ÂíUltraVNC¡£¡£¡£¡£¸ÃscrÎļþÔÚVirusTotalÉϵļì²âÂʽϵͣ¬£¬£¬£¬£¬£¬£¬Ö»ÓÐ4¸öɱÈí½«Æäʶ±ðΪ¶ñÒâÎļþ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/security-researchers-uncover-new-campaign-linked-to-gamaredon-group-44a5eb926.Ðéα¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Cryptohopper£¬£¬£¬£¬£¬£¬£¬·Ö·¢VidarľÂí
Ñо¿Ö°Ô±Fumik0_·¢Ã÷¹¥»÷ÕßÒѾ½¨ÉèÁËÒ»¸öÐéαµÄ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Cryptohopper£¬£¬£¬£¬£¬£¬£¬µ±Óû§»á¼û¸Ãƽ̨ʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØÒ»¸öSetup.exe£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÎļþʹÓÃCryptoHopperµÄlogo£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÊÇVidarľÂíµÄ±äÌå¡£¡£¡£¡£¸Ã±äÌå»áÔÚÊÜѬȾµÄ»úеÉϼÓÔØÒ»¸ö¶ñÒâ¿ó¹¤ºÍÒ»¸ö¼ôÌù°åÐ®ÖÆ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄƾ֤ºÍ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-cryptocurrency-trading-site-pushes-crypto-stealing-malware/


¾©¹«Íø°²±¸11010802024551ºÅ