¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£»£»£»ITЧÀ͹«Ë¾CognizantÔâMaze¹¥»÷£¬£¬£¬ £¬¿Í»§Êý¾Ý¿ÉÄÜй¶

Ðû²¼Ê±¼ä 2020-04-20

1.¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬£¬£¬ £¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¡£¾ÝZDNet±¨µÀ£¬£¬£¬ £¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬£¬£¬ £¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ¡£¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­ÐÞ¸´Á˺ڿÍʹÓõÄÎó²î£¬£¬£¬ £¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2.ºÚ¿ÍʹÓÃCOVID-19ÓïÒô´¹ÂÚÓʼþ¹¥»÷Office 365Óû§


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾ÝPhishLabsÑо¿·¢Ã÷£¬£¬£¬ £¬ºÚ¿ÍÕýÔÚʹÓÃÒÔ COVID-19ΪÖ÷ÌâµÄÓïÒôÓʼþ¶ÔOffice 365Óû§Ìá³«ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬ £¬ÒÔÇÔÈ¡Óû§µÄÉϰ¶Æ¾Ö¤¡£¡£¸ÃÓʼþ°üÀ¨Ò»¸öÃûΪATT30406µÄÐéαÒôƵÎļþ£¬£¬£¬ £¬ÎļþÖÐÒþ²ØÓÐÒ»¸öÁ´½Ó£¬£¬£¬ £¬¶øµ±Óû§µã»÷´ËÎļþʱ£¬£¬£¬ £¬½«±»¶¨Ïòµ½ÐèÒªµÇ¼ƾ֤µÄMicrosoft Office 365£¨O365£©ÍøÂç´¹ÂÚÒ³Ãæ¡£¡£²¢ÇÒ£¬£¬£¬ £¬ºÚ¿ÍʹÓÃ.htmµÄÎļþÃûÌÃÀ´Òþ²Ø¸Ã¶ñÒâÁ´½Ó£¬£¬£¬ £¬Î±×°ÕëÑÔÒôÓʼþµÄ³£¼ûÒôƵ¸½¼þÓÕʹÓû§·­¿ª¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityboulevard.com/2020/04/covid-19-phishing-update-voicemail-attacks-surface-targeting-office-365-users/


3.ITЧÀ͹«Ë¾CognizantÔâMaze¹¥»÷£¬£¬£¬ £¬¿Í»§Êý¾Ý¿ÉÄÜй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ITЧÀ͹«Ë¾CognizantÓÚÉÏÖÜÎåÍíÉÏÔâµ½ÁËMaze RansomwareÍÅ»ïµÄ¹¥»÷£¬£¬£¬ £¬Æä¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¡£CognizantÌåÏÖ£¬£¬£¬ £¬´Ë´Î¹¥»÷µ¼ÖÂijЩ¿Í»§µÄЧÀͱ»ÖÐÖ¹£¬£¬£¬ £¬¶ø¹«Ë¾Ò²ÔÚÆð¾¢½ÓÄɲ½·¥½â¾ö´ËÊ¡£¡£ËäÈ»MazeÍÅ»ïÔÝʱ·ñ¶¨ÁËÕâÒ»¹¥»÷ÊÂÎñ£¬£¬£¬ £¬µ«Æ¾Ö¤Cognizant¹«Ë¾Ïò¿Í»§Ðû²¼µÄIoCÁбí£¬£¬£¬ £¬¿ÉÒÔÈ·ÈÏÕâЩIoCÓëMazeÓйØ¡£¡£¸ÃIoCÁбí°üÀ¨C2ЧÀÍÆ÷µÄIPµØµãÒÔ¼°kepstl32.dll¡¢memes.tmpºÍmaze.dllÎļþµÄÎļþ¹þÏ£¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬£¬£¬ £¬MazeºÚ¿Í¿ÉÄÜÒѾ­ÔÚCognizantµÄÍøÂçÖÐDZÔÚÁËÊýÖÜÖ®¾Ã£¬£¬£¬ £¬²¢ÇÒÔÚ͵ȡÎļþºó²ÅʹÓÃPowerShell EmpireµÈ¹¤¾ß°²ÅÅÀÕË÷Èí¼þ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/it-services-giant-cognizant-suffers-maze-ransomware-cyber-attack/


4.ÃÀ¹ú°ÂÀû°²ÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬ÊÐÕþϵͳÈÔδ»Ö¸´


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÉÏÖÜÎåÔçÉÏ£¬£¬£¬ £¬ÃÀ¹ú°ÂÀû°²ÊÐÕþ¸®Ðû²¼ÆäÊÐÕþϵͳÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬´ó²¿·ÖÅÌËã»úϵͳÀëÏßÔ¼ÎåСʱ£¬£¬£¬ £¬µ«ÏÖÔÚϵͳÈÔδÍêÈ«ÐÞ¸´¡£¡£¸ÃÊÐÊг¤Bill AielloÌåÏÖ£¬£¬£¬ £¬ºÚ¿ÍÊÇͨ¹ýһ̨ÀϾɵġ¢Ã»ÓÐʵʱ¸üÐÂÉý¼¶µÄЧÀÍÆ÷Ìᳫ¹¥»÷µÄ¡£¡£AielloÖ¸³öºÚ¿ÍûÓдӸÃÊеÄϵͳÖлá¼û»òÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ £¬²¢ÇÒË®ÎñЧÀ͵ÄÃÅ»§Ö§¸¶ÍøÕ¾ÈÔÔÚÕý³£ÔËÓª¡£¡£¸ÃÊÐÔ±¹¤µÄµç×ÓÓʼþ¾ùÒѱ¸·Ý£¬£¬£¬ £¬ÊÐÕþϵͳԤ¼ÆÔÚ±¾ÖܻᱻÍêÈ«ÐÞ¸´¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.oleantimesherald.com/news/ransomware-attack-temporarily-knocks-out-olean-city-systems/article_2fdf240f-4e44-54bb-af36-65d5fbc730c8.html


5.ÒøÐÐľÂíUrsnifбäÖÖ£¬£¬£¬ £¬Ö÷ÒªÕë¶ÔÒâ´óÀûÆóÒµ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


YoroiÑо¿·¢Ã÷ÁËÒ»ÖÖÕë¶ÔÒâ´óÀûÆóÒµµÄÒøÐÐľÂíUrsnifбäÖÖ¡£¡£´Ë±äÖÖÖ÷ÒªÊÇʹÓÃÍøÂç´¹ÂÚÕ½ÂÔ£¬£¬£¬ £¬·¢ËÍ´øÓС°Avviso di Pagamento_xxxx_date¡±¸½¼þµÄÀ¬»øÓʼþ¡£¡£Ïà±ÈUrsnif¼Ò×åµÄÆäËû±äÖÖ£¬£¬£¬ £¬Ð±äÖÖ¹²ÓÐÁ½¸öÖ÷ÒªµÄÉý¼¶£¬£¬£¬ £¬Ê×ÏÈËüʹÓÃ΢ÈíExcel 4.0ºêÀ´Ìӱܲ¡¶¾¼à²âºÍÆÊÎö£¬£¬£¬ £¬ÁíÍ⣬£¬£¬ £¬Ëü¾ßÓÐÁ½¸ö²î±ðµÄC2£¬£¬£¬ £¬ÆäÖÐÒ»¸öC2Ö»ÓÃÓÚ×¢²áUUIDÀ´±êʶºÍ¸ú×ÙÄ¿µÄ»úе¡£¡£


Ô­ÎÄÁ´½Ó£º

https://yoroi.company/research/a-brand-new-ursnif-isfb-campaign-targets-italian-organizations/


6.΢Èíµ·»ÙÒÑѬȾ40Íò×°±¸µÄ½©Ê¬ÍøÂç



ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


΢ÈíÌåÏÖÆäÊý×Ö·¸·¨²¿·Ö£¨DCU£©·¢Ã÷²¢×ÊÖú´Ý»ÙÁËÒÑѬȾ40Íǫ̀װ±¸µÄ½©Ê¬ÍøÂ磬£¬£¬ £¬¸Ã½©Ê¬ÍøÂçµÄC2ЧÀÍÆ÷ÊÇLEDµÆµÄ¿ØÖÆÌ¨¡£¡£¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚÖÖÖÖÄ¿µÄ£¬£¬£¬ £¬°üÀ¨´¹ÂÚ¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢ÀÕË÷Èí¼þpayload½»¸¶ÒÔ¼°ÌᳫDDoS¹¥»÷µÈ¡£¡£Î¢ÈíÌåÏָý©Ê¬ÍøÂçÿÖÜ·¢Ë͵ĶñÒâÄÚÈݶà´ï1TB¡£¡£×Ô2010ÄêÒÔÀ´£¬£¬£¬ £¬Î¢ÈíDCUÍŶÓÒÑÔÚÈ«ÇòISP¡¢ÓòÃû×¢²á»ú¹¹¡¢CERTºÍÖ´·¨»ú¹¹µÄ×ÊÖúϹرÕÁË22¸ö½©Ê¬ÍøÂç¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-helped-stop-a-botnet-controlled-via-an-led-light-console/