¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£»£»ITЧÀ͹«Ë¾CognizantÔâMaze¹¥»÷£¬ £¬£¬£¬£¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶

Ðû²¼Ê±¼ä 2020-04-20

1.¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬£¬£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ ¡£¡£¡£¡£¡£¡£¾ÝZDNet±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬ £¬£¬£¬£¬£¬£¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ ¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã ¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­ÐÞ¸´Á˺ڿÍʹÓõÄÎó²î£¬ £¬£¬£¬£¬£¬£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2.ºÚ¿ÍʹÓÃCOVID-19ÓïÒô´¹ÂÚÓʼþ¹¥»÷Office 365Óû§


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¾ÝPhishLabsÑо¿·¢Ã÷£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚʹÓÃÒÔ COVID-19ΪÖ÷ÌâµÄÓïÒôÓʼþ¶ÔOffice 365Óû§Ìá³«ÍøÂç´¹ÂÚ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄÉϰ¶Æ¾Ö¤ ¡£¡£¡£¡£¡£¡£¸ÃÓʼþ°üÀ¨Ò»¸öÃûΪATT30406µÄÐéαÒôƵÎļþ£¬ £¬£¬£¬£¬£¬£¬ÎļþÖÐÒþ²ØÓÐÒ»¸öÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬¶øµ±Óû§µã»÷´ËÎļþʱ£¬ £¬£¬£¬£¬£¬£¬½«±»¶¨Ïòµ½ÐèÒªµÇ¼ƾ֤µÄMicrosoft Office 365£¨O365£©ÍøÂç´¹ÂÚÒ³Ãæ ¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃ.htmµÄÎļþÃûÌÃÀ´Òþ²Ø¸Ã¶ñÒâÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬Î±×°ÕëÑÔÒôÓʼþµÄ³£¼ûÒôƵ¸½¼þÓÕʹÓû§·­¿ª ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityboulevard.com/2020/04/covid-19-phishing-update-voicemail-attacks-surface-targeting-office-365-users/


3.ITЧÀ͹«Ë¾CognizantÔâMaze¹¥»÷£¬ £¬£¬£¬£¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ITЧÀ͹«Ë¾CognizantÓÚÉÏÖÜÎåÍíÉÏÔâµ½ÁËMaze RansomwareÍÅ»ïµÄ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬Æä¿Í»§Êý¾Ý¿ÉÄÜй¶ ¡£¡£¡£¡£¡£¡£CognizantÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷µ¼ÖÂijЩ¿Í»§µÄЧÀͱ»ÖÐÖ¹£¬ £¬£¬£¬£¬£¬£¬¶ø¹«Ë¾Ò²ÔÚÆð¾¢½ÓÄɲ½·¥½â¾ö´ËÊ ¡£¡£¡£¡£¡£¡£ËäÈ»MazeÍÅ»ïÔÝʱ·ñ¶¨ÁËÕâÒ»¹¥»÷ÊÂÎñ£¬ £¬£¬£¬£¬£¬£¬µ«Æ¾Ö¤Cognizant¹«Ë¾Ïò¿Í»§Ðû²¼µÄIoCÁбí£¬ £¬£¬£¬£¬£¬£¬¿ÉÒÔÈ·ÈÏÕâЩIoCÓëMazeÓÐ¹Ø ¡£¡£¡£¡£¡£¡£¸ÃIoCÁбí°üÀ¨C2ЧÀÍÆ÷µÄIPµØµãÒÔ¼°kepstl32.dll¡¢memes.tmpºÍmaze.dllÎļþµÄÎļþ¹þÏ£ ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬ £¬£¬£¬£¬£¬£¬MazeºÚ¿Í¿ÉÄÜÒѾ­ÔÚCognizantµÄÍøÂçÖÐDZÔÚÁËÊýÖÜÖ®¾Ã£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒÔÚ͵ȡÎļþºó²ÅʹÓÃPowerShell EmpireµÈ¹¤¾ß°²ÅÅÀÕË÷Èí¼þ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/it-services-giant-cognizant-suffers-maze-ransomware-cyber-attack/


4.ÃÀ¹ú°ÂÀû°²ÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÊÐÕþϵͳÈÔδ»Ö¸´


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÉÏÖÜÎåÔçÉÏ£¬ £¬£¬£¬£¬£¬£¬ÃÀ¹ú°ÂÀû°²ÊÐÕþ¸®Ðû²¼ÆäÊÐÕþϵͳÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬´ó²¿·ÖÅÌËã»úϵͳÀëÏßÔ¼ÎåСʱ£¬ £¬£¬£¬£¬£¬£¬µ«ÏÖÔÚϵͳÈÔδÍêÈ«ÐÞ¸´ ¡£¡£¡£¡£¡£¡£¸ÃÊÐÊг¤Bill AielloÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÊÇͨ¹ýһ̨ÀϾɵġ¢Ã»ÓÐʵʱ¸üÐÂÉý¼¶µÄЧÀÍÆ÷Ìᳫ¹¥»÷µÄ ¡£¡£¡£¡£¡£¡£AielloÖ¸³öºÚ¿ÍûÓдӸÃÊеÄϵͳÖлá¼û»òÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒË®ÎñЧÀ͵ÄÃÅ»§Ö§¸¶ÍøÕ¾ÈÔÔÚÕý³£ÔËÓª ¡£¡£¡£¡£¡£¡£¸ÃÊÐÔ±¹¤µÄµç×ÓÓʼþ¾ùÒѱ¸·Ý£¬ £¬£¬£¬£¬£¬£¬ÊÐÕþϵͳԤ¼ÆÔÚ±¾ÖܻᱻÍêÈ«ÐÞ¸´ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.oleantimesherald.com/news/ransomware-attack-temporarily-knocks-out-olean-city-systems/article_2fdf240f-4e44-54bb-af36-65d5fbc730c8.html


5.ÒøÐÐľÂíUrsnifбäÖÖ£¬ £¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀûÆóÒµ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


YoroiÑо¿·¢Ã÷ÁËÒ»ÖÖÕë¶ÔÒâ´óÀûÆóÒµµÄÒøÐÐľÂíUrsnifбäÖÖ ¡£¡£¡£¡£¡£¡£´Ë±äÖÖÖ÷ÒªÊÇʹÓÃÍøÂç´¹ÂÚÕ½ÂÔ£¬ £¬£¬£¬£¬£¬£¬·¢ËÍ´øÓС°Avviso di Pagamento_xxxx_date¡±¸½¼þµÄÀ¬»øÓʼþ ¡£¡£¡£¡£¡£¡£Ïà±ÈUrsnif¼Ò×åµÄÆäËû±äÖÖ£¬ £¬£¬£¬£¬£¬£¬Ð±äÖÖ¹²ÓÐÁ½¸öÖ÷ÒªµÄÉý¼¶£¬ £¬£¬£¬£¬£¬£¬Ê×ÏÈËüʹÓÃ΢ÈíExcel 4.0ºêÀ´Ìӱܲ¡¶¾¼à²âºÍÆÊÎö£¬ £¬£¬£¬£¬£¬£¬ÁíÍ⣬ £¬£¬£¬£¬£¬£¬Ëü¾ßÓÐÁ½¸ö²î±ðµÄC2£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öC2Ö»ÓÃÓÚ×¢²áUUIDÀ´±êʶºÍ¸ú×ÙÄ¿µÄ»úе ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://yoroi.company/research/a-brand-new-ursnif-isfb-campaign-targets-italian-organizations/


6.΢Èíµ·»ÙÒÑѬȾ40Íò×°±¸µÄ½©Ê¬ÍøÂç



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÌåÏÖÆäÊý×Ö·¸·¨²¿·Ö£¨DCU£©·¢Ã÷²¢×ÊÖú´Ý»ÙÁËÒÑѬȾ40Íǫ̀װ±¸µÄ½©Ê¬ÍøÂ磬 £¬£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçµÄC2ЧÀÍÆ÷ÊÇLEDµÆµÄ¿ØÖÆÌ¨ ¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚÖÖÖÖÄ¿µÄ£¬ £¬£¬£¬£¬£¬£¬°üÀ¨´¹ÂÚ¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢ÀÕË÷Èí¼þpayload½»¸¶ÒÔ¼°ÌᳫDDoS¹¥»÷µÈ ¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏָý©Ê¬ÍøÂçÿÖÜ·¢Ë͵ĶñÒâÄÚÈݶà´ï1TB ¡£¡£¡£¡£¡£¡£×Ô2010ÄêÒÔÀ´£¬ £¬£¬£¬£¬£¬£¬Î¢ÈíDCUÍŶÓÒÑÔÚÈ«ÇòISP¡¢ÓòÃû×¢²á»ú¹¹¡¢CERTºÍÖ´·¨»ú¹¹µÄ×ÊÖúϹرÕÁË22¸ö½©Ê¬ÍøÂç ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-helped-stop-a-botnet-controlled-via-an-led-light-console/