2019ÄêQ1ÍøÂç·¸·¨Õ½ÂÔºÍÊÖÒÕ±¨¸æ;Windows¸üÐÂÓëɱ¶¾³åÍ»£¬µ¼ÖÂϵͳ¿¨ËÀ£»GootkitºÍAzorult
Ðû²¼Ê±¼ä 2019-04-29
Malwarebytes LabsÐû²¼2019ÄêµÚÒ»¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕ±¨¸æ£¬¸Ã±¨¸æÖ¸³öÆóÒµÔÚµÚÒ»¼¾¶ÈÔâÊܵÄÍþвÔöÌíÁË235%£¬ÓÈÆäÊÇEmotetµÈľÂíºÍÀÕË÷Èí¼þÍþв¡£Õë¶ÔСÎÒ˽¼ÒÏûºÄÕߵĶñÒâÈí¼þÍþвϽµÁ˽ü40%¡£Òƶ¯×°±¸ºÍMac×°±¸Ô½À´Ô½³ÉΪ¹ã¸æÈí¼þµÄÄ¿µÄ£¬Mac¶ñÒâÈí¼þ´Ó2018ÄêQ4µ½2019ÄêQ1ÔöÌíÁË60%£¬¹ã¸æÈí¼þÔòÔöÌíÁË200%¡£ÔÚÈ«ÇòÍþв¼ì²âÂÊÖÐÃÀ¹ú×î¸ß£¬Îª47£¥£¬Ó¡¶ÈÄáÎ÷ÑÇΪ9£¥£¬°ÍÎ÷Ϊ8£¥¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/cybercrime/2019/04/labs-cybercrime-tactics-and-techniques-report-finds-businesses-hit-with-235-percent-more-threats-in-q1/2.¹¥»÷ÕßʹÓÃJasperLoader·Ö·¢ÒøÐÐľÂíGootkit£¬Ö÷ÒªÕë¶ÔÖÐÅ·
ÔÚÒÑÍù¼¸¸öÔÂÄÚ˼¿ÆTalosÊӲ쵽JasperLoaderµÄ¶ñÒâ¹¥»÷Ô˶¯µÄÔöÌí£¬¸Ã¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÖÐÅ·¹ú¼Ò£¬ÓÈÆäÊǵ¹úºÍÒâ´óÀû¡£JasperLoader½ÓÄɶà½×¶ÎѬȾÀú³Ì£¬²¢°üÀ¨¶àÖÖ»ìÏýÊÖÒÕ£¬×îÖÕ·Ö·¢ÒøÐÐľÂíGootKit¡£JasperLoaderͨ¹ýÀ¬»øÓʼþ¾ÙÐÐÈö²¥£¬ÕâЩÀ¬»øÓʼþʹÓÃÁËÓÐÓÃÖ¤ÊéµÄÊðÃûÒÔÌá¸ß¿ÉÐŶȡ£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÁгöÁ˹¥»÷Ô˶¯µÄÏêϸIoC¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/04/jasperloader-targets-italy.html3.AzorultľÂíαװ³ÉÐéαWindowsÇå½à¹¤¾ßG-Cleaner¾ÙÐÐÈö²¥
Ñо¿Ö°Ô±Benkow·¢Ã÷AZORultľÂíαװ³ÉÒ»¸öWindowsÇå½à¹¤¾ß¾ÙÐÐÈö²¥£¬¸Ã¹¤Ç©×ÖΪG-Cleaner»òGarbage Cleaner£¬¹¥»÷ÕßÉõÖÁ½¨ÉèÁËÒ»¸öÍøÕ¾gcleaner[.]infoÀ´·Ö·¢¸ÃľÂí¡£¸ÃÍøÕ¾ÖÆ×÷ÓÅÒ죬¿´ÆðÀ´ÀàËÆÓÚÕýµ±µÄÈí¼þ¹ÙÍø£¬²¢ÇÒÈÔÔÚÕý³£ÔËÐС£Ò»µ©Óû§×°ÖøöñÒâÈí¼þ£¬Ä¾Âí¾Í»áÇÔȡϵͳÉϵÄÃÜÂë¡¢Êý¾Ý¼°¼ÓÃÜÇ®±ÒÇ®°üµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-windows-pc-cleaner-drops-azorult-info-stealing-trojan/4.Ñо¿Ö°Ô±Ðû²¼ÐÂÀÕË÷Èí¼þRobbinHoodµÄÑùÌìÖ°Îö
MalwareHunterTeamÐû²¼ÀÕË÷Èí¼þRobbinHoodµÄÑùÌìÖ°Îö¡£RobbinHoodÊÇÀÕË÷Èí¼þÁìÓòµÄ×îгÉÔ±£¬ÆäÄ¿µÄÊÇÆóÒµºÍÍøÂçÉϵÄÅÌËã»ú£¬¸ÃÀÕË÷Èí¼þÖ÷Ҫͨ¹ýRDP·þÎñ»òľÂí¾ÙÐзַ¢¡£¸ÃÑù±¾ÔÚÔËÐÐʱ½«É±ËÀ181¸öÓëɱ¶¾Èí¼þ¡¢Êý¾Ý¿â¡¢Óʼþ·þÎñµÈÓйصÄWindowsÀú³Ì£¬²¢¶Ï¿ªÍøÂç¹²ÏíÅþÁ¬¡£¸ÃÑù±¾ÔÚ¼ÓÃÜÎļþʱ£¬»áΪÿһ¸öÎļþ½¨Éè²î±ðµÄAESÃÜÔ¿£¬È»ºóÓÃRSA¹«Ô¿¼ÓÃÜAESÃÜÔ¿ºÍÔʼÎļþÃû¡£¼ÓÃܺóµÄÎļþ±»ÖØÃüÃûΪEncrypted_[randomstring].enc_robbinhoodµÄÃûÌá£ÏÖÔÚÉÐûÓиÃÀÕË÷Èí¼þµÄ½âÃÜÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/a-closer-look-at-the-robbinhood-ransomware/5.LAZARUS APTй¥»÷Ô˶¯£¬Ê¹ÓöñÒâWORDÎļþÃé×¼MACÓû§
SentinelOneÐû²¼¹ØÓÚLazarus APTй¥»÷Ô˶¯µÄÆÊÎö±¨¸æ¡£¹¥»÷ÕßʹÓöñÒâWordÎĵµÕë¶ÔMACÓû§£¬¸ÃÎĵµµÄVBA¾ç±¾Ê×Ïȼì²âÊÇ·ñÔÚMacÉÏÔËÐУ¬ÈôÊÇÊÇ£¬ÔòcurlÎļþhttps//nzssdm.com/assets/mt.datµ½ÍâµØ¡£mt.datµÄpayloadÊÇÒ»¸öMach-OµÄ64λ¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþÊÇÒ»¸ö¶¨ÖƵĺóÃÅ£¬µ«¹¦Ð§Éв»Ã÷È·£¬ÆäC2·þÎñÆ÷µÄIPµØµãÈÔÈ»¿ÉÓá£
ÔÎÄÁ´½Ó£º
https://www.sentinelone.com/blog/lazarus-apt-targets-mac-users-poisoned-word-document/6.×î½üµÄWindowsÇå¾²¸üÐÂÓëɱ¶¾Èí¼þ³åÍ»£¬µ¼ÖÂϵͳ¿¨ËÀ
4ÔÂ9ÈÕ΢ÈíÐû²¼WindowsÇå¾²¸üкó£¬Windows 7¡¢Windows 8.1¡¢Windows 2008¡¢Windows 2008 R2¡¢Windows 2012ºÍWindows 2012 R2µÄÓû§¶¼±¨¸æÁËÐÔÄÜϽµºÍ¿¨ËÀÎÊÌ⡣ƾ֤McAfeeºÍAvastµÄͨ¸æ£¬¸ÃÎÊÌâÓëWindows¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ£¨CSRSS£©·þÎñµÄ¸ü¸ÄÓйء£ÆäËü±£´æ³åÍ»µÄɱ¶¾Èí¼þ»¹°üÀ¨Avira¡¢SophosµÈ¡£Î¢ÈíÉÐδ¾ÍÕâÒ»ÎÊÌâ¾ÙÐлØÓ¦¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/software/windows-security-update-caused-recent-antivirus-conflicts-and-freezes/


¾©¹«Íø°²±¸11010802024551ºÅ