Heritage¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷ÁÙʱÖÕ³¡ÔËÓª£»£»£»£»£»FBI°ä²¼ÀÕË÷Èí¼þLockerGogaºÍMegaCortexµÄ¹«¸æ
°ä²¼¹¦·ò 2019-12-26
1.¹ã²¥¹«Ë¾Entercom½ñÄêµÚ¶þ´ÎÔâµ½ÍøÂç¹¥»÷
¾Ý±íý±¨Â·£¬£¬£¬£¬£¬£¬£¬¹ã²¥¹«Ë¾EntercomÔÚÖÜÈÕÔâµ½Ò»´ÎеÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¸Ã¹«Ë¾µÄµç×ÓÓʼþͨѶ¡¢Êý×Ôì½Ì¨µÄÎļþºÍÄÚÈݾùÎÞ·¨½Ó¼û£¬£¬£¬£¬£¬£¬£¬Ä³Ð©µç̨±»ÆÈ²¥·Å¼ÔìµÄ½ÚÄ¿¡£¡£¡£¡£¡£¡£ÕâÊÇEntercomÔÚ½ñÄêÔâµ½µÄµÚ¶þ´ÎÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÉÏÒ»´Î¹¥»÷²úÉúÔÚ9Ô·ݣ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÀàÐÍΪÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Æäʱ¹¥»÷ÕßÏòEntercomÀÕË÷50ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔEntercomÊÇ·ñÖ§¸¶Á˸ñÊÊê½ð¡£¡£¡£¡£¡£¡£ÖÜÒ»Entercom°µÊ¾ÒÑ´Ó×îÐµĹ¥»÷Öи´Ô£¬£¬£¬£¬£¬£¬£¬µ«Î´Åû¶Õâ´Î¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/entercom-radio-network-hit-by-second-cyber-attack-this-year/
2.ÓªÏú¹«Ë¾HeritageÔâÀÕË÷Èí¼þ¹¥»÷ÁÙʱÖÕ³¡ÔËÓª
HeritageÊ×ϯִÐйÙSandra FraneckeÏòÔ±¹¤·¢ËÍÓʼþ³Æ£¬£¬£¬£¬£¬£¬£¬Ô¼Á½¸öÔÂǰHeritage·þÎñÆ÷Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸ø¹«Ë¾Ôì³ÉÁËÊýÊ®ÍòÃÀÔªµÄËðʧ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½«ÁÙʱÖÕ³¡ÔËÓª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ïò¹¥»÷ÕßÖ§¸¶ÁËÊê½ð£¬£¬£¬£¬£¬£¬£¬µ«ITÍŶÓÈÔÔÚ¸´Ôϵͳ¹ý³ÌÖÐÓöµ½ÄÑÌ⣬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄ300¶àÃûÔ±¹¤¿ÉÄÜÒò¶øÊ§Òµ¡£¡£¡£¡£¡£¡£Õâ²»ÊǵÚÒ»¼ÒÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö¹ØÃŵįóÒµ£¬£¬£¬£¬£¬£¬£¬ÔçÔÚ2019Äê4Ô·ÝBrookside¶ú±ÇºíºÍÌýÁ¦ÖоÍÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö»¼Õ߼ͼ¡¢Ô¤Ô¼¹¦·ò±íºÍÖ§¸¶ÐÅÏ¢¾ùÎÞ·¨½Ó¼û£¬£¬£¬£¬£¬£¬£¬×îÖÕÓÀÔ¶¹Ø¹Ø¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/marketing-agency-temporarily-halts-operations-after-ransomware-attack/
3.FBI°ä²¼ÀÕË÷Èí¼þLockerGogaºÍMegaCortexµÄ¹«¸æ
FBIÕë¶ÔÀÕË÷Èí¼þLockerGogaºÍMegaCortexÏò˽Ӫ²¿ÃŰ䲼ÖҸ棬£¬£¬£¬£¬£¬£¬²¢ÌṩÁËÁìµ¼»ººÍ½â½¨Òé´ëÊ©¡£¡£¡£¡£¡£¡£×Ô2019Äê1ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬LockerGogaÒÑÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Å²ÍþºÍºÉÀ¼µÄ´óÐ͹«Ë¾ºÍ×éÖ¯ÌáÒé¶à¸ö¹¥»÷£¬£¬£¬£¬£¬£¬£¬¶øMegaCortexÓÚ2019Äê5Ô³õ´Î³öÏÖ£¬£¬£¬£¬£¬£¬£¬ËüÔÚIOC¡¢C2»ù´¡¼Ü¹¹ºÍÖ¸±êÑ¡Ôñ·½Ãæ¾ùÀàËÆÓÚLockerGoga¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã¾¯±¨£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖØÒªÀûÓ÷ì϶¡¢ÍøÂç´¹µö¹¥»÷¡¢SQL×¢ÈëºÍ±»µÁµÄµÇ¼ʹ´¦ÈëÇÔìóÒµÍøÂ磬£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜÂñ·üÊýԵŦ·ò¡£¡£¡£¡£¡£¡£FBI½¨ÒéÆóҵȷ˷ÖÝÆÚ±¸·ÝÊý¾Ý£¬£¬£¬£¬£¬£¬£¬±£ÁôÍÑ»ú±¸·Ý²¢ÑéÖ¤±¸·Ý¹ý³ÌµÄÆëÈ«ÐÔ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fbi-issues-alert-for-lockergoga-and-megacortex-ransomware/
4.EmotetÔÚ2019ÄêTop¶ñÒâÈí¼þÍþвÖÐÕ¼¾ÝÖ÷µ¼Ö°Î»
½»»¥Ê½¶ñÒâÈí¼þ·ÖÎöɳºÐ·þÎñAny.Run¼ÙÔìÁË2019Äê¶¥¼¶¶ñÒâÈí¼þÍþвÁÐ±í£¬£¬£¬£¬£¬£¬£¬ÆäÖÐEmotetÕ¼¾ÝÖ÷µ¼Ö°Î»¡£¡£¡£¡£¡£¡£ÅÅÔÚǰÁеÄÍþв»¹Ô̺¬ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢£¨Ô̺¬ÒøÐÐÕË»§ÐÅÏ¢£©µÄ¶ñÒâÈí¼þ¡¢RATµÈ¡£¡£¡£¡£¡£¡£¾ßÌåÁбíΪ£ºEmotet-36026¸öÑù±¾¡¢Agent Tesla-10324¸öÑù±¾¡¢NanoCore-6527¸öÑù±¾¡¢LokiBot-5693¸öÑù±¾¡¢Ursnif-4185¸öÑù±¾¡¢FormBook-3548¸öÑù±¾¡¢HawkEye-3388¸öÑù±¾¡¢AZORult-2898¸öÑù±¾¡¢rickBot-2510¸öÑù±¾ÒÔ¼°njRAT-2355¸öÑù±¾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/emotet-reigns-in-sandboxs-top-malware-threats-of-2019/
5.Gartnerµ÷²é·¢ÏÖÖ»ÓÐ65£¥µÄÆóÒµÕ¼ÓÐÍøÂ簲ȫר¼Ò
ƾ¾ÝGartnerµÄµ÷²é»ã±¨£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü95£¥µÄCIOÔ¤¼Æ½«À´ÈýÄêÄÚÍøÂçÍþв»á³ÖÐøÔö³¤£¬£¬£¬£¬£¬£¬£¬µ«Ä¿Ç°Ö»ÓÐ65£¥µÄÆóÒµÕ¼ÓÐÍøÂ簲ȫר¼Ò¡£¡£¡£¡£¡£¡£¸Ãµ÷²é»¹Åú×¢£¬£¬£¬£¬£¬£¬£¬¼¼Êõ·½ÃæµÄÌôÕ½ÒÀÈ»À§ÈÅמÀúÊý×Ö»¯¹ý³ÌµÄÆóÒµ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÊý×Ö°²È«ÈËԱǷȱ±»ÒÔΪÊÇ´´ÐµÄÖØÒª×è°¡£¡£¡£¡£¡£¡£35£¥µÄµ÷²éÊÜ·ÃÕß°µÊ¾ËûÃÇµÄÆóÒµÒѾͶ×ʲ¢²¿ÊðÁËijЩ·½ÃæµÄÊý×Ö°²È«ÐÔ£¬£¬£¬£¬£¬£¬£¬»¹ÓÐ36£¥µÄÊÜ·ÃÕßÔÚ»ý¼«³¢ÊÔ»ò´òËãÔÚ¶ÌÆÚÄÚÖ´ÐÐÊý×Ö°²È«ÐÔ¡£¡£¡£¡£¡£¡£GartnerÔ¤²âµ½2020Ä갲ȫԤËãÖеÄ60£¥½«ÓÃÓÚÖ§³Ö¼ì²âºÍÏìÓ¦Ö°ÄÜ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.gartner.com/en/newsroom/press-releases/2018-07-17-gartner-survey-finds-only-65-percent-of-organizations-have-a-cybersecurity-expert
6.Ç÷Ïò¿Æ¼¼°ä²¼Õë¶ÔWordPressÍøÕ¾¹¥»÷¼¼ÊõµÄ·ÖÎö»ã±¨
Ç÷Ïò¿Æ¼¼×êÑÐÍŶӰ䲼¹ØÓÚÕë¶ÔWordPressÍøÕ¾¹¥»÷¼¼ÊõµÄµ÷²é»ã±¨£¬£¬£¬£¬£¬£¬£¬ ¸Ã»ã±¨Ö¸³öÓÉÓÚWordPressÒѱ»µ±½ñËùÓÐÍøÕ¾µÄÔ¼35£¥Ê¹Ó㬣¬£¬£¬£¬£¬£¬Ê¹Æä³ÉΪ¹¥»÷ÕßµÄÃÎÏëÖ¸±ê¡£¡£¡£¡£¡£¡£»£»£»£»£»ùÓÚÇ÷Ïò¿Æ¼¼ÔÚÒ°±í¹Û²ìµ½µÄpayloadÑù±¾£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷÖÎöÁËÕë¶ÔWordPressµÄ·ÖÆçÀàÐ͵Ĺ¥»÷£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÀûÓ÷ì϶»òͨ¹ýй¶µÄ»òÈõÖÎÀíԱʹ´¦¹¥»÷WordPressÍøÕ¾¡¢ÔÚÊÜϰȾµÄWordPressÍøÕ¾Öв¿ÊðAlfa-Shell¡¢ÀûÓÃÊÜϰȾµÄÍøÕ¾´«È¾ËÑË÷ÒýÇæµÄËÑË÷Á˾ÖÒÔ¼°É¢²¼Ðéα»òÎóµ¼ÐÔÎÄÕµȡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/looking-into-attacks-and-techniques-used-against-wordpress-sites/


¾©¹«Íø°²±¸11010802024551ºÅ