2019ÄêQ1ÍøÂç·¸·¨Õ½ÂÔºÍÊÖÒÕ±¨¸æ;Windows¸üÐÂÓëɱ¶¾³åÍ» £¬µ¼ÖÂϵͳ¿¨ËÀ£»GootkitºÍAzorult

Ðû²¼Ê±¼ä 2019-04-29
1.Malwarebytes LabsÐû²¼2019ÄêQ1ÍøÂç·¸·¨Õ½ÂÔºÍÊÖÒÕ±¨¸æ

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

Malwarebytes LabsÐû²¼2019ÄêµÚÒ»¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕ±¨¸æ £¬¸Ã±¨¸æÖ¸³öÆóÒµÔÚµÚÒ»¼¾¶ÈÔâÊܵÄÍþвÔöÌíÁË235% £¬ÓÈÆäÊÇEmotetµÈľÂíºÍÀÕË÷Èí¼þÍþв ¡£Õë¶ÔСÎÒ˽¼ÒÏûºÄÕߵĶñÒâÈí¼þÍþвϽµÁ˽ü40% ¡£Òƶ¯×°±¸ºÍMac×°±¸Ô½À´Ô½³ÉΪ¹ã¸æÈí¼þµÄÄ¿µÄ £¬Mac¶ñÒâÈí¼þ´Ó2018ÄêQ4µ½2019ÄêQ1ÔöÌíÁË60% £¬¹ã¸æÈí¼þÔòÔöÌíÁË200% ¡£ÔÚÈ«ÇòÍþв¼ì²âÂÊÖÐÃÀ¹ú×î¸ß £¬Îª47£¥ £¬Ó¡¶ÈÄáÎ÷ÑÇΪ9£¥ £¬°ÍÎ÷Ϊ8£¥ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/cybercrime/2019/04/labs-cybercrime-tactics-and-techniques-report-finds-businesses-hit-with-235-percent-more-threats-in-q1/

2.¹¥»÷ÕßʹÓÃJasperLoader·Ö·¢ÒøÐÐľÂíGootkit £¬Ö÷ÒªÕë¶ÔÖÐÅ·

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

ÔÚÒÑÍù¼¸¸öÔÂÄÚ˼¿ÆTalosÊӲ쵽JasperLoaderµÄ¶ñÒâ¹¥»÷»î¶¯µÄÔöÌí £¬¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÖÐÅ·¹ú¼Ò £¬ÓÈÆäÊǵ¹úºÍÒâ´óÀû ¡£JasperLoader½ÓÄɶà½×¶ÎѬȾÀú³Ì £¬²¢°üÀ¨¶àÖÖ»ìÏýÊÖÒÕ £¬×îÖÕ·Ö·¢ÒøÐÐľÂíGootKit ¡£JasperLoaderͨ¹ýÀ¬»øÓʼþ¾ÙÐÐÈö²¥ £¬ÕâЩÀ¬»øÓʼþʹÓÃÁËÓÐÓÃÖ¤ÊéµÄÊðÃûÒÔÌá¸ß¿ÉÐÅ¶È ¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÁгöÁ˹¥»÷»î¶¯µÄÏêϸIoC ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2019/04/jasperloader-targets-italy.html

3.AzorultľÂíαװ³ÉÐéαWindowsÇå½à¹¤¾ßG-Cleaner¾ÙÐÐÈö²¥

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

Ñо¿Ö°Ô±Benkow·¢Ã÷AZORultľÂíαװ³ÉÒ»¸öWindowsÇå½à¹¤¾ß¾ÙÐÐÈö²¥ £¬¸Ã¹¤Ç©×ÖΪG-Cleaner»òGarbage Cleaner £¬¹¥»÷ÕßÉõÖÁ½¨ÉèÁËÒ»¸öÍøÕ¾gcleaner[.]infoÀ´·Ö·¢¸ÃľÂí ¡£¸ÃÍøÕ¾ÖÆ×÷ÓÅÒì £¬¿´ÆðÀ´ÀàËÆÓÚÕýµ±µÄÈí¼þ¹ÙÍø £¬²¢ÇÒÈÔÔÚÕý³£ÔËÐÐ ¡£Ò»µ©Óû§×°ÖøöñÒâÈí¼þ £¬Ä¾Âí¾Í»áÇÔȡϵͳÉϵÄÃÜÂë¡¢Êý¾Ý¼°¼ÓÃÜÇ®±ÒÇ®°üµÈÐÅÏ¢ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-windows-pc-cleaner-drops-azorult-info-stealing-trojan/

4.Ñо¿Ö°Ô±Ðû²¼ÐÂÀÕË÷Èí¼þRobbinHoodµÄÑùÌìÖ°Îö

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

MalwareHunterTeamÐû²¼ÀÕË÷Èí¼þRobbinHoodµÄÑùÌìÖ°Îö ¡£RobbinHoodÊÇÀÕË÷Èí¼þÁìÓòµÄ×îгÉÔ± £¬ÆäÄ¿µÄÊÇÆóÒµºÍÍøÂçÉϵÄÅÌËã»ú £¬¸ÃÀÕË÷Èí¼þÖ÷Ҫͨ¹ýRDP·þÎñ»òľÂí¾ÙÐзַ¢ ¡£¸ÃÑù±¾ÔÚÔËÐÐʱ½«É±ËÀ181¸öÓëɱ¶¾Èí¼þ¡¢Êý¾Ý¿â¡¢Óʼþ·þÎñµÈÓйصÄWindowsÀú³Ì £¬²¢¶Ï¿ªÍøÂç¹²ÏíÅþÁ¬ ¡£¸ÃÑù±¾ÔÚ¼ÓÃÜÎļþʱ £¬»áΪÿһ¸öÎļþ½¨Éè²î±ðµÄAESÃÜÔ¿ £¬È»ºóÓÃRSA¹«Ô¿¼ÓÃÜAESÃÜÔ¿ºÍԭʼÎļþÃû ¡£¼ÓÃܺóµÄÎļþ±»ÖØÃüÃûΪEncrypted_[randomstring].enc_robbinhoodµÄÃûÌà ¡£ÏÖÔÚÉÐûÓиÃÀÕË÷Èí¼þµÄ½âÃÜÆ÷ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/a-closer-look-at-the-robbinhood-ransomware/

5.LAZARUS APTй¥»÷»î¶¯ £¬Ê¹ÓöñÒâWORDÎļþÃé×¼MACÓû§

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

SentinelOneÐû²¼¹ØÓÚLazarus APTй¥»÷»î¶¯µÄÆÊÎö±¨¸æ ¡£¹¥»÷ÕßʹÓöñÒâWordÎĵµÕë¶ÔMACÓû§ £¬¸ÃÎĵµµÄVBA¾ç±¾Ê×Ïȼì²âÊÇ·ñÔÚMacÉÏÔËÐÐ £¬ÈôÊÇÊÇ £¬ÔòcurlÎļþhttps//nzssdm.com/assets/mt.datµ½ÍâµØ ¡£mt.datµÄpayloadÊÇÒ»¸öMach-OµÄ64λ¿ÉÖ´ÐÐÎļþ £¬¸ÃÎļþÊÇÒ»¸ö¶¨ÖƵĺóÃÅ £¬µ«¹¦Ð§Éв»Ã÷È· £¬ÆäC2·þÎñÆ÷µÄIPµØÖ·ÈÔÈ»¿ÉÓà ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.sentinelone.com/blog/lazarus-apt-targets-mac-users-poisoned-word-document/

6.×î½üµÄWindowsÇå¾²¸üÐÂÓëɱ¶¾Èí¼þ³åÍ» £¬µ¼ÖÂϵͳ¿¨ËÀ

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

4ÔÂ9ÈÕ΢ÈíÐû²¼WindowsÇå¾²¸üкó £¬Windows 7¡¢Windows 8.1¡¢Windows 2008¡¢Windows 2008 R2¡¢Windows 2012ºÍWindows 2012 R2µÄÓû§¶¼±¨¸æÁËÐÔÄÜϽµºÍ¿¨ËÀÎÊÌâ ¡£Æ¾Ö¤McAfeeºÍAvastµÄͨ¸æ £¬¸ÃÎÊÌâÓëWindows¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ£¨CSRSS£©·þÎñµÄ¸ü¸ÄÓÐ¹Ø ¡£ÆäËü±£´æ³åÍ»µÄɱ¶¾Èí¼þ»¹°üÀ¨Avira¡¢SophosµÈ ¡£Î¢ÈíÉÐδ¾ÍÕâÒ»ÎÊÌâ¾ÙÐлØÓ¦ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/windows-security-update-caused-recent-antivirus-conflicts-and-freezes/