еÄRiseProͨ¹ýPrivateLoader PPI·þÎñ½øÐзַ¢
°ä²¼¹¦·ò 2022-12-28
¾Ý12ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»ÖÖÐÂÐÍÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þRisePro¡£¡£¡£¡£¡£¡£¡£¡£ËüÓÚ2022Äê12ÔÂ13ÈÕ³õ´Î±»¼ì²âµ½£¬£¬£¬£¬£¬£¬ÔÚͨ¹ýPrivateLoader°´×°Öø¶·Ñ(PPI)¶ñÒâÈí¼þÏÂÔØ·þÎñ½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£RiseProÓÉC++¿ª·¢£¬£¬£¬£¬£¬£¬ËƺõÓµÓÐÓëVidarÀàËÆµÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔ®ÊÖ¹¥»÷Õß´Ó±»Ï°È¾µÄÉ豸ÖÐÇÔȡָ±êµÄÐÅÓþ¿¨¡¢ÃÜÂëºÍ¼ÓÃÜÇ®°ü¡£¡£¡£¡£¡£¡£¡£¡£Flashpoint»ã±¨³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒѾÔÚ¶íÂÞ˹°µÍøÊг¡ÉÏÏúÊÛÊýÒÔǧ¼ÆµÄRiseProÈÕÖ¾£¨´Ó±»Ï°È¾É豸ÖÐÇÔÈ¡µÄÊý¾Ý°ü£©¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-info-stealer-malware-infects-software-pirates-via-fake-cracks-sites/
2¡¢RansomHouseÐû³Æ¶ÔÍßŬ°¢Í¼µ±¾ÖÔâµ½µÄÀÕË÷¹¥»÷ÕÆ¹Ü
¾ÝýÌå12ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬RansomHouseÐû³Æ¶ÔÍßŬ°¢Í¼µ±¾ÖÔâµ½µÄÀÕË÷¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£¡£¡£ÍßŬ°¢Í¼ÔøÔÚ11Ô³õ°ä·¢ËûÃÇÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬ÔÚ½«½üÒ»¸öÔºóÈÔδÆëÈ«¸´Ô¡£¡£¡£¡£¡£¡£¡£¡£12ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬RansomHouseÍŻォÍßŬ°¢Í¼µ±¾ÖÁÐÈëÁËËûÃǵÄÍøÕ¾£¬£¬£¬£¬£¬£¬³ÆÒÑÓÚ10ÔÂ6ÈÕ¼ÓÃÜËûÃǵÄϵͳ£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË3.2 TBµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£°ä²¼µÄÑù±¾ÖÐÎļþ¿´ÆðÀ´µÄÈ·Óëµ±¾ÖµÄÎļþÒ»Ö£¬£¬£¬£¬£¬£¬ÆäÖв»Ô̺¬Ó×ÎÒ»òÃô¸ÐµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÊê½ð½ð¶îÊǼ¸¶à£¬£¬£¬£¬£¬£¬»òÊÇ·ñ½øÐйý½»Éæ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/vanuatu-ransomware-attack-claimed-by-ransomhouse/
3¡¢CrowdStrikeÅû¶GuLoaderÈÆ¹ý°²È«¼ì²âµÄ¶à¸ö²½Öè
CrowdStrikeÔÚ12ÔÂ19ÈÕÅû¶ÁËGuLoaderÈÆ¹ý°²È«¼ì²âµÄ¶à¸ö²½Öè¡£¡£¡£¡£¡£¡£¡£¡£GuLoader£¨±ðÃûCloudEyE£©£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖVisual Basic Script(VBS)ÏÂÔØ·¨Ê½£¬£¬£¬£¬£¬£¬ÓÚ2019Äê³õ´ÎÔÚÒ°±í±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£ËüʹÓöà̬shellcode¼ÓÔØ·¨Ê½À´Èƹý´«Í³°²È«½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬×êÑÐÈËԱΪ¶ñÒâÈí¼þʹÓõÄÿ¸öAPIÓ³ÉäËùÓÐǶÈëʽDJB2¹þÏ£Ö·´·ÖÎöÆä»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ÐµÄshellcode·´·ÖÎö¼¼Êõͨ¹ýɨÃèÕû¸ö¹ý³ÌÄÚ´æÀ´²éÕÒÓëÐé¹¹»ú(VM)ÓйصÄ×Ö·û´®£¬£¬£¬£¬£¬£¬ÐµÄÈßÓà´úÂë×¢Èë»úÔìÒâζ×Åͨ¹ýʹÓÃÄÚÁª»ã±àÈÆ¹ý°²È«½â¾ö¹æ»®µÄÓû§Ä£Ê½hookÀ´È·±£´úÂëµÄÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£
https://www.crowdstrike.com/blog/guloader-dissection-reveals-new-anti-analysis-techniques-and-code-injection-redundancy/
4¡¢TrendMicro·¢ÏÖÀûÓùȸèPPC¸æ°×·Ö·¢IcedIDµÄ»î¶¯
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬Trend Microй©Æä·¢ÏÖ½©Ê¬ÍøÂçIcedIDµÄ·Ö·¢·½Ê½²úÉúÁ˳Á´ó±ä¶¯¡£¡£¡£¡£¡£¡£¡£¡£×Ô2022Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±¹Û²ìµ½ÀûÓùȸèÿ´Îµã»÷¸¶·Ñ(PPC)¸æ°×·Ö·¢IcedIDµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£IcedIDÔËÓªÍÅ»ï½Ù³ÖÁËAdobe¡¢FortinetºÍDiscordµÈÆ·ÅÆºÍÀûÓÃËùʹÓõĹؼü´ÊÀ´ÏÔʾ¶ñÒâ¸æ°×¡£¡£¡£¡£¡£¡£¡£¡£µ±Óû§ËÑË÷¹Ø¼ü×Öʱ£¬£¬£¬£¬£¬£¬Ö¸Ïò¶ñÒâÍøÕ¾µÄ¸æ°×ÏÔʾÔÚÌìÈ»ËÑË÷Á˾ÖÉÏ·½¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬£¬£¬¼ÓÔØ·¨Ê½ÊÇͨ¹ýMSIÎļþ·Ö·¢µÄ£¬£¬£¬£¬£¬£¬Õâ¶ÔÓÚIcedIDÀ´ËµÊDz»³£¼ûµÄ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁ˺Ϸ¨µÄKeitaroÁ÷Á¿µ¼Ïòϵͳ(TDS)À´¹ýÂËÀ´×Ô×êÑÐÈËÔ±ºÍɳºÐµÄÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£¡£
https://www.trendmicro.com/en_us/research/22/l/icedid-botnet-distributors-abuse-google-ppc-to-distribute-malware.html
5¡¢Ö¥¼Ó¸çµÄÄÜÔ´¹«Ë¾Sargent & LundyÔâµ½ÀÕË÷¹¥»÷
ýÌå12ÔÂ27Èճƣ¬£¬£¬£¬£¬£¬ÃÀ¹úCNNй©ºÚ¿ÍÔÚ½üÆÚµÄÀÕË÷¹¥»÷ÖÐÇÔÈ¡Á˶à¼ÒµçÁ¦¹«Ë¾µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÀÕË÷¹¥»÷Õë¶ÔµÄÊÇ×ܲ¿Î»ÓÚÖ¥¼Ó¸çµÄSargent & Lundy¹¤³Ì¹«Ë¾£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Éè¼ÆÁË900¶à¸ö·¢µçÕ¾ºÍÊýǧӢÀïµÄµçÁ¦ÏµÍ³£¬£¬£¬£¬£¬£¬²¢³ÖÓÐÕâЩÏîÖ÷ÕÅÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¾ÝÆäÍøÕ¾³Æ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹´¦Öú˰²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÒѵõ½½ÚÔìºÍ²¹¾È£¬£¬£¬£¬£¬£¬Ëƺõ²¢Î´¶ÔÆäËüµçÁ¦ÐÐÒµµÄ¹«Ë¾Ôì³ÉÓ°Ï죬£¬£¬£¬£¬£¬Ò²Ã»º±¼û¾Ý±»°ä²¼µ½°µÍøÉÏ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/hackers-stole-data-from-multiple-electric-utilities-in-recent-ransomware-attack/
6¡¢Kaspersky°ä²¼Õë¶Ô°¢¶û°ÍÄáÑǵÄÁ½ÂÖ¹¥»÷µÄ·ÖÎö»ã±¨
KasperskyÔÚ12ÔÂ22ÈÕ°ä²¼ÁËÕë¶Ô°¢¶û°ÍÄáÑÇ×éÖ¯µÄÁ½ÂÖ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨ÖØÒª±ÈÁ¦ÁËÕâÁ½ÂÖ¹¥»÷»î¶¯ËùʹÓõÄÀÕË÷Èí¼þºÍ²Á³ý¶ñÒâÈí¼þÖ®¼äµÄÇø±ð¡£¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬Á½ÂÖ¹¥»÷»î¶¯µÄÑù±¾ÓµÓÐÒ»ÑùµÄÊðÃûÖ¤Êé²ÎÊý£¬£¬£¬£¬£¬£¬Óë¿ÆÍþÌØµçÐŹ«Ë¾Óйء£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¶ÔµÚ¶þÂÖʹÓõIJÁ³ý¶ñÒâÈí¼þ½øÐÐÁËÂÅ´ÎÅú¸Ä£¬£¬£¬£¬£¬£¬¿ÉÄÜÊÇΪÁËÈÆ¹ý¼ì²â£¬£¬£¬£¬£¬£¬ÖØÒª±ä¶¯ÊÇʹÓÃNvidiaÖ¤Êé¶Ô¶ñÒâÈí¼þÊðÃû¡¢ÔÚ¶ñÒâÈí¼þÖÐǶÈëEldoS RawDiskÇý¶¯·¨Ê½£¬£¬£¬£¬£¬£¬ÒÔ¼°ÔÚÇý¶¯·¨Ê½×°ÖúóÁ¢¼´Æô¶¯É¾³ýÀý³Ì¡£¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/ransomware-and-wiper-signed-with-stolen-certificates/108350/


¾©¹«Íø°²±¸11010802024551ºÅ