µÂ¹úÁª°î¾¯²ì¾ÖÖØÖÃEmotet£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ£»»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷£¬250GBδ¼ÓÃܵÄÎļþй¶

Ðû²¼Ê±¼ä 2021-04-27

1.µÂ¹úÁª°î¾¯²ì¾ÖÖØÖÃEmotet£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ


1.jpg


µÂ¹úÁª°î¾¯²ì¾ÖBundeskriminalamtÖØÖÃÁËEmotet£¬¸Ã¶ñÒâÈí¼þ½«ÔÚËùÓÐÊÜѬȾµÄϵͳÖÐ×Ô¶¯Ð¶ÔØ¡£EmotetÊǽüÆÚ×îΣÏÕµÄÀ¬»øÓʼþ½©Ê¬ÍøÂçÖ®Ò»£¬Æä»ù´¡ÉèÊ©ÓÚ½ñÄê1Ô·ÝÓɶà¹úÖ´·¨²¿ÃÅÁªºÏµ·»Ù¡£ÔÚ´Ë´ÎÐж¯ÖУ¬µÂ¹ú¾¯·½ÂôÁ¦¿ª·¢ºÍÍÆËÍÐ¶ÔØÄ £¿é£¬ÆäΪÁËÊÕ¼¯Ö¤¾ÝºÍÐÅÏ¢¶øÍƳÙÁ˸ÃÐ¶ÔØÄ £¿éµÄÐû²¼¡£¸Ã»ú¹¹Í¨¹ýÆä¿ØÖƵÄC2·þÎñÆ÷£¬½«32λEmotetLoader.dllÐÎʽµÄÐÂEmotetÄ £¿é·Ö·¢¸øËùÓÐÊÜѬȾµÄϵͳ£¬Ê¹ÕâЩϵͳÔÚ2021Äê4ÔÂ25ÈÕ×Ô¶¯Ð¶ÔظöñÒâÈí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/


2.»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷£¬250GBδ¼ÓÃܵÄÎļþй¶


2.jpg


»ªÊ¢¶ÙÌØÇø¾¯²ì¾ÖMPDÈ·ÈÏÆäÔâµ½ÀÕË÷ÍÅ»ïBabukµÄ¹¥»÷£¬250 GBδ¼ÓÃܵÄÎļþй¶¡£ÀÕË÷ÍÅ»ï¹ûÈ»µÄ±»µÁÎļþ¼ÐµÄ½ØÍ¼ÖеÄʱ¼ä´Á¾ùΪ2021.4.19£¬Õâ¿ÉÄÜÏÔʾÁ˹¥»÷ÕßÇÔÈ¡Êý¾ÝµÄʱ¼ä¡£´ËÍ⣬BabukÍÅ»ïÌØ±ðÖ¸³öÁËÒ»·ÝÎļþ£¬ÆäËÆºõÓë1ÔÂ6ÈÕÏ®»÷¹ú»á´óÏõĿ¹Òé»î¶¯Óйء£MPD³ÆÆäÒѾ­ÓëFBIÁªºÏÕ¹¿ªÁËÈ«ÃæµÄÊӲ죬µ«ÊÇĿǰÉÐδ¹ûÈ»Óйش˴ÎʼþµÄÏêϸÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dc-police-confirms-cyberattack-after-ransomware-gang-leaks-data/


3.Ñо¿ÍŶӷ¢ÏÖÀûÓÃFileZenÖеÄ2¸ö©¶´µÄ¹¥»÷»î¶¯


3.jpg


Ñо¿ÍŶӷ¢ÏÖÀûÓÃÎļþ¹²Ïí·þÎñÆ÷Soliton FileZenÖеÄ2¸ö©¶´ÇÔÈ¡Êý¾ÝµÄ´ó¹æÄ£¹¥»÷»î¶¯¡£´Ë´Î»î¶¯ÖÐÀûÓõÄ©¶´·Ö±ðΪĿ¼±éÀú©¶´£¨CVE-2020-5639£©£¬¿É½«Ìض¨ÎļþÉÏÔØµ½Ìض¨Ä¿Â¼Öжøµ¼ÖÂÖ´ÐÐÈÎÒâOSÃüÁÒÔ¼°Ò»¸öÈÎÒâOSÃüÁîÖ´ÐЩ¶´£¨CVE-2021-20655£©¡£ÔÚÆäÖеÄÒ»´Î¹¥»÷ÖУ¬ÈÕ±¾Ê×ÏàÄÚ¸ó°ì¹«ÊÒ(Cabinet Office)ÊÂÇéÈËԱʹÓõÄSolitonÎļþ¹²Ïí´æ´¢Ôâµ½ÁËδ¾­ÊÚȨµÄ·ÃÎÊ¡£SolitonÒѾ­¿¯Ðй̼þ°æ±¾V4.2.8ºÍV5.0.3ÐÞ¸´ÁËFileZenÖеÄÁ½¸ö©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117208/hacking/soliton-filezen-file-sharing-servers.html


4.Sophos³ÆÏÖÔÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´Òþ²ØÍ¨ÐÅ


4.jpg


Sophosͨ¹ý·ÖÎö·¢ÏÖ£¬½üÆÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´Òþ²ØÍ¨ÐÅ¡£ÔÚ¹ýÈ¥µÄÊ®ÄêÖУ¬HTTPSµÄʹÓÃÂÊ´Ó2014ÄêÕ¼ËùÓÐÍøÒ³·ÃÎÊÁ¿µÄ40£¥ÒÔÉÏÔö³¤µ½2021Äê3ÔµÄ98£¥¡£¶ø¶ñÒâÈí¼þÒ²³öÓÚÏàͬµÄÔ­Òò½ÓÄÉTLS£¬2020Äê¼ì²âµ½23£¥µÄ¶ñÒâÈí¼þʹÓÃTLSÓëÔ¶³Ìϵͳ½øÐÐͨÐÅ£¬µ½ÏÖÔÚÕâÒ»±ÈÀýÒѽӽü46£¥¡£GoogleÔÆ·þÎñÊÇ9£¥µÄ¶ñÒâTLSÇëÇóµÄÄ¿±ê£¬Æä´ÎÊÇÓ¡¶ÈµÄBSNL£¬ËùÓеĶñÒâTLSͨÐÅÖм¸ºõÓÐÒ»°ëÁ÷ÏòÁËÃÀ¹úºÍÓ¡¶ÈµÄ·þÎñÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://news.sophos.com/en-us/2021/04/21/nearly-half-of-malware-now-use-tls-to-conceal-communications/


5.MimecastÐû²¼Óйصç×ÓÓʼþÄþ¾²Ì¬ÊƵķÖÎö³ÂËß


5.jpg


MimecastÐû²¼ÁËÓйصç×ÓÓʼþÄþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£¸Ã³ÂËß»ùÓÚ¶ÔÈ«Çò1225λ¾ö²ßÕßµÄÊӲ죬ÆäÖÐ79£¥µÄÊÜ·ÃÕßÌåÏÖÓÉÓÚȱ·¦Äþ¾²·½ÃæµÄ×¼±¸£¬ËûÃǵĹ«Ë¾ÔÚ2020Äê¾­ÀúÁËÒµÎñÖжϡ¢²ÆÕþËðʧ»òÆäËûÎÊÌ⣻61£¥µÄ¹«Ë¾ÔÚ2020ÄêÊܵ½ÀÕË÷Èí¼þµÄÓ°Ï죬±ÈÈ¥ÄêÔö¼ÓÁË20£¥£»52£¥µÄÀÕË÷Èí¼þÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬µ«ÊÇËûÃÇÖÐÖ»ÓÐ66£¥µÄÈ˻ָ´ÁËÊý¾Ý£¬ÁíÍâ34£¥µÄ¹«Ë¾Ö§¸¶ÁËÊê½ðÈ´ÒÀȻûÓеõ½ËûÃǵÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.mimecast.com/state-of-email-security/


6.OpenTextÐû²¼2020ÄêµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


6.jpg


OpenTextÐû²¼ÁË2020ÄêµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬½ö´Ó2020Äê1Ôµ½2Ô£¬ÍøÂçµöÓãµÄ¹¥»÷´ÎÊý¾ÍÔö¼ÓÁË510£¥£¬¹¥»÷Ä¿±êÖ÷ÒªÊÇÄ¿±êÊÇeBay¡¢Apple¡¢Microsoft¡¢FacebookºÍGoogle¡£ÈÕ±¾µÄPCѬȾÂÊ×îµÍ£¬Îª2.3%£¬Æä´ÎÊÇÓ¢¹ú(2.7%)¡¢´óÑóÖÞ(3.2%)ºÍ±±ÃÀ(3.7%)¡£ÔÚÅ·ÖÞ£¬¼ÒÓÃÉ豸±»Ñ¬È¾µÄ¿ÉÄÜÐÔ£¨17.4%£©ÊÇÉÌÓÃÉ豸µÄÈý±¶¶à(5.3%)¡£2020ÄêÔÚAndroid?É豸Éϼì²âµ½µÄÌØÂåÒÁľÂíºÍ¶ñÒâÈí¼þÕ¼Íþв×ÜÊýµÄ95.9£¥£¬¸ßÓÚ2019ÄêµÄ92.2£¥¡£


Ô­ÎÄÁ´½Ó£º

https://mypage.webroot.com/2021-threat-report.html