¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180820

Ðû²¼Ê±¼ä 2018-08-20

¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯


Ç÷ÊÆ¿Æ¼¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£¡£¡£¡£ÔÚ×îа汾µÄWindowsÖУ¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript£¬£¬£¬£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÓïÒôÐÅÏäÐ®ÖÆPayPalºÍWhatsAppÕË»§


Çå¾²Ñо¿Ö°Ô±Martin Vigo³Æ¹¥»÷Õß¿ÉʹÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§£¬£¬£¬£¬£¬£¬£¬ÈçPayPalºÍWhatsAppµÈ¡£¡£¡£¡£´ó´ó¶¼ÔËÓªÉ̲»µ«Ö§³Öͨ¹ýÊÖʱ»ú¼ûÓïÒôÐÅÏ䣬£¬£¬£¬£¬£¬£¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃÍⲿµç»°ºÅÂë»á¼ûÓïÒôÐÅÏä¡£¡£¡£¡£Ðí¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂ룬£¬£¬£¬£¬£¬£¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈ¼òÆÓÃÜÂë¡£¡£¡£¡£Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃÓïÒôÐÅÏäÀ´ÖØÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬²¢×îÖÕÐ®ÖÆÓû§µÄPayPalºÍWhatsAppÕË»§¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora


SalesforceÑо¿Ö°Ô±Vishal Thakur·¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£¡£¡£¡£µ½2018Äê7ÔÂ⣬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÅÌËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬×î³õµÄѬȾǰÑÔÊÇÍøÂç´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬Æä°üÀ¨Á½¸öÓÐÓúÉÔØ£¬£¬£¬£¬£¬£¬£¬Ò»¸öÊÇÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤µÄľÂí£¬£¬£¬£¬£¬£¬£¬ÀýÈçÍâµØÕË»§ºÍä¯ÀÀÆ÷µÄƾ֤µÈ¡£¡£¡£¡£ÁíÒ»¸öÓÐÓúÉÔØÊÇÀÕË÷Èí¼þAurora£¬£¬£¬£¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA


Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£¡£¡£¡£ÏÖÔÚ»¹²»ÖªµÀMAFIAÔõÑù½øÈëÓû§µÄϵͳ£¬£¬£¬£¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹ÂڻʵÏÖÕâÒ»²½µÄ¡£¡£¡£¡£MAFIAʹÓÃOpenSSLÀ´¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©Õ¹Ãû¡£¡£¡£¡£ÓÉÓÚÆä¼ÓÃÜÀú³ÌºÜÂý£¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÖÕÖ¹ÆäÀú³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø±ÕÅÌËã»úÀ´×èÖ¹Ëü¡£¡£¡£¡£MAFIAʹÓÃTorÊðÀí¾ÙÐÐC2ͨѶ£¬£¬£¬£¬£¬£¬£¬Æäͨ¹ýHTTP GETÇëÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿»ú¹¹Ðû²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄÆÊÎö±¨¸æ


CyberbitÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²âÊÖÒÕ¡£¡£¡£¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬Æä°üÀ¨ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÅÌËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûƾ֤µÈÄ£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷TrickbotµÄбäÖÖ½ÓÄÉÀú³ÌÍڿյĴúÂë×¢ÈëÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬´ó´ó¶¼Çå¾²²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸öÇå¾²Îó²î


8ÔÂ19ÈÕProject InsecurityµÄÁ½ÃûÇå¾²Ñо¿Ö°Ô±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ±£´æÒ»¸öÍâµØÎļþй¶Îó²î¡£¡£¡£¡£TRSϵͳÊÇÖ¸µçÐÅÖмÌЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ×ÊÖú¶úÁû»òÓïÑÔÕϰ­µÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨Öú×°±¸²¦´òµç»°¡£¡£¡£¡£¼ÓÄôóµÄËùÓÐÖ÷ÒªISP¶¼ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬°üÀ¨Rogers¡¢TelusºÍBCEµÈ£¬£¬£¬£¬£¬£¬£¬ÕâЩISPµÄЧÀ͹¤¾ßº­¸ÇÁËÁè¼Ý3000Íò¼ÓÄÃÖÁ¹«Ãñ¡£¡£¡£¡£ËùÓеÄÖ÷Òª¼ÓÄôóISP¶¼ÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/