¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181016

Ðû²¼Ê±¼ä 2018-10-16
1¡¢Malwarebytes LabsÐû²¼2018 Q3ÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Malwarebytes LabsÐû²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ£¬£¬£¬£¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμÓËÙÁËËûÃǵĶñÒâ»î¶¯¡£¡£¡£¡£±¾¼¾¶ÈµÄÍþвÇ÷ÊÆ°üÀ¨¶ñÒâÍÚ¿óÈí¼þºÍÎó²îʹÓù¤¾ß°ü±äµÃ³ÉÊ죬£¬£¬£¬ÀÕË÷Èí¼þÎȲ½ÔöÌí£¬£¬£¬£¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯×îÏÈËÕÐѵȡ£¡£¡£¡£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔöÌíÁË55%£¬£¬£¬£¬Ïà±ÈÖ®ÏÂÕë¶ÔÏûºÄÕßµÄÍþв½öÔöÌí4%£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÕýÔÚ×·Çó¸ü´óµÄÀûÒæ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/


2¡¢Branch.ioЧÀͱ»ÆØ±£´æXSSÎó²î£¬£¬£¬£¬6.85ÒÚÓû§ÒÉÃæÁÙΣº¦

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

vpnMentorµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Branch.ioЧÀͱ£´æXSSÎó²î£¬£¬£¬£¬Ðí¶àʹÓøÃЧÀ͵ĴóÐÍÍøÕ¾¶¼Êܵ½Ó°Ï죬£¬£¬£¬°üÀ¨Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ£¬£¬£¬£¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæÁÙΣº¦¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î»á¼ûÓû§µÄÉèÖÃÎļþºÍÏêϸÐÅÏ¢¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÒÑÐÞ¸´£¬£¬£¬£¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§¼ì²é×Ô¼ºµÄÕË»§²¢ÇÒÐÞ¸ÄÃÜÂë¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/


3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´ÐеÄÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓëÆÊÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ßΣº¦Îó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©£¬£¬£¬£¬¸øÕþ¸®»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´Î£º¦¡£¡£¡£¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£¡£ÏÖÔÚ»¹Ã»ÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/


4¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÎÚ¿ËÀ¼Çå¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷¡£¡£¡£¡£SBUר¼ÒÖ¸³ö£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ£¬£¬£¬£¬Æä¹¦Ð§°üÀ¨Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍ×èµ²ÃÜÂëµÈ¡£¡£¡£¡£Æ¾Ö¤SBUºÍÒ»¸öÇå¾²³§É̵ÄÊӲ죬£¬£¬£¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬SBU»¹·¢Ã÷ÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÍ̹¤¾ß¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html


5¡¢¿¨°Í˹»ùÅû¶·¸·¨ÍÅ»ïDustSquadµÄй¤¾ßOctopus

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿¨°Í˹»ùʵÑéÊÒÅû¶·¸·¨ÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£OctopusÖ÷ÒªÕë¶ÔÖÐÑǵØÇøµÄÍâ½»²¿·Ö£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü£¬£¬£¬£¬Æäʱ¼ä´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ£¬£¬£¬£¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â£¬£¬£¬£¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£¡£¡£¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖ³¤ÆÚÐÔ£¬£¬£¬£¬ÆäЧÀÍÆ÷¶ËÊÇPHPµÄ£¬£¬£¬£¬°²ÅÅÔÚ²î±ð¹ú¼Ò/µØÇøµÄÉÌÒµÍйÜЧÀÍÖС£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/octopus-infested-seas-of-central-asia/88200/


6¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿Ö°Ô±ÔÚ°µÍøÂÛ̳ÉÏ·¢Ã÷Ò»¸ö°üÀ¨´ó×ÚÑ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ¡£¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ¡£¡£¡£¡£Ñо¿Ö°Ô±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾¾ÙÐÐÁËÉó²é£¬£¬£¬£¬È·ÈÏÕâЩÊý¾ÝÓÐÓò¢ÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶȡ£¡£¡£¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´£¬£¬£¬£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆËðÑ¡¾Ù»ò¾ÙÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí