¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181016

Ðû²¼Ê±¼ä 2018-10-16
1¡¢Malwarebytes LabsÐû²¼2018 Q3ÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Malwarebytes LabsÐû²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ£¬ £¬£¬£¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó£¬ £¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμÓËÙÁËËûÃǵĶñÒâ»î¶¯¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÍþвÇ÷ÊÆ°üÀ¨¶ñÒâÍÚ¿óÈí¼þºÍÎó²îʹÓù¤¾ß°ü±äµÃ³ÉÊ죬 £¬£¬£¬ÀÕË÷Èí¼þÎȲ½ÔöÌí£¬ £¬£¬£¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯×îÏÈËÕÐѵÈ¡£¡£¡£¡£¡£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔöÌíÁË55%£¬ £¬£¬£¬Ïà±ÈÖ®ÏÂÕë¶ÔÏûºÄÕßµÄÍþв½öÔöÌí4%£¬ £¬£¬£¬ÕâÒâζ׏¥»÷ÕßÕýÔÚ×·Çó¸ü´óµÄÀûÒæ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/


2¡¢Branch.ioЧÀͱ»ÆØ±£´æXSSÎó²î£¬ £¬£¬£¬6.85ÒÚÓû§ÒÉÃæÁÙΣº¦

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

vpnMentorµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Branch.ioЧÀͱ£´æXSSÎó²î£¬ £¬£¬£¬Ðí¶àʹÓøÃЧÀ͵ĴóÐÍÍøÕ¾¶¼Êܵ½Ó°Ï죬 £¬£¬£¬°üÀ¨Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ£¬ £¬£¬£¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæÁÙΣº¦¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î»á¼ûÓû§µÄÉèÖÃÎļþºÍÏêϸÐÅÏ¢¡£¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÒÑÐÞ¸´£¬ £¬£¬£¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§¼ì²é×Ô¼ºµÄÕË»§²¢ÇÒÐÞ¸ÄÃÜÂë¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/


3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´ÐеÄÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓëÆÊÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ßΣº¦Îó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©£¬ £¬£¬£¬¸øÕþ¸®»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´Î£º¦¡£¡£¡£¡£¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»ÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/


4¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÎÚ¿ËÀ¼Çå¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷¡£¡£¡£¡£¡£SBUר¼ÒÖ¸³ö£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ£¬ £¬£¬£¬Æä¹¦Ð§°üÀ¨Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍ×èµ²ÃÜÂëµÈ¡£¡£¡£¡£¡£Æ¾Ö¤SBUºÍÒ»¸öÇå¾²³§É̵ÄÊӲ죬 £¬£¬£¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬SBU»¹·¢Ã÷ÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÍ̹¤¾ß¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html


5¡¢¿¨°Í˹»ùÅû¶·¸·¨ÍÅ»ïDustSquadµÄй¤¾ßOctopus

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿¨°Í˹»ùʵÑéÊÒÅû¶·¸·¨ÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£OctopusÖ÷ÒªÕë¶ÔÖÐÑǵØÇøµÄÍâ½»²¿·Ö£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü£¬ £¬£¬£¬Æäʱ¼ä´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ£¬ £¬£¬£¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â£¬ £¬£¬£¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£¡£¡£¡£¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖ³¤ÆÚÐÔ£¬ £¬£¬£¬ÆäЧÀÍÆ÷¶ËÊÇPHPµÄ£¬ £¬£¬£¬°²ÅÅÔÚ²î±ð¹ú¼Ò/µØÇøµÄÉÌÒµÍйÜЧÀÍÖС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/octopus-infested-seas-of-central-asia/88200/


6¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿Ö°Ô±ÔÚ°µÍøÂÛ̳ÉÏ·¢Ã÷Ò»¸ö°üÀ¨´ó×ÚÑ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾¾ÙÐÐÁËÉó²é£¬ £¬£¬£¬È·ÈÏÕâЩÊý¾ÝÓÐÓò¢ÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶÈ¡£¡£¡£¡£¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´£¬ £¬£¬£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆËðÑ¡¾Ù»ò¾ÙÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí