¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181022
Ðû²¼Ê±¼ä 2018-10-23
ÉÏÖÜÎåÃÀ¹úÒ½Áưü¹ÜºÍÒ½ÁƽòÌùЧÀÍÖÐÐÄ£¨CMS£©Ðû²¼ÐÂÎųƣ¬£¬£¬ÓëHealthCare.govÏà¹ØµÄÒ»¸öÕþ¸®ÅÌËã»úϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬Ô¼7.5ÍòÃûÓû§µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£CMSÌåÏÖÔÚ10ÔÂ16ÈÕÈ·ÈÏÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬£¬£¬²¢½ûÓÃÁËÓëÒì³£»£»£»£»£»£»î¶¯Ïà¹ØµÄÓû§ÕË»§¡£¡£¡£¡£¡£CMSºÍFBIÕýÔÚÍýÏë֪ͨËùÓÐÊÜÓ°ÏìµÄÓû§£¬£¬£¬²¢ÌṩÐÅÓñ£»£»£»£»£»£»¤µÈ×ÊÔ´¡£¡£¡£¡£¡£
2£¬£¬£¬Çå¾²³§ÉÌÅû¶Õë¶Ô¹·¹·±ÒµÄÔÚÏßÚ²ÆÀ˳±

Çå¾²³§ÉÌDoctor WebµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶Ô¹·¹·±ÒµÄÔÚÏßթƻ¡£¡£¡£¡£¡£¹¥»÷Õß±»³ÆÎªInvestimer£¨ÓÖÃûHyipblock»òMmpower£©£¬£¬£¬ËûÃÇʹÓðµÍøÊг¡ÉϵÄÖÖÖÖÖ÷Á÷ÉÌҵľÂíÀ´ÇÔÈ¡Óû§µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬°üÀ¨Eredel¡¢AZORult¡¢Kpot¡¢Kratos¡¢N0F1L3¡¢ACRUX¡¢Predator The Thief¡¢ArkeiºÍPonyµÈ¡£¡£¡£¡£¡£Investimerͨ¹ýÖÖÖÖ´¹ÂÚÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬×¨¼ÒÔ¤¼ÆÊÜÓ°ÏìµÄÓû§Áè¼Ý1ÍòÈË£¬£¬£¬×ÜËðʧÁè¼Ý2.3ÍòÃÀÔª¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://news.drweb.com/show/?c=5&i=12886&lng=en
3£¬£¬£¬Ñо¿Ö°Ô±Åû¶Õë¶ÔWindowsϵͳµÄÐÂRIDÐ®ÖÆ¹¥»÷

CSLÇå¾²Ñо¿Ö°Ô±Sebasti¨¢nCastro·¢Ã÷Ò»ÖÖÕë¶ÔWindowsÓû§ÕÊ»§²ÎÊýRIDµÄÐ®ÖÆ¹¥»÷¡£¡£¡£¡£¡£RIDÓÃÓÚÐÎòÓû§µÄȨÏÞ×飬£¬£¬°üÀ¨±ê×¼À´±öÕÊ»§501ºÍÖÎÀíÔ±ÕÊ»§500µÈ¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÐÞ¸ÄWindowsÕÊ»§ÐÅÏ¢µÄ×¢²á±íÏ£¬£¬ÎªÖ¸¶¨ÕË»§ÊÚÓè²î±ðµÄRID£¬£¬£¬½ø¶ø»ñµÃϵͳµÄÍêÕû»á¼ûȨÏÞ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¿ª·¢ÁËÒ»¸ö¿É×Ô¶¯»¯ÊµÑé´Ë¹¥»÷µÄMetasploitÄ£¿£¿£¿£¿érid_hijack¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttp://csl.com.co/rid-hijacking/
4£¬£¬£¬ÃÀWest HavenÊÐÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶2000ÃÀÔªÊê½ð
ÃÀ¹ú¿µÄùµÒ¸ñÖݵÄWest HavenÊÐÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Õþ¸®ÒÑÏò¹¥»÷ÕßÖ§¸¶ÁË2000ÃÀÔªµÄÊê½ðÒÔ½âËø23̨ЧÀÍÆ÷²¢»Ö¸´¶Ô¶¼»áÏà¹ØÏµÍ³Êý¾ÝµÄ»á¼û¡£¡£¡£¡£¡£¸Ã±ÊÊê½ðÊÇͨ¹ý±ÈÌØ±ÒÖ§¸¶µÄ¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚÉÏÖܶþÉÏÎ磬£¬£¬ÊÐÕþ¹ÙԱͨ¹ýÑо¿ÒÔΪ֧¸¶Êê½ðÊÇ×îºÃµÄ½â¾ö¼Æ»®¡£¡£¡£¡£¡£ÁìÍÁÇå¾²²¿ÒÔΪ¸Ã¹¥»÷À´×ÔÓÚ¾³Í⣬£¬£¬ÏÖÔÚ»¹ÔÚ¼ÌÐø¾ÙÐÐÊӲ졣¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/city-pays-2000-computer-ransomware-attack
5£¬£¬£¬Ñо¿ÍŶÓÅû¶¶à¿îNAS×°±¸ÖеĶà¸öÇå¾²Îó²î

WizCaseÇå¾²Ñо¿Ö°Ô±ÔÚ¶à¿îNAS×°±¸Öз¢Ã÷¶à¸öÇå¾²Îó²î£¬£¬£¬ÊÜÓ°ÏìµÄÆ·ÅÆ°üÀ¨Î÷Êý¡¢Íø¼þ¡¢Ï£½ÝºÍMedionµÈ¡£¡£¡£¡£¡£ÕâЩװ±¸¶¼±£´æÒ»¸öÁãÈÕÎó²î£¬£¬£¬¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£ÏÖÔÚÏà¹ØÎó²î£¨CVE-2018-18472ºÍCVE-2018-18471£©»¹Î´»ñµÃÐÞ¸´£¬£¬£¬ÊÜÓ°ÏìµÄÔÚÏß×°±¸µÄÊýÄ¿´ï½ü200Íǫ̀¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪÆäËüNAS×°±¸ºÜÓпÉÄÜÒ²±£´æÀàËÆµÄÎó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.wizcase.com/blog/hack-2018/
6£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÔÚ¼ÓÃÜʱÅþÁ¬µ½BleepingComputerÍøÕ¾µÄÐÂÀÕË÷Èí¼þ

Ñо¿Ö°Ô±nao_secºÍKafeine·¢Ã÷ÀÕË÷Èí¼þKraken Cryptor v2.0.6»áÔÚ¼ÓÃܵIJî±ð½×¶ÎÅþÁ¬µ½BleepingComputerÍøÕ¾²¢·¢ËÍÏà¹ØÊý¾Ý¡£¡£¡£¡£¡£¸Ã°æ±¾ÊÇÉÏÖÜÄ©Ðû²¼µÄ£¬£¬£¬Ö÷Ҫͨ¹ý¶ñÒâ¹ã¸æºÍÎó²îʹÓù¤¾ß°üRIG¾ÙÐзַ¢¡£¡£¡£¡£¡£×Ô2018Äê10ÔÂ20ÈÕÒÔÀ´£¬£¬£¬¸Ã°æ±¾ÒÑÔÚÈ«ÌìϹæÄ£ÄÚѬȾÁË217ÃûÓû§¡£¡£¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎú¶ñÒâÈí¼þ¿ª·¢ÕßÕâÑù×öµÄÄ¿µÄ£¬£¬£¬µ«Ñо¿Ö°Ô±ÒÔΪÕâ¿ÉÄÜÊǶñÒâµÄÍæÐ¦¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/kraken-cryptor-ransomware-connecting-to-bleepingcomputer-during-encryption/
ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí