2018ÄêIoT¹¥»÷ÔöÌí217.5£¥£»£»£»£»Ìع¤Èí¼þExodus£»£»£»£»ÒøÐÐľÂíAnubisѬȾ300¶à¼Ò½ðÈÚ»ú¹¹

Ðû²¼Ê±¼ä 2019-04-01


¡ª άËûÃüÖðÈÕÇå¾²¼òѶ ¡ª



1.ÄáÈÕÀûÑǹúÃñÒé»áNASS¹ÙÍø±»Ö²Èë´¹ÂÚ´úÂë

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


MalwareHunterTeamÑо¿ÍŶӷ¢Ã÷ÄáÈÕÀûÑǹúÃñÒé»á£¨NASS£©¹ÙÍøÉÏÍйÜÁËÒ»¸öαװ³É¹ú¼Ê¿ìµÝЧÀÍDHLµÄ´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬¸ÃÒ³ÃæÖÁÉÙ±£´æÁËÁ½ÖܵÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÇÔÈ¡Óû§µÄDHLÕË»§Æ¾Ö¤¡£¡£¡£¡£¡£¡£¡£Õâ¸ö´¹ÂÚÒ³Ãæu.php±£´æÓÚ¶à¸ö±»ÉøÍ¸µÄÕýµ±ÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬°üÀ¨onlinequranglobal[.]com¡¢pioneer-sys[.]netµÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿ÍŶӻ¹³ÆNASSµÄ¹ÙÍøÖ®Ç°¾ÍÔøÍйܹý¶à¸ö¶ñÒâÕ¾µã¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ironically-phishing-kit-hosted-on-nigerian-government-site/


2.GOG Galaxy¶à¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÌáȨ¡¢ÐÅϢй¶¼°DoS


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÅû¶GOG GalaxyÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬GOG GalaxyÊÇÒ»¸öÊ¢ÐеÄÓÎϷƽ̨£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚÆä¿Í»§¶Ë°æ±¾1.2.48.36Öз¢Ã÷6¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨4¸öÌáȨÎó²î£¨CVE-2018-4048~CVE-2018-4051£©¡¢1¸öÐÅϢй¶Îó²î£¨CVE-2018-4052£©ºÍ1¸ö¿Éµ¼ÖÂDoSµÄÎó²î£¨CVE-2018-4053£©¡£¡£¡£¡£¡£¡£¡£ËùÓÐÎó²î¶¼ÒÑÔÚ×îа汾µÄGOG GalaxyÖлñµÃÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/gog-galaxy-riddled-with-multilple-security-vulnerabilities-859d95fd


3.SonicWallб¨¸æ³Æ2018ÄêIoT¹¥»÷ÔöÌí217.5£¥


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤SonicWallµÄÄê¶ÈÍøÂçÍþв±¨¸æ£¨2019°æ£©£¬£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬£¬£¬£¬£¬£¬£¬±È2017ÄêµÄ1030Íò´ÎÔöÌíÁË217.5£¥¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÔöÌíµÄÔµ¹ÊÔ­ÓÉÊÇIoT×°±¸ÖÆÔìÉÌδÄÜʵÑéÊʵ±µÄÇå¾²¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£È«ÇòÁè¼Ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØµãÔ´ÓÚÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú£¨13%£©¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´Î´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬±È2017ÄêϽµ4.1£¥¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/


4.Google PlayÖз¢Ã÷ÐÂÌØ¹¤Èí¼þExodus£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±ÔÚGoogle Play StoreÖз¢Ã÷Ò»¸öÌØ¹¤Èí¼þExodus¡£¡£¡£¡£¡£¡£¡£Exodusαװ³ÉÒâ´óÀûÒÆ¶¯Í¨Ñ¶É̵ĴÙÏú/ÓªÏúAPP»òÊÖ»úÐÔÄÜÓÅ»¯¹¤¾ß£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨Â¼Òô¡¢µç»°¡¢ä¯ÀÀÀúÊ·¡¢ÈÕÀú¡¢µØÀíλÖá¢Facebook MessengerÈÕÖ¾¡¢WhatsApp̸ÌìÐÅÏ¢ºÍ¶ÌÐŵȡ£¡£¡£¡£¡£¡£¡£Exodus»¹»áÔÚÊÜѬȾµÄ×°±¸ÉϽ¨ÉèÒ»¸öshellºóÃÅ¡£¡£¡£¡£¡£¡£¡£Exodusͨ¹ýCheckValidTarget¹¦Ð§Ãé×¼ÌØ¶¨µÄÒâ´óʹÓû§£¬£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±³Æ¸Ã¹¦Ð§²»¿ÉÕý³£ÊÂÇ飬£¬£¬£¬£¬£¬£¬Òò´ËÆäËûÓû§Ò²»áÊܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/83102/breaking-news/exodus-malware-google-play.html


5.ÒøÐÐľÂíAnubis£¬£¬£¬£¬£¬£¬£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AndroidÒøÐÐľÂíAnubisÖ÷Ҫͨ¹ýGoogle Play Store·Ö·¢£¬£¬£¬£¬£¬£¬£¬×Ô2017ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬£¬AnubisÒѾ­Ñ¬È¾ÁËÈ«ÇòÁè¼Ý300¼Ò½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£Anubisͨ³£Î±×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊÊÓÃС¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍ̸ÌìAPPµÈ£¬£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£¡£¡£¡£¡£¡£¡£2019Äê3Ô£¬£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67


6.΢Èí½ÓÊÜÒÁÀÊPhosphorus APTµÄ99¸ö¹¥»÷ÓòÃû


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÐû²¼ÒÑÀֳɽÓÊÜÒÁÀÊPhosphorus APT£¨ÓÖ³ÆAPT35£©ËùʹÓõÄ99¸ö¹¥»÷ÓòÃû¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ïà¹ØÎļþ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÏòÃÀ¹úµØÒªÁìÔºÌá³öÉêËߣ¬£¬£¬£¬£¬£¬£¬³ÆÕâЩÓòÃûÓë¸ÃAPT×éÖ¯µÄ²»·¨ÈëÇֻÓйء£¡£¡£¡£¡£¡£¡£ÔÚ·¨ÔºÏÂÁîµÄÊÚȨÏ£¬£¬£¬£¬£¬£¬£¬Î¢Èí½ÓÊÜÁËÕâЩ¹¥»÷ÓòÃû²¢Î´À´×ÔÊÜѬȾװ±¸µÄÁ÷Á¿Öض¨ÏòÖÁsinkhole¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/83128/apt/phosphorus-apt-seized-domains.html