IBMÐÞ¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸öÎó²î£»£»£»£»£»£»TA505ÐÂÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬£¬£¬Ö÷Òª·Ö·¢GelupºÍFlowerPippi

Ðû²¼Ê±¼ä 2019-07-05
1¡¢IBMÐÞ¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
IBMÐÞ¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸öÎó²î£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Êý¾ÝÆÊÎö¹¤¾ßPlanning Analytics¡¢Êý¾Ý±£»£»£»£»£»£»¤Æ½Ì¨Security GuardiumºÍWebͼÏñÉó²éÆ÷Daeja ViewONEµÈ¡£ ¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇSpectrum ProtectÖеĻº³åÇøÒç³öÎó²î£¨CVE-2019-4087£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8·Ö¡£ ¡£¡£Æ¾Ö¤IBMµÄ±íÊö£¬£¬£¬£¬£¬£¬Í¨¹ý·¢Ë͹ý³¤µÄÇëÇ󣬣¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜ»áÒç³ö»º³åÇø²¢ÔÚ¾ßÓÐʵÀýIDȨÏÞµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬»òµ¼ÖÂЧÀÍÆ÷/´æ´¢ÊðÀíÍ߽⡣ ¡£¡£¸ÃÎó²îÔ´ÓÚSpectrum ProtectÖеIJ»×¼È·½çÏß¼ì²é£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾°üÀ¨7.1ºÍ8.1¡£ ¡£¡£ÁíÒ»¸öÑÏÖØµÄÎó²îÊÇSecurity GuardiumÖеÄÎļþÉÏ´«Îó²î£¨CVE-2019-4292£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8·Ö£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾Îª10.5¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/ibm-patches-critical-high-severity-flaws-in-spectrum-protect/146201/

2¡¢TA505ÐÂÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬£¬£¬Ö÷Òª·Ö·¢GelupºÍFlowerPippi

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶÓÔÚ6Ô·ÝÊӲ쵽TA505µÄ¶à¸ö¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷»î¶¯Ö÷ÒªÕë¶Ô°¢ÁªÇõºÍÉ³ÌØ°¢À­²®µÈÖж«¹ú¼ÒÒÔ¼°Ó¡¶È¡¢ÈÕ±¾¡¢°¢¸ùÍ¢¡¢·ÆÂɱöºÍº«¹úµÈÆäËü¹ú¼Ò¡£ ¡£¡£Ñо¿ÍŶӼì²âµ½Ò»¸öеĶñÒâÈí¼þ¹¤¾ßGelup£¨Trojan.Win32.GELUP.A£©£¬£¬£¬£¬£¬£¬Gelup¿ÉÈÆ¹ýUAC²¢¼ÓÔØÆäËüpayload£¬£¬£¬£¬£¬£¬ÀýÈçFlawedAmmyy RAT¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬TA505»¹Ê¹ÓÃÁËÁíÒ»¸ö¹¤¾ßFlowerPippi£¨Backdoor.Win32.FLOWERPIPPI.A£©£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇÒ»¸öеĺóÃźÍÏÂÔØÆ÷¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/latest-spam-campaigns-from-ta505-now-using-new-malware-tools-gelup-and-flowerpippi/

3¡¢SodinokibiÐÂÑù±¾Ê¹ÓÃWindowsÎó²î¾ÙÐÐÌáȨ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
¿¨°Í˹»ùÐû²¼¹ØÓÚÀÕË÷Èí¼þSodinokibiÐÂÑù±¾µÄÆÊÎö±¨¸æ¡£ ¡£¡£Ñо¿Ö°Ô±·¢Ã÷SodinokibiʹÓÃWindowsÖеÄÎó²î£¨CVE-2018-8453£©¾ÙÐÐÌáȨ¡£ ¡£¡£Æ¾Ö¤¿¨°Í˹»ùµÄÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þµÄѬȾÊÂÎñ±é²¼È«Çò£¬£¬£¬£¬£¬£¬ÆäÖд󲿷ÖλÓÚÑÇÌ«µØÇø£ºÖйų́Í壨17.56£¥£©¡¢ÖйúÏã¸ÛÒÔ¼°º«¹ú£¨8.78£¥£©¡£ ¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃÀÕË÷Èí¼þÔÚ×¢²á±íÖд洢Á˹«Ô¿ºÍ¼ÓÃܵÄ˽Կ¡£ ¡£¡£¸ÃÀÕË÷Èí¼þ»¹»áʶ±ð¼üÅ̽ṹ£¬£¬£¬£¬£¬£¬²¢ÔÚ¶íÂÞ˹¡¢ÎÚ¿ËÀ¼µÈ¹ú¼ÒµÄÅÌËã»úÉÏÖÐÖ¹ÔËÐС£ ¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-exploits-windows-bug-to-elevate-privileges/

4¡¢ÒøÐÐľÂíTrickbotÐÂÔöä¯ÀÀÆ÷CookieÇÔÈ¡Ä £¿£¿£¿ £¿£¿£¿£¿é

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Ñо¿Ö°Ô±Brad Duncan·¢Ã÷ÒøÐÐľÂíTrickbotÐÂÔöÒ»¸öcookieÇÔÈ¡Ä £¿£¿£¿ £¿£¿£¿£¿é¡£ ¡£¡£¸ÃÄ £¿£¿£¿ £¿£¿£¿£¿éÍêÈ«×ÔÁ¦£¬£¬£¬£¬£¬£¬²¢ÇÒ´øÓÐ×Ô¼ºµÄÉèÖÃÎļþ¡£ ¡£¡£ÁíÒ»ÃûÑо¿Ö°Ô±Vitali Kremez֤ʵÁ˸ÃÄ £¿£¿£¿ £¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬²¢Ôö²¹³ÆÐÂÄ £¿£¿£¿ £¿£¿£¿£¿éµÄ¹¹½¨ÈÕÆÚÊÇ6ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÕë¶ÔËùÓеÄÖ÷ÒªWebä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨Chrome¡¢Firefox¡¢Internet ExplorerºÍMicrosoft Edge¡£ ¡£¡£Í¨¹ýÇÔÈ¡cookie£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»ñȡĿµÄµÄÍøÕ¾µÇ¼״̬¡¢Æ«ºÃ¡¢¸öÐÔ»¯ÄÚÈÝ»ò¸ú×ÙÓû§µÈ¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/trickbot-trojan-updated-with-standalone-cookie-stealing-module-1831b2a8

5¡¢BianLianбäÖÖÌí¼ÓÆÁÄ»Â¼ÖÆºÍ½¨ÉèSSHЧÀÍÆ÷¹¦Ð§

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
FortiGuard LabsÑо¿Ö°Ô±·¢Ã÷ÒøÐÐľÂíBianLianµÄбäÖÖ£¬£¬£¬£¬£¬£¬¸Ã±äÖÖ°üÀ¨Á½¸öÐÂÄ £¿£¿£¿ £¿£¿£¿£¿é£ºÆÁÄ»Â¼ÖÆºÍ½¨ÉèSSHЧÀÍÆ÷¡£ ¡£¡£¸ÃбäÖÖÒÔAPKµÄÐÎʽ·Ö·¢£¬£¬£¬£¬£¬£¬²¢¾­ÓÉÑÏÖØ»ìÏý£¬£¬£¬£¬£¬£¬ÀýÈçÌìÉúÖÖÖÖËæ»úº¯ÊýÒÔÒþ²ØÄ¾ÂíµÄÕæÊµ¹¦Ð§¡£ ¡£¡£Ñо¿Ö°Ô±Ö¸³ö¸Ã±äÖÖ¿ÉÒþ²ØÍ¼±ê²¢ÉêÇëAndroid¸¨Öú¹¦Ð§µÄȨÏÞ£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡´°¿ÚÄÚÈݺÍÓû§ÔÚÆäËüÓ¦ÓÃÖÐÊäÈëµÄ¿¨ºÅºÍÃÜÂë¡£ ¡£¡£¸Ã±äÖÖ½¨ÉèµÄSSHЧÀÍÆ÷¿ÉÒÔÊðÀíת·¢ÆäC2ͨѶ£¬£¬£¬£¬£¬£¬ÒÔÌӱܼì²â¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/new-bianlian-variant-comes-with-screen-recording-and-creating-ssh-server-capabilities-5f772c50

6¡¢ÓÌËûÖÝÒ»ºÚ¿ÍÒòDDoSÓÎÏ·¹«Ë¾±»ÅÐÈëÓü27¸öÔÂ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Ò»ÃûÀ´×ÔÓÌËûÖݵÄ23ËêºÚ¿Í£¨Austin Thompson£©ÒòÔÚ2013Äê12ÔÂÖÁ2014Äê1ÔÂʱ´ú¶Ô¶à¸öÓÎϷƽ̨ÌᳫDDoS¹¥»÷±»ÅÐÈëÓü27¸öÔ¡£ ¡£¡£ÊÜÆä¹¥»÷µÄÓÎϷƽ̨°üÀ¨EAµÄOriginƽ̨¡¢Ë÷ÄáµÄPlayStationÍøÂçÒÔ¼°ValveµÄSteamƽ̨µÈ¡£ ¡£¡£Æ¾Ö¤ÃÀ¹ú˾·¨²¿ÖÜÈýÐû²¼µÄÐÂΟ壬£¬£¬£¬£¬£¬ThompsonµÄÐÐΪÖÁÉÙµ¼ÖÂÁË9.5ÍòÃÀÔªµÄËðʧ¡£ ¡£¡£³ýÁËÈëÓüÖ®Í⣬£¬£¬£¬£¬£¬Ë¾·¨²¿»¹ÏÂÁî±»¸æÏòDaybreak Games£¨Ô­Ë÷ÄáÔÚÏßÓéÀÖ¹«Ë¾£©Ö§¸¶9.5ÍòÃÀÔªµÄÅâ³¥½ð¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/christmas-ddos-attacks.html