¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181012
°ä²¼¹¦·ò 2018-10-12
¿¨°Í˹»ù³¢ÊÔÊÒÓÚ2018Äê8ÔÂ17ÈÕÏò΢Èí»ã±¨ÁËWindows 0day£¨CVE-2018-8453£©£¬¸Ã·ì϶ÒÑÔÚ΢ÈíµÄ10Ô°²È«¸üÐÂÖеõ½½¨¸´¡£¸Ã·ìÏ¶ÖØÒª±»APT×éÖ¯FruityArmorËùʹÓã¬ÓÃÀ´¹¥»÷Öж«µØÓòµÄÖ¸±ê¡£Æä¹¥»÷»î¶¯ÊǸ߶ÈÕë¶ÔÐԵģ¬Êܺ¦ÕßµÄÊýÁ¿²»³¬¹ý12¸ö¡£×êÑÐÍŶÓÄæÏòÁ˲¶»ñµ½µÄ·ì϶ÀûÓÃÑù±¾£¬²¢½«Æä³ÁдΪÆëÈ«µÄPoC¡£
https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/
2¡¢×êÑÐÍŶӷ¢ÏÖNotPetyaºÍIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª
ESET×êÑÐÍŶӷ¢ÏÖ¶ñÒâÈí¼þNotPetyaºÍºóÃÅIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª¡£ÕâÁ½¸ö¶ñÒâÈí¼þ¶¼±»ÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µÄÖ¸±ê¡£×êÑÐÍŶÓͨ¹ý¶ÈÎöTeleBotsʹÓõÄкóÃÅWin32/ExaramelÈ·ÈÏÁËÕâЩÁªÏµ£¬ÔÚÕâ֮ǰ×êÑÐÍŶÓÖ»Äܲ²âËüÃǵĹØÁª¡£ÐµÄÖ¤¾ÝÅú×¢£¬ExaramelºÍIndustroyerÖ®¼äÓµÓкÜÇ¿µÄ´úÂëÀàËÆÐÔºÍÐÐΪ£¬ÕâÒâζ×ÅËüÃÇÀ´×ÔÓÚͳһ¿ª·¢Õß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-backdoor-ties-notpetya-and-industroyer-to-telebots-group/3¡¢×êÑÐÍŶÓ×ܽá´ÓǰËÄÄêÄÚººÉÀ¼»îÔ¾µÄAPT×éÖ¯
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚºÉÀ¼µÄ»îÔ¾APT×éÖ¯µÄ×ÛÊö£¬¸Ã×ÛÊöͨ¹ý×ܽá´ÓǰËÄÄêÄÚ£¨2014Äê9ÔÂÖÁ2018Äê9Ô£©ºÉÀ¼µÄ¸ß¼¶ÍøÂçÍþв»î¶¯£¬¸ÅÊöÁ˺ÉÀ¼µÄAPT×éÖ¯¼°Æä»îÔ¾¹¦·ò¡¢ÖØÒªÕë¶ÔµÄÖ¸±êµÈÐÅÏ¢¡£ÕâЩAPT×éÖ¯Ô̺¬BlackOasis¡¢Sofacy¡¢Hades¡¢Buhtrap¡¢The Lamberts¡¢Turla¡¢Gatak¡¢Putter PandaºÍAnimal Farm¡£
https://securelist.com/threats-in-the-netherlands/88185/
4¡¢McAfee°ä²¼¹ØÓÚÀÕË÷Èí¼þGandCrab v5.0.2µÄ·ÖÎö»ã±¨
McAfee Labs°ä²¼¹ØÓÚÀÕË÷Èí¼þGandCrab v5µÄ·ÖÎö»ã±¨£¬±¾Ô³õGandCrabÒѾ¸üÐÂÖÁ°æ±¾5.0.2¡£´Ó°æ±¾4ÆðÍ·£¬GandCrabÆðͷͨ¹ýFallout EK½øÐзַ¢£»ÔÚ°æ±¾5ÖУ¬GandCrabÓÖÓë¶ñÒâÈí¼þ¼ÓÃÜ·þÎñNTCrypt½øÐкÏ×÷¡£NTCrypt¿ÉÒÔΪ¶ñÒâÈí¼þÌṩ»ìºÏÒÔÌӱܼì²â¡£ÕâÖÖÓëÆäËü¶ñÒâÈí¼þ½øÐнáÃ˵ÄÐÐΪʹµÃÆä¹¥»÷»î¶¯µÄÔËÓªÔ½·¢·½±ã£¬²¢ÇÒ¿¿µÃסµÄͬÃËÄܹ»Ô¤·À²»ÊÜÐÅÀµµÄ¹©¸øÉ̺ͷÖÏúÉÌ£¬´Ó¶ø×î´óÏ޶ȵؽµµÍ·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/mcafee-labs/rapidly-evolving-ransomware-gandcrab-version-5-partners-with-crypter-service-for-obfuscation/5¡¢TalosÍŶӷ¢ÏÖÖØÒªÕë¶ÔAndroidµÄÐÂľÂíGPlayed
˼¿ÆTalos·¢ÏÖÖØÒªÕë¶ÔAndroidƽ̨µÄÐÂÌØÂåÒÁľÂíGPlayed¡£GPlayedÓµÓкܶàÄÚÖÃÖ°ÄÜ£¬²¢ÇÒ¼«¶È½Ã½Ý£¬¹¥»÷ÕßÄܹ»Ô¶³Ì¼ÓÔØ²å¼þ¡¢×¢Èë¾ç±¾ÉõÖÁ±àÒëеÄ.NET´úÂë¡£×êÑÐÍŶӷ¢ÏֵĶñÒâÑù±¾Ê¹ÓÃÁËÀàËÆÓÚGoogle AppsµÄͼ±ê£¬¼Ù×°³ÉGoogle Play MarketplaceÒÔºýŪÓû§¡£¸Ã¶ñÒâÈí¼þÊÇÔÚXamarin»·¾³ÏÂÓÃ.NET±àдµÄ£¬ÆäÖ÷DLLÊÇReznov.DLL£¬¸ÃDLLÖÐÔ̺¬Ä¾ÂíµÄÖ÷Ìâ¸ùÀàeClient¡£¸ÃÑù±¾ÖØÒªÕë¶Ô¶íÓïÓû§£¬·ÖÎöÅú×¢¸ÃľÂí»¹´¦ÓÚ²âÊԽ׶Ρ£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2018/10/gplayedtrojan.html6¡¢ÄÏ·ÇÍйܷþÎñÉÌHetznerÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ
ÄÏ·ÇÍøÂçÍйܷþÎñÉÌHetznerÔÚ´Óǰ12¸öÔÂÄÚµÚ¶þ´ÎÔâµ½ºÚ¿ÍÈëÇÖ¡£ÈëÇÖ²úÉúÔÚ10ÔÂ5ÈÕÐÇÆÚÎ壬¹¥»÷ÕßÉè·¨½Ó¼ûÁ˲¿ÃÅÓû§µÄÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µØÖ·¡¢Éí·ÝºÅÂë¡¢Ôöֵ˰ºÅÂëÒÔ¼°ÒøÐÐÕ˺ŵȣ¬µ«Ã»ÓÐÈκÎÖ§¸¶ÐÅÏ¢ºÍÃÜÂëÐÅϢй¶¡£ÉÏÒ»´ÎºÚ¿ÍÈëÇÖ²úÉúÔÚ2017Äê11Ô£¬Ô¼4ÍòÃûÓû§µÄÐÅÏ¢±»ÇÔ£¬µ«¸Ã¹«Ë¾Ã»ÓÐй©µÚ¶þ´Î¹¥»÷µÄÓ°ÏìÁìÓò¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-breach-web-hosting-provider-for-the-second-time-in-the-past-year/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ