¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181016

°ä²¼¹¦·ò 2018-10-16
1¡¢Malwarebytes Labs°ä²¼2018 Q3ÍøÂç·¸×ïÕ½ÊõÓë¼¼Êõµ÷²é»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Malwarebytes Labs°ä²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸×ïÕ½ÊõÓë¼¼Êõµ÷²é»ã±¨£¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó£¬ÍøÂç·¸×ï·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμӿìÁËËûÃǵĶñÒâ»î¶¯¡£±¾¼¾¶ÈµÄÍþвÇ÷ÏòÔ̺¬¶ñÒâÍÚ¿óÈí¼þºÍ·ì϶ÀûÓù¤¾ß°ü±äµÃ³ÉÊ죬ÀÕË÷Èí¼þÎȲ½Ôö³¤£¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯ÆðÍ·¸´Ëյȡ£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔö³¤ÁË55%£¬Ïà±ÈÖ®ÏÂÕë¶ÔÏû·ÑÕßµÄÍþв½öÔö³¤4%£¬ÕâÒâζ׏¥»÷ÕßÔÚ×·Çó¸ü´óµÄÀûÒæ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/


2¡¢Branch.io·þÎñ±»ÆØ´æÔÚXSS·ì϶£¬6.85ÒÚÓû§ÒÉÃæ¶Ô·çÏÕ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

vpnMentorµÄ°²È«×êÑÐÈËÔ±·¢ÏÖBranch.io·þÎñ´æÔÚXSS·ì϶£¬ºÜ¶àʹÓø÷þÎñµÄ´óÐÍÍøÕ¾¶¼Êܵ½Ó°Ï죬Ô̺¬Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ£¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæ¶Ô·çÏÕ¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶½Ó¼ûÓû§µÄÅäÖÃÎļþºÍ¾ßÌåÐÅÏ¢¡£¹ÌÈ»¸Ã·ì϶Òѽ¨¸´£¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§²é³­×Ô¼ºµÄÕË»§²¢ÇÒÅú¸ÄÃÜÂë¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/


3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´Ðеķì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓë·ÖÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ß·çÏÕ·ì϶¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ִÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ£¨DoS£©£¬¸øµ±¾Ö»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´·çÏÕ¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11Öн¨¸´ÁËÕâЩ·ì϶£¬½¨ÒéÓû§¾¡¿ì½øÐÐÉý¼¶¡£Ä¿Ç°»¹Ã»ÓйØÓÚÕâЩ·ì϶ÔÚÒ°±í±»ÀûÓõĻ㱨¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/


4¡¢ÎÚ¿ËÀ¼µ±¾Ö»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÚ¿ËÀ¼°²È«¾Ö£¨SBU£©°µÊ¾×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌáÒé¹¥»÷¡£SBUר¼ÒÖ¸³ö£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ£¬ÆäÖ°ÄÜÔ̺¬Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´Ôì¡¢¼à¿ØÓû§ÐÐΪºÍÀ¹½ØÃÜÂëµÈ¡£Æ¾¾ÝSBUºÍÒ»¸ö°²È«³§É̵ĵ÷²é£¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£´Ë±í£¬SBU»¹·¢ÏÖÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÓй¤¾ß¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html


5¡¢¿¨°Í˹»ùÅû¶·¸×ïÍÅ»ïDustSquadµÄй¤¾ßOctopus

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒÅû¶·¸×ïÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄ¼¼Êõϸ½Ú¡£OctopusÖØÒªÕë¶ÔÖÐÑǵØÓòµÄ±í½»²¿ÃÅ£¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü£¬Æä¹¦·ò´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ£¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â£¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖÓÆ¾ÃÐÔ£¬Æä·þÎñÆ÷¶ËÊÇPHPµÄ£¬²¿ÊðÔÚ·ÖÆç¹ú¶È/µØÓòµÄóÒ×ÍйܷþÎñÖС£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/octopus-infested-seas-of-central-asia/88200/


6¡¢³¬¹ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉÏÏúÊÛ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄ×êÑÐÈËÔ±ÔÚ°µÍøÂÛ̳ÉÏ·¢ÏÖÒ»¸öÔ̺¬´óÁ¿Ñ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÔÚÏúÊÛ¡£¸ÃÊý¾Ý¿âÔ̺¬À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£ÕâЩ¼Í¼Ô̺¬ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±º¹ÇàºÍÆäËüͶƱÊý¾ÝµÈ¡£×êÑÐÈËÔ±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾½øÐÐÁËÉó²é£¬È·ÈÏÕâЩÊý¾ÝÓÐЧ²¢ÇÒ¸ÃÊý¾Ý¿âÓµÓи߶ȵĿÉÐŶÈ¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´·ÛËéÑ¡¾Ù»ò½øÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù