¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181022
°ä²¼¹¦·ò 2018-10-23
ÉÏÖÜÎåÃÀ¹úÒ½ÁƱ£ÏÕºÍÒ½ÁƲ¹Öú·þÎñÖÐÐÄ£¨CMS£©°ä²¼ÐÂÎųƣ¬ÓëHealthCare.govÓйصÄÒ»¸öµ±¾ÖÍÆËã»úϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬Ô¼7.5ÍòÃûÓû§µÄÃô¸ÐÓ×ÎÒÐÅÏ¢±»ÇÔ¡£CMS°µÊ¾ÔÚ10ÔÂ16ÈÕÈ·ÈÏÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬²¢½ûÓÃÁËÓëÒì³£»î¶¯ÓйصÄÓû§ÕË»§¡£CMSºÍFBIÔÚ´òËã֪ͨËùÓÐÊÜÓ°ÏìµÄÓû§£¬²¢ÌṩÐÅÓþ±£»¤µÈ×ÊÔ´¡£
2£¬°²È«³§ÉÌÅû¶Õë¶Ô¹·¹·±ÒµÄÔÚÏßڲƺ£³±
°²È«³§ÉÌDoctor WebµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶Ô¹·¹·±ÒµÄÔÚÏßڿƻ¡£¹¥»÷Õß±»³ÆÎªInvestimer£¨±ðÃûHyipblock»òMmpower£©£¬ËûÃÇʹÓðµÍøÊг¡Éϵĸ÷ÀàÖ÷Á÷óÒ׾ÂíÀ´ÇÔÈ¡Óû§µÄ¼ÓÃÜÇ®±Ò£¬Ô̺¬Eredel¡¢AZORult¡¢Kpot¡¢Kratos¡¢N0F1L3¡¢ACRUX¡¢Predator The Thief¡¢ArkeiºÍPonyµÈ¡£Investimerͨ¹ý¸÷Àà´¹µöÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ£¬×¨¼Ò¹À¼ÆÊÜÓ°ÏìµÄÓû§³¬¹ý1ÍòÈË£¬×ÜËðʧ³¬¹ý2.3ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£ºhttps://news.drweb.com/show/?c=5&i=12886&lng=en
3£¬×êÑÐÈËÔ±Åû¶Õë¶ÔWindowsϵͳµÄÐÂRID½Ù³Ö¹¥»÷
CSL°²È«×êÑÐÈËÔ±Sebasti¨¢nCastro·¢ÏÖÒ»ÖÖÕë¶ÔWindowsÓû§ÕÊ»§²ÎÊýRIDµÄ½Ù³Ö¹¥»÷¡£RIDÓÃÓÚÃèÊöÓû§µÄȨÏÞ×飬Ô̺¬³ß¶ÈÀ´±öÕÊ»§501ºÍÖÎÀíÔ¹ØÊ»§500µÈ¡£¹¥»÷Õßͨ¹ýÅú¸ÄWindowsÕÊ»§ÐÅÏ¢µÄ×¢²á±íÏΪָ¶¨ÕË»§ÊÚÓè·ÖÆçµÄRID£¬½ø¶ø»ñµÃϵͳµÄÆëÈ«½Ó¼ûȨÏÞ¡£×êÑÐÈËÔ±¿ª·¢ÁËÒ»¸ö¿É×Ô¶¯»¯Ö´Ðд˹¥»÷µÄMetasploitÄ£¿érid_hijack¡£
ÔÎÄÁ´½Ó£ºhttp://csl.com.co/rid-hijacking/
4£¬ÃÀWest HavenÊÐÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶2000ÃÀÔªÊê½ð
ÃÀ¹ú¿µÄùµÒ¸ñÖݵÄWest HavenÊÐÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ±¾ÖÒÑÏò¹¥»÷ÕßÖ§¸¶ÁË2000ÃÀÔªµÄÊê½ðÒÔ½âËø23̨·þÎñÆ÷²¢¸´Ô¶Ô³ÇÊÐÓйØÏµÍ³Êý¾ÝµÄ½Ó¼û¡£¸Ã±ÊÊê½ðÊÇͨ¹ý±ÈÌØ±ÒÖ§¸¶µÄ¡£Õâ´Î¹¥»÷²úÉúÔÚÉÏÖܶþÉÏÎ磬ÊÐÕþ¹ÙԱͨ¹ý×êÑÐÒÔΪ֧¸¶Êê½ðÊÇ×îºÃµÄ½â¾ö¹æ»®¡£ºÓɽ°²È«ÊýÒÔΪ¸Ã¹¥»÷À´×ÔÓÚ¾³±í£¬Ä¿Ç°»¹ÔÚ³ÖÐø½øÐе÷²é¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/city-pays-2000-computer-ransomware-attack
5£¬×êÑÐÍŶÓÅû¶¶à¿îNASÉ豸ÖеĶà¸ö°²È«·ì϶
WizCase°²È«×êÑÐÈËÔ±ÔÚ¶à¿îNASÉ豸Öз¢ÏÖ¶à¸ö°²È«·ì϶£¬ÊÜÓ°ÏìµÄÆ·ÅÆÔ̺¬Î÷Êý¡¢Íø¼þ¡¢Ï£½ÝºÍMedionµÈ¡£ÕâЩÉ豸¶¼´æÔÚÒ»¸öÁãÈÕ·ì϶£¬¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁĿǰÓйطì϶£¨CVE-2018-18472ºÍCVE-2018-18471£©»¹Î´µÃµ½½¨¸´£¬ÊÜÓ°ÏìµÄÔÚÏßÉ豸µÄÊýÁ¿´ï½ü200Íǫ̀¡£×êÑÐÈËÔ±ÒÔΪÆäËüNASÉ豸ºÜÓпÉÄÜÒ²´æÔÚÀàËÆµÄ·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.wizcase.com/blog/hack-2018/
6£¬×êÑÐÈËÔ±·¢´Ë¿Ì¼ÓÃÜʱÏνӵ½BleepingComputerÍøÕ¾µÄÐÂÀÕË÷Èí¼þ
×êÑÐÈËÔ±nao_secºÍKafeine·¢ÏÖÀÕË÷Èí¼þKraken Cryptor v2.0.6»áÔÚ¼ÓÃܵķ֯ç½×¶ÎÏνӵ½BleepingComputerÍøÕ¾²¢·¢ËÍÓйØÊý¾Ý¡£¸Ã°æ±¾ÊÇÉÏÖÜÄ©°ä²¼µÄ£¬ÖØÒªÍ¨¹ý¶ñÒâ¸æ°×ºÍ·ì϶ÀûÓù¤¾ß°üRIG½øÐзַ¢¡£×Ô2018Äê10ÔÂ20ÈÕÒÔÀ´£¬¸Ã°æ±¾ÒÑÔÚÈ«ÊÀ½çÁìÓòÄÚϰȾÁË217ÃûÓû§¡£Ä¿Ç°»¹²»Ã÷ÏÔ¶ñÒâÈí¼þ¿ª·¢ÕßÕâÑù×öµÄÖ÷ÕÅ£¬µ«×êÑÐÈËÔ±ÒÔΪÕâ¿ÉÄÜÊǶñÒâµÄÍæÐ¦¡£
https://www.bleepingcomputer.com/news/security/kraken-cryptor-ransomware-connecting-to-bleepingcomputer-during-encryption/
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ