¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181030

°ä²¼¹¦·ò 2018-10-30
1¡¢AvastÅû¶Õë¶ÔÓ¢ÐÛͬÃËÍæ¼ÒµÄÍøÂç´¹µö»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Avast×êÑÐÍŶÓÔÚ2018ÄêÏļ¾Ä©¹Û²ìµ½Õë¶ÔÓ¢ÐÛͬÃËÍæ¼ÒµÄÒ»¸öÐÂÍøÂç´¹µö»î¶¯¡£¹¥»÷ÕßÖØÒªÕë¶ÔÎ÷Å·µØÓò£¬´óÎÞÊý¹¥»÷²úÉúÔÚ·¨¹ú£¬Æä´ÎÊǵ¹úºÍÎ÷°àÑÀ¡£¸Ã´¹µöÍøÕ¾ÍйÜÔÚÃâ·ÑµÄÍйܷþÎñÉÌ000webhostÉÏ£¬ÒÔ½Ú¼ó¿ªÖ§£¬²¢ÇÒ´¹µöÍøÕ¾Í¨³£²»»áÕ¼ÓÃÌ«¶à´ÅÅ̿ռäºÍ²úÉú½Ï¶àµÄÁ÷Á¿£¬Òò¶ø¹¥»÷ÕßÍùÍù»áÑ¡ÔñʹÓÃÃâ·ÑµÄÍйܷþÎñ¡£¸Ã´¹µöÒ³ÃæÔì×÷µÃ¼«¶È¾«²Ê£¬Í¼ÏñÖÊÁ¿Ò²Ã»ÓнµµÍ£¬²¢ÔÚÓû§µã»÷µÇ¼ʱ½«Í´´¦·¢ËÍÖÁ¹¥»÷Õß¡£

   

Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/league-of-legends-gamers-targeted-by-phishing-scam-avast


2¡¢×êÑÐÈËÔ±·¢ÏÖEmotetÀûÓÃDKIMÈÆ¹ýÓʼþ¹ýÂË´ëÊ©

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018Äê7ÔÂUS-CERTÔø°ä²¼¹ØÓÚÒøÐÐľÂíEmotetµÄ¾¯±¨£¬²¢Ìá³öÁËÏàÓ¦µÄ·À»¤´ëÊ©½¨Ò飬ÆäÖÐÒ»ÏÒéÊÇʹÓûùÓÚÓòµÄÐÂÎÅÈÏÖ¤¡¢»ã±¨ºÍÒ»ÖÂÐÔ£¨DMARC£©£¬¸Ã»úÔìÄܹ»Åжϵç×ÓÓʼþÊÇ·ñÀ´×ÔÕæÊµµÄµØÖ·¡£È»¶ø²»ÐÒµÄÊÇ£¬¹¥»÷ÕßËÆºõÒ²ÔĶÁÁËUS-CERTµÄ¾¯±¨£¬Emotetͨ¹ýÒ»ÖÖÓò½Ù³Ö¼¼ÊõÀ´ÈƹýDMARC½ÚÔì»úÔì¡£ÔÚTrickbot¨CEmotet¶ñÒâ»î¶¯ÖУ¬ÕâÊÇͨ¹ýд´½¨µÄ×ÓÓò_domainkeyʵÏֵġ£
  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malware-distributors-adopt-dkim-to-bypass-mail-filters/


3¡¢ÃÀ¼ÓÖÝÔ¼2800ÃûŮͯ¾üµÄÓ×ÎÒÐÅÏ¢Ôâй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÄϼÓÖݵİÂÀ¼ÖÎÏØÅ®Í¯¾ü×éÖ¯£¨GSOC£©Ôâµ½ºÚ¿Í¹¥»÷£¬¸Ã×éÖ¯µÄµç×ÓÓʼþÕË»§Ôâµ½µÚÈý·½Î´ÊÚȨ½Ó¼û£¬Ô¼2800ÃûŮͯ¾ü³ÉÔ±µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜй¶¡£±»µÁµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢±£ÏÕºÅÂëºÍÒ½ÁÆÐÅÏ¢¡£ÕâЩÐÅÏ¢¿ÉÄܻᱻÓÃÓÚºóÐøµÄÉç½»¹¤³Ì¹¥»÷ºÍÉí·Ý͵ÇԵȡ£¸ÃÕË»§ÔÚ9ÔÂ30ÈÕÖÁ10ÔÂ1ÈÕÖ»±»½Ù³ÖÁË1Ìì¡£

  

Ô­ÎÄÁ´½Ó£º

https://abc30.com/4561129/


4¡¢Æ±Îñ¹«Ë¾PaylogicÔâºÚ¿ÍÈëÇÖ£¬Ô¼6.4ÍòÓû§µÄÓ×ÎÒÐÅÏ¢±»µÁ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƱÎñ¹«Ë¾PaylogicÐû³ÆÆäƱÎñϵͳÔâºÚ¿ÍÈëÇÖ£¬²ÎÓëTomorrowland 2014ÒôÀÖ½ÚµÄÔ¼6.4ÍòÃûµç×ÓÎèÇú·ÛË¿µÄÓ×ÎÒÐÅÏ¢±»µÁ¡£TomorrowlandÊÇÔÚ±ÈÀûʱÓ×ÕòBoom½øÐеĵç×ÓÒôÀÖ½Ú£¬ÊÇÊÀ½çÉÏ×î´óµÄÒôÀÖ½ÚÖ®Ò»¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÐԱ𡢴ºÇïºÍÓÊÕþ±àÂëµÈ£¬µ«²»Ô̺¬Ö§¸¶ÐÅÏ¢¡¢ÃÜÂëºÍÓû§µØÖ·¡£PaylogicÔÚÉêÃ÷Öв¢Ã»ÓÐй©¹¥»÷µÄ¾ßÌåϸ½Ú¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/crooks-stole-data-of-64-000-tomorrowland-festival-goers-523493.shtml


5¡¢¼ÓÃÜÇ®±ÒÂòÂôËùMapleChangeÔâºÚ¿Í¹¥»÷£¬Ëðʧ913¸ö±ÈÌØ±Ò

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÃÜÇ®±ÒÂòÂôËùMapleChange³ÆÆäÔâµ½ºÚ¿Í¹¥»÷£¬¹²Ëðʧ913¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼600ÍòÃÀÔª£©¡£¸Ãƽ̨¾Ý³ÆÊǼÓÄôóµÄÒ»¸öÓ×ÐÍÂòÂôËù¡£MapleChangeÔÚTwitterÉϳƾ­¹ý¾ßÌåµÄµ÷²é£¬¸ÃÂòÂôËùÎÞÁ¦¶ÔÓû§½øÐÐÅ⸶£¬½«²»µÃ²»¹Ø¹Ø£¬Ô̺¬¹Ø¹ØÆäTwitterÕË»§ºÍÍøÕ¾¡£ÕâÒ»ÊÂÎñѸ¿ìÒý·¢Á˶àÈËÒÉ»ó£¬ÒÔΪ¸ÃÓ×ÐÍÂòÂôËù¿ÉÄÜÖ»ÊÇÒ»¸öȦÌ×£¬¸ÃÊÂÎñ¿ÉÄÜ»áÒý·¢ºóÐøµÄÐÌʵ÷²é¡£

  

Ô­ÎÄÁ´½Ó£º

https://ethereumworldnews.com/maplechange-crypto-exchange-hacked-for-913-bitcoin-btc-exit-scam-likely/


6¡¢×êÑÐÍŶӰ䲼¹ØÓÚÀ¬»øÓʼþµÄ¸½¼þÎļþÀàÐ͵ķÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼×êÑÐÍŶӰ䲼¹ØÓÚÀ¬»øÓʼþµÄ¸½¼þÎļþÀàÐ͵ķÖÎö»ã±¨£¬2017Äê×î³£¼ûµÄ¶ñÒ⸽¼þµÄÎļþÀàÐÍÊÇ.XLS¡¢.PDF¡¢.JS¡¢.VBS¡¢.DOCX¡¢.DOC¡¢.WSF¡¢.XLSX¡¢.EXEºÍ.HTML£¬µ«ÍøÂç·¸×ï·Ö×ÓÒѾ­À©´óÁËËûÃǵÄÁìÓò£¬ÐµĶñÒ⸽¼þÎļþÀàÐÍÔ̺¬.ARJ¡¢.Z¡¢.IQY¡¢.PUBÒÔ¼°Windows 10ÖеÄÐÂÎļþÀàÐÍSettingContents-ms¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/same-old-yet-brand-new-new-file-types-emerge-in-malware-spam-attachments/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù