¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181207
°ä²¼¹¦·ò 2018-12-07
ÃÀ¹úDHSÏÂÊô¹ú¶ÈÍøÂ簲ȫºÍͨѶ¼¯³ÉÖÐÐÄ£¨NCCIC£©½áºÏFBI¹²Í¬°ä²¼ÀÕË÷Èí¼þSamSamжñÒâ»î¶¯µÄ¾¯±¨¡£SamSamÖØÒªÕë¶ÔÃÀ¹ú£¬¶Ô×¼¶à¸öÐÐÒµ£¬Ô̺¬Ò»Ð©¹Ø¼ü»ù´¡ÉèÊ©¡£¹¥»÷ÕßÖØÒªÕë¶ÔWindows·þÎñÆ÷£¬Æ¾¾ÝFBIµÄ·ÖÎö£¬×Ô2016ÄêÄêÖÐÒÔÀ´£¬¹¥»÷Õßͨ¹ýRDPºÍ̸ÈëÇÖÊܺ¦ÕßµÄÍøÂ硣ͨ³£Çé¿öϹ¥»÷ÕßʹÓñ©Á¦ÆÆ½â¹¥»÷»ò±»µÁÍ´´¦½øÐÐÈëÇÖ£¬µ«FBIµÄ·ÖÎöÅú×¢¹¥»÷Õß»¹´Ó°µÍøÊг¡ÉϲɰìÁËһЩ±»µÁµÄRDPÍ´´¦¡£DHSºÍFBI½¨ÒéÓû§ºÍÖÎÀíÔ±Ìáǰ²ÉÈ¡°²È«´ëÊ©À´Ô¤·À¸Ã¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/alerts/AA18-337A2¡¢ÃÀIRS³Æ2018ÄêÍøÂç´¹µö¹¥»÷ÊýÁ¿Ôö³¤³¬¹ý60%
ƾ¾ÝÃÀ¹ú¹ú˰¾Ö£¨IRS£©µÄ˵·¨£¬¹ÌÈ»2015Äê¡¢2016ÄêºÍ2017ÄêµÄÍøÂç´¹µö¹¥»÷ÊýÁ¿³Ê½µÂäÇ÷Ïò£¬µ«ÔÚ2018ÄêIRS¹Û²ìµ½ÍøÂç´¹µöÚ¿ÆÊýÁ¿Ôö³¤³¬¹ý60%£¬´Ó2017ÄêµÄÔ¼1200Æð´ËÀàÊÂÎñÔö³¤µ½2018Äê1ÔÂÖÁ10Ôµij¬¹ý2000Æð¡£IRS°µÊ¾Ú¿ÆÕßͨ¹ý¶ÔÄÉ˰È˽øÐÐÍøÂç´¹µö¹¥»÷£¬ÊÔͼÇÔÈ¡ËûÃǵÄ×ʽðºÍ˰ÎñÊý¾Ý¡£×î½üµÄ¶ñÒâ»î¶¯¾ÍʹÓÃÁËÖîÈç¡°IRS³ÁҪ֪ͨ¡±¡¢¡°IRSÄÉ˰ÈË֪ͨ¡±µÈÖ÷Ìâ½øÐÐÚ¿Æ¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/irs-warns-of-60-percent-surge-in-email-phishing-scams-during-2018-524126.shtml3¡¢³¯ÏÊAPT¹¥»÷»î¶¯STOLEN PENCIL£¬ÖØÒª¶Ô׼ѧÊõ»ú¹¹
ƾ¾ÝNETSCOUTµÄ×îÐÂ×êÑУ¬×Ô2018Äê5ÔÂÒÔÀ´Ò»¸öеÄAPT¹¥»÷»î¶¯STOLEN PENCILÖØÒªÕë¶ÔѧÊõ»ú¹¹¡£¸Ã¹¥»÷»î¶¯¿ÉÄÜÀ´×ÔÓÚ³¯ÏÊ£¬Æä³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹µöÓʼþ£¬²¢ÓÕʹÓû§×°ÖöñÒâµÄChrome²å¼þ¡£ºÜ¶à·ÖÆç´óѧµÄÊܺ¦Õß¶¼ÊÇÉúÎ﹤³ÌרҵµÄ£¬Õâ¿ÉÄܽ²ÁËÈ»¹¥»÷Õߵ͝»ú¡£¹¥»÷ÕßʹÓÃÄÚÖõÄWindowsÖÎÀí¹¤¾ßºÍÏֳɵÄóÒ×Èí¼þÀ´ÌӱܹéÒò£¬²¢ÇÒʹÓÃRDPÀ´½Ó¼ûÊÜϰȾµÄϵͳ£¬¶ø²»ÊǺóÃźÍRAT¡£Ã»ÓÐÖ¤¾ÝÅú×¢º±¼û¾Ý±»ÇÔ£¬Ê¹µÃSTOLEN PENCILµÄ¶¯»ú»¹²»¼«¶ÈÃ÷È·¡£
ÔÎÄÁ´½Ó£º
https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/4¡¢½©Ê¬ÍøÂçϰȾ³¬¹ý2Íò¸öWordPressÍøÕ¾£¬C2·þÎñÆ÷ÓëHostSailorÓйØ
ƾ¾ÝDefiantµÄÐÂ×êÑл㱨£¬Ò»¸öÓɳ¬¹ý2Íò¸öWordPressÍøÕ¾×é³ÉµÄ½©Ê¬ÍøÂçÕý±»ÓÃÓÚ¹¥»÷ºÍϰȾÆäËüµÄWordPressÍøÕ¾¡£¸Ã½©Ê¬ÍøÂç»á¶ÔÆäËüWordPressÍøÕ¾½øÐб©Á¦ÆÆ½â¹¥»÷£¬Ö±µ½·¢ÏÖÓÐЧµÄÓû§ÕË»§¡£ÕâÖÖ±¬ÆÆ¹¥»÷Õë¶ÔWordPressµÄXML-RPCʵÏÖ£¬ÓÉÓÚXML-RPCĬÈϲ»»á¶ÔAPIÒªÇóµÄ¿ìÂʽøÐÐÏÞ¶È£¬Òò¶ø¹¥»÷ÕßÄܹ»Ò»Ïò½øÐг¢ÊÔ¡£¸Ã½©Ê¬ÍøÂçʹÓÃÁË4¸öC2·þÎñÆ÷£¬ÕâЩC2ͨ¹ý¶íÂÞ˹Best-Proxies.ruµÄ´úÀí·þÎñÆ÷·¢³öÖ¸Áî¡£¹¥»÷ÕßÒ»¹²Ê¹ÓÃÁË1.4Íò¶à¸ö´úÀí·þÎñÆ÷À´ÒþÄäC2·þÎñÆ÷µÄµØÎ»£¬ÆäÖÐÈý¸öC2·þÎñÆ÷ÓëHostSailor¹«Ë¾Óйء£
ÔÎÄÁ´½Ó£º
https://www.wordfence.com/blog/2018/12/wordpress-botnet-attacking-wordpress/5¡¢ÎÚ¿ËÀ¼SBUÔð¹Ö¶íÂÞ˹µý±¨»ú¹¹¹¥»÷¸Ã¹ú˾·¨ÏµÍ³
ÎÚ¿ËÀ¼SBUÐû³Æ×èÖ¹Á˶íÂÞ˹µý±¨»ú¹¹ÌáÒéµÄÕë¶Ô¸Ã¹ú˾·¨²¿ÃÅITϵͳµÄÍøÂç¹¥»÷»î¶¯¡£¹¥»÷Õßͨ¹ýÓã²æÊ½ÍøÂç´¹µö¹¥»÷·Ö·¢¶ñÒâµÄ¹ÜÕÊÎĵµ£¬ÕâЩÎĵµÖÐÔ̺¬ÓÃÓÚÇÔÈ¡Êý¾ÝºÍ·ÛËé˾·¨ÏµÍ³µÄ¶ñÒâÈí¼þ¡£ÎÚ¿ËÀ¼°²È«×¨¼Ò·¢Ïָù¥»÷»î¶¯ÖеÄC&C»ù´¡ÉèʩʹÓÃÁ˶íÂÞ˹µÄIPµØÖ·¡£ÎÚ¿ËÀ¼SSIPºÍ¹ú¶È˾·¨ÐÐÕþ²¿ÃŹ²Í¬×èÖ¹Á˸ù¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78726/cyber-warfare-2/sbu-russia-cyber-attack.html6¡¢ESET·¢ÏÖ21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬¾ùΪOpenSSHºóÃÅľÂí
ÔÚÒ»·Ý³¤´ï53Ò³µÄ»ã±¨ÖУ¬ESET¾ßÌå½éÉÜÁË21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬ÕâЩ¶ñÒâÈí¼þ¶¼ÊÇOpenSSH¿Í»§¶ËµÄľÂí»¯°æ±¾¡£ÆäÖÐһЩ¶ñÒâÈí¼þ¼«¶Èµ¥Ò»£¬µ«Ò²ÓÐһЩ¼«¶È¸´ÔÓ£¬¿ÉÄÜÀ´×ÔÓÚÓоÑéµÄ¶ñÒâÈí¼þ¿ª·¢ÈËÔ±¡£ÕâЩ¶ñÒâÈí¼þ¶¼Êǵڶþ½×¶Î¹¤¾ß£¬Äܹ»²¿ÊðÔÚ¸ü¸´ÔӵĽ©Ê¬ÍøÂç»î¶¯ÖУ¬ÓÃÀ´´úÌæÕý³£µÄOpenSSH°æ±¾¡£ESET°µÊ¾ÆäÖÐ18¸ö¼Ò×å¶¼ÓµÓÐÍ´´¦ÇÔȡְÄÜ£¬²¢ÇÒ17¸ö¼Ò×åÓµÓкóÃÅģʽ£¬¿ÉÔÊÐíÒþÄäµÄ¶ñÒâÏνӡ£»ã±¨ÖÐÔ̺¬ÁËÕâЩ¶ñÒâÈí¼þµÄIoCÖ¸±ê¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdfÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ