¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190131

°ä²¼¹¦·ò 2019-01-31
1¡¢Êý¾ÝÖÎÀí¹«Ë¾RubrikÒâ±íй¶´óÁ¿¿Í»§Êý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Oliver Hough·¢ÏÖÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearch·þÎñÆ÷δÊÜÃÜÂë±£»¤£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬Ô̺¬ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍ¹¤×÷°¸Àý ¡£Æ¾¾Ý¹¦·ò´Á£¬ÕâЩÊý¾Ý¿É×·ÒäÖÁ2018Äê10Ô ¡£¾­¹ýµ÷²é£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓɱ¨´ðÃýÎóµ¼ÖµÄ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/01/29/rubrik-data-leak/


2¡¢Å·ÖÞ·¨ÂÉ»ú¹¹ÔÚµ÷²éʹÓùýwebstresser.orgµÄÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Å·ÖÞ·¨ÂÉ»ú¹¹ÔÚ½áºÏÈ«ÇòµÄ·¨ÂÉ»ú¹¹¶ÔʹÓùýDDoS×âÓ÷þÎñwebstresser.orgµÄÓû§½øÐе÷²é ¡£ÔÚ2018Äê4Ô¹عØwebstresser.org·þÎñʱ£¬Å·ÖÞÐ̾¯×éÖ¯»ñµÃÁ˳¬¹ý15.1ÍòÃû×¢²áÓû§µÄÐÅÏ¢ ¡£Æ¾¾ÝÕâЩÐÅÏ¢£¬È«Çò·¨ÂÉ»ú¹¹½«¶ÔʹÓø÷þÎñÌáÒéDDoS¹¥»÷µÄÓû§½øÐе÷²éºÍ¸æ×´ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/80435/cyber-crime/europol-ddos-for-hire.html


3¡¢ÒÁÀÊAPT39жñÒâ»î¶¯£¬ÖØÒªÕë¶ÔÖж«µçÐÅÐÐÒµ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FireEye°ä²¼¹ØÓÚÒÁÀÊAPT39жñÒâ»î¶¯µÄ·ÖÎö»ã±¨ ¡£ÓëÆäËüÒÁÀÊAPT×éÖ¯·ÖÆçµÄÊÇ£¬APT39¸ü²à³ÁÓÚÇÔÈ¡Ó×ÎÒÐÅÏ¢£¬ÒÔ±ãΪÒÁÀÊµÄ¼à¿Ø¡¢¸ú×ٺͼල»î¶¯Ìṩ֧³Ö ¡£¹ÌÈ»APT39µÄÖ¸±ê±é²¼È«Çò£¬µ«Æä»î¶¯ÖØÒª¼¯ÖÐÔÚÖж«µØÓò£¬²¢ÇÒÓÅÏÈÕë¶ÔµçÐÅÐÐÒµ£¬´Ë±í£¬Ò²¶Ô×¼ÓÎÀÀÒµºÍIT¹«Ë¾ ¡£APT39ÖØÒªÊ¹ÓÃSEAWEEDºÍCACHEMONEYºóÃÅÒÔ¼°POWBATºóÃÅ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html


4¡¢Altran Technologies¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·¨¹ú¹¤³ÌÕ÷ѯ¹«Ë¾Altran TechnologiesÔâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷£¬ÆäÔÚһЩŷÖÞ¹ú¶ÈµÄÔËÓª»î¶¯Êܵ½Ó°Ïì ¡£ÎªÁ˱£»¤¿Í»§µÄÊý¾ÝºÍ×ʲú£¬Altranһʱ¹Ø¹ØÁËÍøÂçºÍÀûÓ÷¨Ê½ ¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ1ÔÂ24ÈÕ£¬µ«¸Ã¹«Ë¾²¢Ã»ÓÐÅû¶ÓйØÏ¸½Ú£¬²¢³ÆÊÂÎñ»¹ÔÚµ÷²éÖ®ÖÐ ¡£Æ¾¾ÝÉÏ´«µ½VirusTotalµÄ¶ñÒâÑù±¾£¬LockerGoga»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lockedÀ©´óÃû ¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/altran-technologies-hit-by-lockergoga-ransomware-attack-e1f90570


5¡¢ÀÕË÷Èí¼þJobCrypterбäÖÖ£¬¿É½ØÈ¡ÆÁÄ»ÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þJobCrypterµÄÒ»¸öбäÖÖ£¬¸Ã±äÖÖÓµÓжî±íµÄ¼ÓÃܲãºÍ¸ü³¤µÄÃÜÔ¿£¬»¹Äܹ»Í¨¹ýSMTP½«Ö¸±êÉ豸µÄÆÁÄ»½ØÍ¼·¢ËÍÖÁÖ¸¶¨µÄµç×ÓÓÊÏä ¡£¸Ã±äÖÖ»áÏȽ«Îļþ½øÐÐBase64±àÂ룬¶øºóʹÓÃTriple DESËã·¨½øÐмÓÃÜ£¬×îºóÔÙ½øÐÐÒ»´ÎBase64±àÂ룬ÃÜÔ¿ÓÉ67λÊý×Ö×é³É ¡£¸Ã±äÖÖÒªÇóÊÜϰȾµÄÓû§ÔÚ24Ó×ʱÄÚÖ§¸¶1000Å·ÔªµÄÊê½ð ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.scmagazineuk.com/new-jobcrypter-ransomware-variant-captures-screenshots-infected-devices/article/1524199


6¡¢Î÷ÃÅ×Ó½¨¸´S7-1500 PLCÖеÄÁ½¸öDoS·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Î÷ÃÅ×Ó½¨¸´Simatic S7-1500¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©ÖеÄÁ½¸ö¿Éµ¼ÖÂDoSµÄ°²È«·ì϶ ¡£ÕâÁ½¸ö·ì϶£¨CVE-2018-16558ºÍCVE-2018-16559£©ÊÇÓÉPositive TechnologiesµÄ×êÑÐÈËÔ±·¢Ïֵ쬯äCVSS v3.0µÃ·Ö¾ùΪ7.5 ¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòTCP¶Ë¿Ú80»ò443·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢·ì϶ ¡£Î÷ÃÅ×ÓÔÚSimatic S7-1500¹Ì¼þ°æ±¾2.5Öн¨¸´ÁËÕâЩ·ì϶ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://cert-portal.siemens.com/productcert/pdf/ssa-180635.pdf


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù