¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180704
Ðû²¼Ê±¼ä 2018-07-04¡¾Îó²î²¹¶¡¡¿Î¢ÈíÑо¿Ö°Ô±Åû¶AdobeºÍWindowsÄÚºËÖеÄÁ½¸ö0dayÎó²î
΢ÈíÑо¿Ö°Ô±Åû¶2¸ö0dayÎó²îµÄÏà¹ØÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£3ÔÂÏÂÑ®ESETÑо¿Ö°Ô±ÔÚVirusTotalÉÏ·¢Ã÷Ò»¸ö¶ñÒâPDFÎļþ£¬£¬£¬²¢½«¸ÃÎļþÓë΢ÈíµÄÇå¾²ÍŶӹ²Ïí¡£¡£¡£¡£¡£¡£Î¢ÈíÍŶӷ¢Ã÷¸ÃÎļþ°üÀ¨2¸ö0dayÎó²î£¬£¬£¬Ò»¸öÊÇAdobe AcrobatºÍReaderÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-4990£©£¬£¬£¬ÁíÒ»¸öÊÇWindowsÖеÄÌáȨÎó²î£¨CVE-2018-8120£©¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²î¶¼ÒÑÔÚ5Ô·ݵÄÇå¾²¸üÐÂÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cloudblogs.microsoft.com/microsoftsecure/2018/07/02/taking-apart-a-double-zero-day-sample-discovered-in-joint-hunt-with-eset/
¡¾ÍþвÇ鱨¡¿Çå¾²³§ÉÌ·¢Ã÷ÒÁÀÊAPT×éÖ¯Charming KittenµÄй¥»÷»î¶¯
ÒÔÉ«ÁÐÍøÂçÇå¾²¹«Ë¾ClearSky Security·¢Ã÷ÒÁÀÊAPT×éÖ¯Charming Kitten¸´ÖÆÁËÆä¹Ù·½ÍøÕ¾£¬£¬£¬²¢ÍйÜÔÚclearskysecurity.netÓòÃûÉÏ£¨¹ÙÍøÓòÃûÊÇClearSkySec.com£©¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾°üÀ¨¶à¸öµÇ¼ѡÏ£¬£¬ÓÃÓÚÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬»ñÈ¡Óû§µÄƾ֤¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸ÃÍøÕ¾ËÆºõ»¹ÔÚ½¨ÉèÖУ¬£¬£¬ÓÉÓÚÆä²¿·ÖÍøÒ³ÈÔÈ»°üÀ¨¹ýʧÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/iranian-apt-poses-as-israeli-cyber-security-firm-that-exposed-its-operations/
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆWin 10ÖеÄÐÂÎļþÀàÐͿɱ»¶ñÒâÈí¼þÀÄÓÃ
SpecterOpsÇå¾²Ñо¿Ô±Matt Nelson·¢Ã÷Windows 10ÖеÄÐÂÎļþÀàÐͿɱ»ÀÄÓÃÓÚÔÚÓû§ÅÌËã»úÉÏÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎļþÀàÐÍÊÇ.SettingContent-ms£¬£¬£¬ÊÇ2015ÄêWin 10ÖÐÒýÈëµÄÐÂÎļþÃûÌ㬣¬£¬ÓÃÓÚ½¨ÉèÉèÖÃÒ³ÃæµÄ¿ì½Ý·½·¨¡£¡£¡£¡£¡£¡£ÕâÖÖÎļþ×ÅʵÊǰüÀ¨±êÇ©µÄXMLÎļþ£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¿ÉÓÃÈκοÉÖ´ÐÐÎļþµÄÁ´½ÓÌæ»»¸Ã±êÇ©£¬£¬£¬´Ó¶øÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£ÕâÖÖÖ´ÐжñÒâ´úÂëµÄ·½·¨»¹¿ÉÒÔÈÆ¹ýWindows DefenderµÄ·À»¤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.sentinelone.com/blog/new-windows-10-file-type-can-abused-running-malicious-applications/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚSmoke LoaderµÄбäÌåµÄÆÊÎö±¨¸æ
˼¿ÆTalosÑо¿ÍŶÓÐû²¼¹ØÓÚ¶ñÒâÈí¼þSmoke LoaderµÄбäÌåµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸ÃбäÌåµÄ³õʼѬȾÏòÁ¿ÊǰüÀ¨¶ñÒâWordÎļþµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£Smoke LoaderÖ÷ÒªÓÃÓÚÏÂÔØºÍÖ´ÐÐÆäËü¶ñÒâÈí¼þ£¬£¬£¬°üÀ¨ÀÕË÷Èí¼þºÍ¶ñÒâÍÚ¿óÈí¼þµÈ¡£¡£¡£¡£¡£¡£¸Ã±äÌåûÓн»¸¶ÌØÁíÍâ¿ÉÖ´ÐÐÎļþ£¬£¬£¬ÕâÅú×¢Ëü¿ÉÄܲ»Ïñ֮ǰÄÇôÊܽӴý£¬£¬£¬»òÕß½öÓÃÓÚ˽ÈËÄ¿µÄ¡£¡£¡£¡£¡£¡£Smoke LoaderµÄ²å¼þ¿ÉÒÔÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬°üÀ¨ÖÖÖֵǼƾ֤µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/smoking-guns-smoke-loader-learned-new.html
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô²¨À¼µÄÐÂÀÕË÷Èí¼þNozelesn
MalwareHunterTeam·¢Ã÷Ö÷ÒªÕë¶Ô²¨À¼µÄÐÂÀÕË÷Èí¼þNozelesnµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×îÏÈÓÚ7ÔÂ1ÈÕ£¬£¬£¬¿ÉÄÜÊÇͨ¹ýÀ¬»øÓʼþ¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£Nozelesn»á¼ÓÃÜÓû§µÄÎļþ²¢ÔÚØÊºó¸½¼Ó.nozelesnÀ©Õ¹Ãû£¬£¬£¬ÏÖÔÚÆäÊê½ðΪ0.10±ÈÌØ±Ò£¨Ô¼660ÃÀÔª£©£¬£¬£¬µ«²¢²»½¨ÒéÓû§Ö§¸¶ÈκÎÊê½ð¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/nozelesn-ransomware-reportedly-using-spam-to-target-poland/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷еÄÀÕË÷Èí¼þ±äÌåGandCrab V4
Ñо¿Ö°Ô±Fly·¢Ã÷ͨ¹ýÐéÎ±ÆÆ½âÍøÕ¾·Ö·¢µÄGandCrab v4±äÌå¡£¡£¡£¡£¡£¡£¸Ã±äÌå¸Ä±äΪʹÓÃSalsa20¼ÓÃÜËã·¨£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.KRABÀ©Õ¹Ãû¡£¡£¡£¡£¡£¡£¸Ã±äÌåÒªÇóÓû§»á¼ûÖÆ¶©µÄTorÍøÕ¾£¨gandcrabmfe6mnef.onion£©ÒÔ»ñÈ¡½âÃÜÃÜÔ¿£¬£¬£¬ÆäÊê½ðΪԼ1200ÃÀÔª£¬£¬£¬ÒªÇóʹÓôïÊÀ±Ò£¨DSH£©Ö§¸¶¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆÏÖÔÚ»¹ÎÞ·¨Ã⺬»ìÃܸñäÌå¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/gandcrab-v4-released-with-the-new-krab-extension-for-encrypted-files/


¾©¹«Íø°²±¸11010802024551ºÅ