¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180820

Ðû²¼Ê±¼ä 2018-08-20

¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯


Ç÷ÊÆ¿Æ¼¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷»î¶¯ £¬£¬£¬£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î £¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£¡£¡£ÔÚ×îа汾µÄWindowsÖÐ £¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript £¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÓïÒôÐÅÏäÐ®ÖÆPayPalºÍWhatsAppÕË»§


Çå¾²Ñо¿Ö°Ô±Martin Vigo³Æ¹¥»÷Õß¿ÉʹÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§ £¬£¬£¬£¬ÈçPayPalºÍWhatsAppµÈ¡£¡£¡£´ó´ó¶¼ÔËÓªÉ̲»µ«Ö§³Öͨ¹ýÊÖʱ»ú¼ûÓïÒôÐÅÏä £¬£¬£¬£¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃÍⲿµç»°ºÅÂë»á¼ûÓïÒôÐÅÏä¡£¡£¡£Ðí¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂë £¬£¬£¬£¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈ¼òÆÓÃÜÂë¡£¡£¡£Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃÓïÒôÐÅÏäÀ´ÖØÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂë £¬£¬£¬£¬²¢×îÖÕÐ®ÖÆÓû§µÄPayPalºÍWhatsAppÕË»§¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora


SalesforceÑо¿Ö°Ô±Vishal Thakur·¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£¡£¡£µ½2018Äê7ÔÂβ £¬£¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÅÌËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖÐ £¬£¬£¬£¬×î³õµÄѬȾǰÑÔÊÇÍøÂç´¹ÂÚÓʼþ £¬£¬£¬£¬Æä°üÀ¨Á½¸öÓÐÓúÉÔØ £¬£¬£¬£¬Ò»¸öÊÇÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤µÄľÂí £¬£¬£¬£¬ÀýÈçÍâµØÕË»§ºÍä¯ÀÀÆ÷µÄƾ֤µÈ¡£¡£¡£ÁíÒ»¸öÓÐÓúÉÔØÊÇÀÕË÷Èí¼þAurora £¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA


Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£¡£¡£ÏÖÔÚ»¹²»ÖªµÀMAFIAÔõÑù½øÈëÓû§µÄϵͳ £¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹ÂڻʵÏÖÕâÒ»²½µÄ¡£¡£¡£MAFIAʹÓÃOpenSSLÀ´¼ÓÃÜÎļþ £¬£¬£¬£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ £¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©Õ¹Ãû¡£¡£¡£ÓÉÓÚÆä¼ÓÃÜÀú³ÌºÜÂý £¬£¬£¬£¬Óû§¿Éͨ¹ýÖÕÖ¹ÆäÀú³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø±ÕÅÌËã»úÀ´×èÖ¹Ëü¡£¡£¡£MAFIAʹÓÃTorÊðÀí¾ÙÐÐC2ͨѶ £¬£¬£¬£¬Æäͨ¹ýHTTP GETÇëÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿»ú¹¹Ðû²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄÆÊÎö±¨¸æ


CyberbitÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²âÊÖÒÕ¡£¡£¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬£¬£¬£¬Æä°üÀ¨ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÅÌËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûƾ֤µÈÄ£¿£¿£¿£¿£¿£¿£¿ £¿é¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷TrickbotµÄбäÖÖ½ÓÄÉÀú³ÌÍڿյĴúÂë×¢ÈëÊÖÒÕ £¬£¬£¬£¬´ó´ó¶¼Çå¾²²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¡£¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸öÇå¾²Îó²î


8ÔÂ19ÈÕProject InsecurityµÄÁ½ÃûÇå¾²Ñо¿Ö°Ô±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ±£´æÒ»¸öÍâµØÎļþй¶Îó²î¡£¡£¡£TRSϵͳÊÇÖ¸µçÐÅÖмÌЧÀÍ £¬£¬£¬£¬ÓÃÓÚ×ÊÖú¶úÁû»òÓïÑÔÕϰ­µÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨Öú×°±¸²¦´òµç»°¡£¡£¡£¼ÓÄôóµÄËùÓÐÖ÷ÒªISP¶¼ÊÜÓ°Ïì £¬£¬£¬£¬°üÀ¨Rogers¡¢TelusºÍBCEµÈ £¬£¬£¬£¬ÕâЩISPµÄЧÀ͹¤¾ßº­¸ÇÁËÁè¼Ý3000Íò¼ÓÄÃÖÁ¹«Ãñ¡£¡£¡£ËùÓеÄÖ÷Òª¼ÓÄôóISP¶¼ÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/