¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181207
Ðû²¼Ê±¼ä 2018-12-07
ÃÀ¹úDHSÏÂÊô¹ú¼ÒÍøÂçÇå¾²ºÍͨѶ¼¯³ÉÖÐÐÄ£¨NCCIC£©ÁªºÏFBIÅäºÏÐû²¼ÀÕË÷Èí¼þSamSamжñÒâ»î¶¯µÄ¾¯±¨¡£¡£¡£¡£SamSamÖ÷ÒªÕë¶ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬Ãé×¼¶à¸öÐÐÒµ£¬£¬£¬£¬£¬£¬°üÀ¨Ò»Ð©Òªº¦»ù´¡ÉèÊ©¡£¡£¡£¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔWindowsЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Æ¾Ö¤FBIµÄÆÊÎö£¬£¬£¬£¬£¬£¬×Ô2016ÄêÄêÖÐÒÔÀ´£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýRDPÐÒéÈëÇÖÊܺ¦ÕßµÄÍøÂç¡£¡£¡£¡£Í¨³£ÇéÐÎϹ¥»÷ÕßʹÓñ©Á¦ÆÆ½â¹¥»÷»ò±»µÁƾ֤¾ÙÐÐÈëÇÖ£¬£¬£¬£¬£¬£¬µ«FBIµÄÆÊÎöÅú×¢¹¥»÷Õß»¹´Ó°µÍøÊг¡ÉϹºÖÃÁËһЩ±»µÁµÄRDPƾ֤¡£¡£¡£¡£DHSºÍFBI½¨ÒéÓû§ºÍÖÎÀíÔ±Ìáǰ½ÓÄÉÇå¾²²½·¥À´Ô¤·À¸Ã¹¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/alerts/AA18-337A2¡¢ÃÀIRS³Æ2018ÄêÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿ÔöÌíÁè¼Ý60%
ƾ֤ÃÀ¹ú¹ú˰¾Ö£¨IRS£©µÄ˵·¨£¬£¬£¬£¬£¬£¬ËäÈ»2015Äê¡¢2016ÄêºÍ2017ÄêµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿³ÊϽµÇ÷ÊÆ£¬£¬£¬£¬£¬£¬µ«ÔÚ2018ÄêIRSÊÓ²ìµ½ÍøÂç´¹ÂÚÕ©ÆÊýÄ¿ÔöÌíÁè¼Ý60%£¬£¬£¬£¬£¬£¬´Ó2017ÄêµÄÔ¼1200Æð´ËÀàÊÂÎñÔöÌíµ½2018Äê1ÔÂÖÁ10ÔµÄÁè¼Ý2000Æð¡£¡£¡£¡£IRSÌåÏÖÕ©ÆÕßͨ¹ý¶ÔÄÉ˰È˾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬ÊÔͼÇÔÈ¡ËûÃǵÄ×ʽðºÍ˰ÎñÊý¾Ý¡£¡£¡£¡£×î½üµÄ¶ñÒâ»î¶¯¾ÍʹÓÃÁËÖîÈç¡°IRSÖ÷Ҫ֪ͨ¡±¡¢¡°IRSÄÉ˰ÈË֪ͨ¡±µÈÖ÷Ìâ¾ÙÐÐÕ©Æ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/irs-warns-of-60-percent-surge-in-email-phishing-scams-during-2018-524126.shtml3¡¢³¯ÏÊAPT¹¥»÷»î¶¯STOLEN PENCIL£¬£¬£¬£¬£¬£¬Ö÷ÒªÃé׼ѧÊõ»ú¹¹
ƾ֤NETSCOUTµÄ×îÐÂÑо¿£¬£¬£¬£¬£¬£¬×Ô2018Äê5ÔÂÒÔÀ´Ò»¸öеÄAPT¹¥»÷»î¶¯STOLEN PENCILÖ÷ÒªÕë¶ÔѧÊõ»ú¹¹¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯¿ÉÄÜÀ´×ÔÓÚ³¯ÏÊ£¬£¬£¬£¬£¬£¬Æä³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬²¢ÓÕʹÓû§×°ÖöñÒâµÄChrome²å¼þ¡£¡£¡£¡£Ðí¶à²î±ð´óѧµÄÊܺ¦Õß¶¼ÊÇÉúÎ﹤³ÌרҵµÄ£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÅú×¢Îú¹¥»÷ÕßµÄÄîÍ·¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÄÚÖõÄWindowsÖÎÀí¹¤¾ßºÍÏֳɵÄÉÌÒµÈí¼þÀ´ÌӱܹéÒò£¬£¬£¬£¬£¬£¬²¢ÇÒʹÓÃRDPÀ´»á¼ûÊÜѬȾµÄϵͳ£¬£¬£¬£¬£¬£¬¶ø²»ÊǺóÃźÍRAT¡£¡£¡£¡£Ã»ÓÐÖ¤¾ÝÅú×¢ÓÐÊý¾Ý±»ÇÔ£¬£¬£¬£¬£¬£¬Ê¹µÃSTOLEN PENCILµÄÄîÍ·»¹²»Ê®Ã÷È·È·¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/4¡¢½©Ê¬ÍøÂçѬȾÁè¼Ý2Íò¸öWordPressÍøÕ¾£¬£¬£¬£¬£¬£¬C2ЧÀÍÆ÷ÓëHostSailorÓйØ
ƾ֤DefiantµÄÐÂÑо¿±¨¸æ£¬£¬£¬£¬£¬£¬Ò»¸öÓÉÁè¼Ý2Íò¸öWordPressÍøÕ¾×é³ÉµÄ½©Ê¬ÍøÂçÕý±»ÓÃÓÚ¹¥»÷ºÍѬȾÆäËüµÄWordPressÍøÕ¾¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç»á¶ÔÆäËüWordPressÍøÕ¾¾ÙÐб©Á¦ÆÆ½â¹¥»÷£¬£¬£¬£¬£¬£¬Ö±µ½·¢Ã÷ÓÐÓõÄÓû§ÕË»§¡£¡£¡£¡£ÕâÖÖ±¬ÆÆ¹¥»÷Õë¶ÔWordPressµÄXML-RPCʵÏÖ£¬£¬£¬£¬£¬£¬ÓÉÓÚXML-RPCĬÈϲ»»á¶ÔAPIÇëÇóµÄËÙÂʾÙÐÐÏÞÖÆ£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔÒ»Ö±¾ÙÐÐʵÑé¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçʹÓÃÁË4¸öC2ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÕâЩC2ͨ¹ý¶íÂÞ˹Best-Proxies.ruµÄÊðÀíЧÀÍÆ÷·¢³öÖ¸Áî¡£¡£¡£¡£¹¥»÷ÕßÒ»¹²Ê¹ÓÃÁË1.4Íò¶à¸öÊðÀíЧÀÍÆ÷À´ÒþÄäC2ЧÀÍÆ÷µÄλÖ㬣¬£¬£¬£¬£¬ÆäÖÐÈý¸öC2ЧÀÍÆ÷ÓëHostSailor¹«Ë¾Óйء£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.wordfence.com/blog/2018/12/wordpress-botnet-attacking-wordpress/5¡¢ÎÚ¿ËÀ¼SBUÖ¸Ôð¶íÂÞ˹Ç鱨»ú¹¹¹¥»÷¸Ã¹ú˾·¨ÏµÍ³
ÎÚ¿ËÀ¼SBUÐû³Æ×èÖ¹Á˶íÂÞ˹Ç鱨»ú¹¹ÌᳫµÄÕë¶Ô¸Ã¹ú˾·¨²¿·ÖITϵͳµÄÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷·Ö·¢¶ñÒâµÄ»á¼ÆÎĵµ£¬£¬£¬£¬£¬£¬ÕâЩÎĵµÖаüÀ¨ÓÃÓÚÇÔÈ¡Êý¾ÝºÍÆÆËð˾·¨ÏµÍ³µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£ÎÚ¿ËÀ¼Ç徲ר¼Ò·¢Ã÷¸Ã¹¥»÷»î¶¯ÖеÄC&C»ù´¡ÉèʩʹÓÃÁ˶íÂÞ˹µÄIPµØµã¡£¡£¡£¡£ÎÚ¿ËÀ¼SSIPºÍ¹ú¼Ò˾·¨ÐÐÕþ²¿·ÖÅɺÏ×èÖ¹Á˸ù¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78726/cyber-warfare-2/sbu-russia-cyber-attack.html6¡¢ESET·¢Ã÷21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬£¬¾ùΪOpenSSHºóÃÅľÂí
ÔÚÒ»·Ý³¤´ï53Ò³µÄ±¨¸æÖУ¬£¬£¬£¬£¬£¬ESETÏêϸÏÈÈÝÁË21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâÈí¼þ¶¼ÊÇOpenSSH¿Í»§¶ËµÄľÂí»¯°æ±¾¡£¡£¡£¡£ÆäÖÐһЩ¶ñÒâÈí¼þºÜÊǼòÆÓ£¬£¬£¬£¬£¬£¬µ«Ò²ÓÐһЩºÜÊÇÖØ´ó£¬£¬£¬£¬£¬£¬¿ÉÄÜÀ´×ÔÓÚÓÐÂÄÀúµÄ¶ñÒâÈí¼þ¿ª·¢Ö°Ô±¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ¶¼Êǵڶþ½×¶Î¹¤¾ß£¬£¬£¬£¬£¬£¬¿ÉÒÔ°²ÅÅÔÚ¸üÖØ´óµÄ½©Ê¬ÍøÂç»î¶¯ÖУ¬£¬£¬£¬£¬£¬ÓÃÀ´Ìæ»»Õý³£µÄOpenSSH°æ±¾¡£¡£¡£¡£ESETÌåÏÖÆäÖÐ18¸ö¼Ò×å¶¼¾ßÓÐÆ¾Ö¤ÇÔÈ¡¹¦Ð§£¬£¬£¬£¬£¬£¬²¢ÇÒ17¸ö¼Ò×å¾ßÓкóÃÅģʽ£¬£¬£¬£¬£¬£¬¿ÉÔÊÐíÒþÄäµÄ¶ñÒâÅþÁ¬¡£¡£¡£¡£±¨¸æÖаüÀ¨ÁËÕâЩ¶ñÒâÈí¼þµÄIoCÖ¸±ê¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdfÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ