¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180820

Ðû²¼Ê±¼ä 2018-08-20

¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷Ô˶¯


Ç÷ÊÆ¿Æ¼¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷Ô˶¯£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£ÔÚ×îа汾µÄWindowsÖУ¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÓïÒôÐÅÏäÐ®ÖÆPayPalºÍWhatsAppÕË»§


Çå¾²Ñо¿Ö°Ô±Martin Vigo³Æ¹¥»÷Õß¿ÉʹÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§£¬ÈçPayPalºÍWhatsAppµÈ¡£´ó´ó¶¼ÔËÓªÉ̲»µ«Ö§³Öͨ¹ýÊÖʱ»ú¼ûÓïÒôÐÅÏ䣬»¹Ö§³Öͨ¹ýPINÂëʹÓÃÍⲿµç»°ºÅÂë»á¼ûÓïÒôÐÅÏä¡£Ðí¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂ룬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈ¼òÆÓÃÜÂë¡£Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃÓïÒôÐÅÏäÀ´ÖØÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂ룬²¢×îÖÕÐ®ÖÆÓû§µÄPayPalºÍWhatsAppÕË»§¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora


SalesforceÑо¿Ö°Ô±Vishal Thakur·¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£µ½2018Äê7ÔÂ⣬Ñо¿Ö°Ô±ÊӲ쵽¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÅÌËã»úµÄ¶ñÒâ¹¥»÷Ô˶¯ÖУ¬×î³õµÄѬȾǰÑÔÊÇÍøÂç´¹ÂÚÓʼþ£¬Æä°üÀ¨Á½¸öÓÐÓúÉÔØ£¬Ò»¸öÊÇÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤µÄľÂí£¬ÀýÈçÍâµØÕË»§ºÍä¯ÀÀÆ÷µÄƾ֤µÈ¡£ÁíÒ»¸öÓÐÓúÉÔØÊÇÀÕË÷Èí¼þAurora£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA


Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£ÏÖÔÚ»¹²»ÖªµÀMAFIAÔõÑù½øÈëÓû§µÄϵͳ£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹ÂÚÔ˶¯ÊµÏÖÕâÒ»²½µÄ¡£MAFIAʹÓÃOpenSSLÀ´¼ÓÃÜÎļþ£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©Õ¹Ãû¡£ÓÉÓÚÆä¼ÓÃÜÀú³ÌºÜÂý£¬Óû§¿Éͨ¹ýÖÕÖ¹ÆäÀú³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø±ÕÅÌËã»úÀ´×èÖ¹Ëü¡£MAFIAʹÓÃTorÊðÀí¾ÙÐÐC2ͨѶ£¬Æäͨ¹ýHTTP GETÇëÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿»ú¹¹Ðû²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄÆÊÎö±¨¸æ


CyberbitÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²âÊÖÒÕ¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Æä°üÀ¨ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÅÌËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûƾ֤µÈÄ£¿é¡£Ñо¿Ö°Ô±·¢Ã÷TrickbotµÄбäÖÖ½ÓÄÉÀú³ÌÍڿյĴúÂë×¢ÈëÊÖÒÕ£¬´ó´ó¶¼Çå¾²²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸öÇå¾²Îó²î


8ÔÂ19ÈÕProject InsecurityµÄÁ½ÃûÇå¾²Ñо¿Ö°Ô±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ±£´æÒ»¸öÍâµØÎļþй¶Îó²î¡£TRSϵͳÊÇÖ¸µçÐÅÖм̷þÎñ£¬ÓÃÓÚ×ÊÖú¶úÁû»òÓïÑÔÕϰ­µÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨Öú×°±¸²¦´òµç»°¡£¼ÓÄôóµÄËùÓÐÖ÷ÒªISP¶¼ÊÜÓ°Ï죬°üÀ¨Rogers¡¢TelusºÍBCEµÈ£¬ÕâЩISPµÄ·þÎñ¹¤¾ßº­¸ÇÁËÁè¼Ý3000Íò¼ÓÄÃÖÁ¹«Ãñ¡£ËùÓеÄÖ÷Òª¼ÓÄôóISP¶¼ÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/