¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180820

Ðû²¼Ê±¼ä 2018-08-20

¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯


Ç÷ÊÆ¿Æ¼¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷»î¶¯£¬£¬£¬£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£¡£ÔÚ×îа汾µÄWindowsÖУ¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÓïÒôÐÅÏäÐ®ÖÆPayPalºÍWhatsAppÕË»§


Çå¾²Ñо¿Ö°Ô±Martin Vigo³Æ¹¥»÷Õß¿ÉʹÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§£¬£¬£¬£¬ÈçPayPalºÍWhatsAppµÈ¡£¡£´ó´ó¶¼ÔËÓªÉ̲»µ«Ö§³Öͨ¹ýÊÖʱ»ú¼ûÓïÒôÐÅÏ䣬£¬£¬£¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃÍⲿµç»°ºÅÂë»á¼ûÓïÒôÐÅÏä¡£¡£Ðí¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂ룬£¬£¬£¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈ¼òÆÓÃÜÂë¡£¡£Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃÓïÒôÐÅÏäÀ´ÖØÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂ룬£¬£¬£¬²¢×îÖÕÐ®ÖÆÓû§µÄPayPalºÍWhatsAppÕË»§¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora


SalesforceÑо¿Ö°Ô±Vishal Thakur·¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£¡£µ½2018Äê7ÔÂ⣬£¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÅÌËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬×î³õµÄѬȾǰÑÔÊÇÍøÂç´¹ÂÚÓʼþ£¬£¬£¬£¬Æä°üÀ¨Á½¸öÓÐÓúÉÔØ£¬£¬£¬£¬Ò»¸öÊÇÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤µÄľÂí£¬£¬£¬£¬ÀýÈçÍâµØÕË»§ºÍä¯ÀÀÆ÷µÄƾ֤µÈ¡£¡£ÁíÒ»¸öÓÐÓúÉÔØÊÇÀÕË÷Èí¼þAurora£¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA


Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£¡£ÏÖÔÚ»¹²»ÖªµÀMAFIAÔõÑù½øÈëÓû§µÄϵͳ£¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹ÂڻʵÏÖÕâÒ»²½µÄ¡£¡£MAFIAʹÓÃOpenSSLÀ´¼ÓÃÜÎļþ£¬£¬£¬£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ£¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©Õ¹Ãû¡£¡£ÓÉÓÚÆä¼ÓÃÜÀú³ÌºÜÂý£¬£¬£¬£¬Óû§¿Éͨ¹ýÖÕÖ¹ÆäÀú³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø±ÕÅÌËã»úÀ´×èÖ¹Ëü¡£¡£MAFIAʹÓÃTorÊðÀí¾ÙÐÐC2ͨѶ£¬£¬£¬£¬Æäͨ¹ýHTTP GETÇëÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿»ú¹¹Ðû²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄÆÊÎö±¨¸æ


CyberbitÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²âÊÖÒÕ¡£¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬Æä°üÀ¨ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÅÌËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûƾ֤µÈÄ£¿£¿é¡£¡£Ñо¿Ö°Ô±·¢Ã÷TrickbotµÄбäÖÖ½ÓÄÉÀú³ÌÍڿյĴúÂë×¢ÈëÊÖÒÕ£¬£¬£¬£¬´ó´ó¶¼Çå¾²²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸öÇå¾²Îó²î


8ÔÂ19ÈÕProject InsecurityµÄÁ½ÃûÇå¾²Ñо¿Ö°Ô±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ±£´æÒ»¸öÍâµØÎļþй¶Îó²î¡£¡£TRSϵͳÊÇÖ¸µçÐÅÖмÌЧÀÍ£¬£¬£¬£¬ÓÃÓÚ×ÊÖú¶úÁû»òÓïÑÔÕϰ­µÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨Öú×°±¸²¦´òµç»°¡£¡£¼ÓÄôóµÄËùÓÐÖ÷ÒªISP¶¼ÊÜÓ°Ï죬£¬£¬£¬°üÀ¨Rogers¡¢TelusºÍBCEµÈ£¬£¬£¬£¬ÕâЩISPµÄЧÀ͹¤¾ßº­¸ÇÁËÁè¼Ý3000Íò¼ÓÄÃÖÁ¹«Ãñ¡£¡£ËùÓеÄÖ÷Òª¼ÓÄôóISP¶¼ÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/