¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181016

Ðû²¼Ê±¼ä 2018-10-16
1¡¢Malwarebytes LabsÐû²¼2018 Q3ÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Malwarebytes LabsÐû²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ £¬£¬£¬£¬£¬£¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó £¬£¬£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμÓËÙÁËËûÃǵĶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÍþвÇ÷ÊÆ°üÀ¨¶ñÒâÍÚ¿óÈí¼þºÍÎó²îʹÓù¤¾ß°ü±äµÃ³ÉÊì £¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÎȲ½ÔöÌí £¬£¬£¬£¬£¬£¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯×îÏÈËÕÐѵȡ£¡£¡£¡£¡£¡£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔöÌíÁË55% £¬£¬£¬£¬£¬£¬Ïà±ÈÖ®ÏÂÕë¶ÔÏûºÄÕßµÄÍþв½öÔöÌí4% £¬£¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÕýÔÚ×·Çó¸ü´óµÄÀûÒæ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/


2¡¢Branch.ioЧÀͱ»ÆØ±£´æXSSÎó²î £¬£¬£¬£¬£¬£¬6.85ÒÚÓû§ÒÉÃæÁÙΣº¦

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

vpnMentorµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Branch.ioЧÀͱ£´æXSSÎó²î £¬£¬£¬£¬£¬£¬Ðí¶àʹÓøÃЧÀ͵ĴóÐÍÍøÕ¾¶¼Êܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬°üÀ¨Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ £¬£¬£¬£¬£¬£¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î»á¼ûÓû§µÄÉèÖÃÎļþºÍÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÒÑÐÞ¸´ £¬£¬£¬£¬£¬£¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§¼ì²é×Ô¼ºµÄÕË»§²¢ÇÒÐÞ¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/


3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´ÐеÄÎó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓëÆÊÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ßΣº¦Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£© £¬£¬£¬£¬£¬£¬¸øÕþ¸®»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´Î£º¦¡£¡£¡£¡£¡£¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11ÖÐÐÞ¸´ÁËÕâЩÎó²î £¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»ÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/


4¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÎÚ¿ËÀ¼Çå¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£SBUר¼ÒÖ¸³ö £¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ £¬£¬£¬£¬£¬£¬Æä¹¦Ð§°üÀ¨Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍ×èµ²ÃÜÂëµÈ¡£¡£¡£¡£¡£¡£Æ¾Ö¤SBUºÍÒ»¸öÇå¾²³§É̵ÄÊÓ²ì £¬£¬£¬£¬£¬£¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬SBU»¹·¢Ã÷ÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÍ̹¤¾ß¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html


5¡¢¿¨°Í˹»ùÅû¶·¸·¨ÍÅ»ïDustSquadµÄй¤¾ßOctopus

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¿¨°Í˹»ùʵÑéÊÒÅû¶·¸·¨ÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£OctopusÖ÷ÒªÕë¶ÔÖÐÑǵØÇøµÄÍâ½»²¿·Ö £¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü £¬£¬£¬£¬£¬£¬Æäʱ¼ä´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ £¬£¬£¬£¬£¬£¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â £¬£¬£¬£¬£¬£¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£¡£¡£¡£¡£¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖ³¤ÆÚÐÔ £¬£¬£¬£¬£¬£¬ÆäЧÀÍÆ÷¶ËÊÇPHPµÄ £¬£¬£¬£¬£¬£¬°²ÅÅÔÚ²î±ð¹ú¼Ò/µØÇøµÄÉÌÒµÍйÜЧÀÍÖС£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/octopus-infested-seas-of-central-asia/88200/


6¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿Ö°Ô±ÔÚ°µÍøÂÛ̳ÉÏ·¢Ã÷Ò»¸ö°üÀ¨´ó×ÚÑ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾¾ÙÐÐÁËÉó²é £¬£¬£¬£¬£¬£¬È·ÈÏÕâЩÊý¾ÝÓÐÓò¢ÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶȡ£¡£¡£¡£¡£¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´ £¬£¬£¬£¬£¬£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆËðÑ¡¾Ù»ò¾ÙÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí