¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181019
Ðû²¼Ê±¼ä 2018-10-22
McAfeeÑо¿Ö°Ô±Åû¶Õë¶Ôº«¹ú¡¢ÃÀ¹úºÍ¼ÓÄôóµÄй¥»÷»î¶¯Operation Oceansalt¡£¡£Ñо¿Ö°Ô±ÊӲ쵽Õë¶Ô²î±ðÄ¿µÄµÄ5²¨¹¥»÷À˳±£¬£¬£¬¹¥»÷ÕßʹÓõĴúÂëÓë8ÄêǰµÄºÚ¿ÍÍÅ»ïAPT1ºÜÊÇÏàËÆ£¬£¬£¬µ«Õâ²¢²»ÁÏζ×ÅAPT1ÒѾ¾íÍÁÖØÀ´£¬£¬£¬Ò²ÓпÉÄÜÊÇ·¸·¨ÍÅ»ïÖ®¼ä¹²ÏíÁ˲¿·Ö´úÂë»òÔʼ´úÂ뱻й¶»òÇÔÈ¡£¡£¬£¬£¬»òÕßÊǹ¥»÷Õß¾ÓÐÄÉèÖõÄÓÃÓÚÎóµ¼Ñо¿Ö°Ô±µÄFalse Flag¡£¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/mcafee-labs/operation-oceansalt-delivers-wave-after-wave/2£¬£¬£¬Çå¾²³§ÉÌÅû¶Õë¶ÔÒâ´óÀûˮʦ¹¤ÒµµÄÐÂÍøÂçÌØ¹¤»î¶¯MartyMcFly
Çå¾²³§ÉÌYoroiÅû¶Õë¶ÔÒâ´óÀûˮʦ¹¤ÒµµÄÐÂÍøÂçÌØ¹¤»î¶¯MartyMcFly¡£¡£¹¥»÷Õßͨ¹ý´¹ÂÚÓʼþ·Ö·¢¶ñÒâµÄxlsÎļþ£¬£¬£¬Æä×îÖÕÓÐÓúÉÔØÊÇ´ÓÒ»¸öÍÁ¶úÆäÍøÕ¾ÏÂÔØ»ñµÃ¡£¡£¸ÃÍøÕ¾ÊôÓÚÒ»¼ÒÕýµ±µÄ»úеÅä¼þÏúÊÛ¹«Ë¾£¬£¬£¬µ«ºÜ¿ÉÄÜÒÑÔâµ½ÈëÇÖ¡£¡£Ñо¿Ö°Ô±ÒÔΪÕâ¿ÉÄÜÊÇÒ»¸öÕë¶Ôˮʦ¹¤ÒµµÄÐÂÐËÍþв£¬£¬£¬ÏÖÔÚ»¹Ã»Óв½·¥¶ÔÆä¾ÙÐйéÒò¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77195/malware/martymcfly-malware-cyber-espionage.html3£¬£¬£¬GandCrab¿ª·¢ÕßΪÐðÀûÑÇÊܺ¦ÕßÐû²¼½âÃÜÃÜÔ¿
ÔÚÒ»¸öÐðÀûÑÇÊܺ¦ÕßÌåÏÖËûÒѹʺ¢×ÓµÄÕÕÆ¬±»GandCrab¼ÓÃܲ¢ÔÚtwitterÉÏ×·Çó×ÊÖúÖ®ºó£¬£¬£¬GandCrab¿ª·¢ÕßÐû²¼ÁËËùÓÐÐðÀûÑÇÊܺ¦ÕߵĽâÃÜÃÜÔ¿¡£¡£ÆäÅû¶µÄSY_keys.txtÎļþ°üÀ¨978¸öÐðÀûÑÇÊܺ¦ÕߵĽâÃÜÃÜÔ¿£¬£¬£¬°æ±¾°üÀ¨1.0.0rµ½5.0¡£¡£GandCrab¿ª·¢Õß»¹ÌåÏÖ£¬£¬£¬ÐðÀûÑDz»ÔÚGandCrabµÄ°×Ãûµ¥ÁбíÖÐÊÇÒ»¸ö¹ýʧ£¬£¬£¬µ«Ã»ÓÐ˵Ã÷ÊÇ·ñ»áÔÚδÀ´½«Æä¼ÓÈë°×Ãûµ¥¡£¡£¹ØÓÚÆäËü¹ú¼ÒµÄÊܺ¦Õߣ¬£¬£¬¿ª·¢ÕßÌåÏÖÓÀÔ¶²»»áÐû²¼½âÃÜÃÜÔ¿¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/gandcrab-devs-release-decryption-keys-for-syrian-victims/4£¬£¬£¬Ñо¿ÍŶÓÅû¶APT×éÖ¯TickÕë¶Ô¶«ÑǵÄй¥»÷»î¶¯
˼¿ÆTalosÍŶÓÅû¶APT×éÖ¯Tick½üÆÚÕë¶Ô¶«ÑǵØÇøµÄй¥»÷»î¶¯¡£¡£¹¥»÷ÕßʹÓõÄжñÒâÈí¼þÊÇDatper£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÔÚÊܺ¦ÕßµÄÅÌËã»úÉÏÖ´ÐÐshellÏÂÁîºÍ»ñÈ¡Ö÷»ú/Ó²ÅÌÐÅÏ¢¡£¡£DatperµÄC2ЧÀÍÆ÷ÊÇλÓÚº«¹úºÍÈÕ±¾µÄÍøÕ¾¡£¡£Ñо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þ¼Ò×åDatper¡¢ºóÃÅxxmmºÍEmdiviʹÓÃÁËÏàͬµÄ»ù´¡ÉèÊ©£¬£¬£¬ÕâÈý¸ö¶ñÒâÈí¼þ¶¼ÊôÓÚAPT×éÖ¯Tick¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2018/10/tracking-tick-through-recent-campaigns.html5£¬£¬£¬TumblrÐÞ¸´¹ÙÍøÖеĿɵ¼ÖÂÓû§ÐÅϢй¶µÄÎó²î
TumblrÐÞ¸´Ò»¸ö¿Éµ¼ÖÂÓû§Ãô¸ÐÐÅϢй¶µÄÇå¾²Îó²î¡£¡£¸ÃÎó²î±£´æÓÚTumblr×ÀÃæ°æµÄ²©¿ÍÍÆ¼ö¹¦Ð§ÖУ¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÇÔÈ¡Óû§µÄµç×ÓÓʼþµØµã¡¢¼ÓÑεĹþÏ£ÃÜÂ롢λÖá¢ÀúÊ·µç×ÓÓʼþµØµã¡¢×îºóµÇ¼IPÒÔ¼°ÕË»§¹ØÁªµÄ²©¿ÍÃû³ÆµÈÐÅÏ¢¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶Îó²îµÄÏà¹ØÊÖÒÕϸ½Ú£¬£¬£¬Ò²Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄÓû§ÊýÄ¿¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/tumblr-account-hacking.html6£¬£¬£¬D-Link·ÓÉÆ÷±»ÆØ±£´æ3¸öÇå¾²Îó²î£¬£¬£¬¿Éµ¼ÖÂ×°±¸½ÓÊÜ
²¨À¼Î÷ÀïÎ÷ÑÇÀí¹¤´óѧµÄÑо¿Ö°Ô±B?a?ejAdamczyk·¢Ã÷¶à¸öÐͺŵÄD-Link·ÓÉÆ÷Ò×ÊÜÈý¸öÇå¾²Îó²îµÄÓ°Ïì¡£¡£ÕâЩÎó²î°üÀ¨Â·¾¶±éÀúÎó²î£¨CVE-2018-10822£©¡¢ÃÜÂëÃ÷ÎÄ´æ´¢Îó²î£¨CVE-2018-10824£©ºÍshellÏÂÁî×¢ÈëÎó²î£¨CVE-2018-10823£©£¬£¬£¬×ÛºÏʹÓÃÕâЩÎó²î¿Éµ¼Ö´úÂëÖ´ÐкÍ×°±¸½ÓÊÜ¡£¡£Ñо¿Ö°Ô±Åû¶ÁËÏà¹ØPoC´úÂë¡£¡£¹²ÓÐ8¸öÐͺŵÄD-Link·ÓÉÆ÷Êܵ½Ó°Ï죬£¬£¬µ«¹©Ó¦ÉÌÌåÏÖÖ»ÔÚÁ½¸öÐͺÅÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬ÆäËüÐͺÅÒÑ×èÖ¹Ö§³Ö¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bug-trio-affecting-eight-d-link-models-leads-to-full-compromise/ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ