¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180820

°ä²¼¹¦·ò 2018-08-20

¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯


Ç÷Ïò¿Æ¼¼µÄ°²È«×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÔÚÀûÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕ·ì϶£¨CVE-2018-8373£©ÌáÒé¹¥»÷»î¶¯ £¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öuse-after-free·ì϶ £¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÍÆËã»úÉÏÔËÐÐshellcode¡£¡£¡£¡£¡£¡£ÔÚ×îа汾µÄWindowsÖÐ £¬£¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÅäÖÃÖнûÓÃÁËVBScript £¬£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£Î¢ÈíÒÑÔÚ8Ô°²È«¸üÐÂÖн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃÓïÒôÐÅÏä½Ù³ÖPayPalºÍWhatsAppÕË»§


°²È«×êÑÐÈËÔ±Martin Vigo³Æ¹¥»÷Õß¿ÉÀûÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§ £¬£¬£¬£¬£¬ÈçPayPalºÍWhatsAppµÈ¡£¡£¡£¡£¡£¡£´óÎÞÊýÔËÓªÉ̲»½öÖ§³Öͨ¹ýÊÖ»ú½Ó¼ûÓïÒôÐÅÏä £¬£¬£¬£¬£¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃ±í²¿µç»°ºÅÂë½Ó¼ûÓïÒôÐÅÏä¡£¡£¡£¡£¡£¡£ºÜ¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂë £¬£¬£¬£¬£¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈµ¥Ò»ÃÜÂë¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓÃÓïÒôÐÅÏäÀ´³ÁÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂë £¬£¬£¬£¬£¬²¢×îÖÕ½Ù³ÖÓû§µÄPayPalºÍWhatsAppÕË»§¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora


Salesforce×êÑÐÈËÔ±Vishal Thakur·¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£¡£¡£¡£¡£¡£µ½2018Äê7ÔÂµ× £¬£¬£¬£¬£¬×êÑÐÈËÔ±¹Û²ìµ½¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÍÆËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖÐ £¬£¬£¬£¬£¬×î³õµÄϰȾý½éÊÇÍøÂç´¹µöÓʼþ £¬£¬£¬£¬£¬ÆäÔ̺¬Á½¸öÓÐЧºÉÔØ £¬£¬£¬£¬£¬Ò»¸öÊÇÖØÒªÓÃÓÚÇÔÈ¡Óû§Í´´¦µÄľÂí £¬£¬£¬£¬£¬ÀýÈç±¾µØÕË»§ºÍä¯ÀÀÆ÷µÄÍ´´¦µÈ¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÓÐЧºÉÔØÊÇÀÕË÷Èí¼þAurora £¬£¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/


¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA


×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹²»ÖªÂ·MAFIAÈôºÎ½øÈëÓû§µÄϵͳ £¬£¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹µö»î¶¯ÊµÏÖÕâÒ»²½µÄ¡£¡£¡£¡£¡£¡£MAFIAÀûÓÃOpenSSLÀ´¼ÓÃÜÎļþ £¬£¬£¬£¬£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ £¬£¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©´óÃû¡£¡£¡£¡£¡£¡£ÓÉÓÚÆä¼ÓÃܹý³ÌºÜÂý £¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÖÕÖ¹Æä¹ý³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø¹ØÍÆËã»úÀ´×èÖ¹Ëü¡£¡£¡£¡£¡£¡£MAFIAʹÓÃTor´úÀí½øÐÐC2ͨѶ £¬£¬£¬£¬£¬Æäͨ¹ýHTTP GETÒªÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html


¡¾¶ñÒâÈí¼þ¡¿×êÑлú¹¹°ä²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄ·ÖÎö»ã±¨


Cyberbit×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²â¼¼Êõ¡£¡£¡£¡£¡£¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬£¬£¬£¬£¬ÆäÔ̺¬ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÍÆËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûÍ´´¦µÈÄ£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖTrickbotµÄбäÖÖѡȡ¹ý³ÌÍڿյĴúÂë×¢Èë¼¼Êõ £¬£¬£¬£¬£¬´óÎÞÊý°²È«²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¡£¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸ö°²È«·ì϶


8ÔÂ19ÈÕProject InsecurityµÄÁ½Ãû°²È«×êÑÐÈËÔ±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ´æÔÚÒ»¸ö±¾µØÎļþй¶·ì϶¡£¡£¡£¡£¡£¡£TRSϵͳÊÇÖ¸µçÐÅÖм̷þÎñ £¬£¬£¬£¬£¬ÓÃÓÚÔ®ÊÖ¶úÁû»ò˵»°×è°­µÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨ÖúÉ豸²¦´òµç»°¡£¡£¡£¡£¡£¡£¼ÓÄôóµÄËùÓÐÖØÒªISP¶¼ÊÜÓ°Ïì £¬£¬£¬£¬£¬Ô̺¬Rogers¡¢TelusºÍBCEµÈ £¬£¬£¬£¬£¬ÕâЩISPµÄ·þÎñ¶ÔÏóº­¸ÇÁ˳¬¹ý3000Íò¼ÓÄôó¹«Ãñ¡£¡£¡£¡£¡£¡£ËùÓеÄÖØÒª¼ÓÄôóISP¶¼ÒѾ­½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/