¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181012

°ä²¼¹¦·ò 2018-10-12
1¡¢¿¨°Í˹»ù°ä²¼¹ØÓÚWindows 0day(CVE-2018-8453)µÄ¸ü¶à¼¼Êõϸ½Ú

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

¿¨°Í˹»ù³¢ÊÔÊÒÓÚ2018Äê8ÔÂ17ÈÕÏò΢Èí»ã±¨ÁËWindows 0day£¨CVE-2018-8453£©£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚ΢ÈíµÄ10Ô°²È«¸üÐÂÖеõ½½¨¸´¡£¡£¡£¡£¡£¡£¸Ã·ìÏ¶ÖØÒª±»APT×éÖ¯FruityArmorËùʹÓ㬣¬£¬£¬£¬£¬ÓÃÀ´¹¥»÷Öж«µØÓòµÄÖ¸±ê¡£¡£¡£¡£¡£¡£Æä¹¥»÷»î¶¯ÊǸ߶ÈÕë¶ÔÐԵ쬣¬£¬£¬£¬£¬Êܺ¦ÕßµÄÊýÁ¿²»³¬¹ý12¸ö¡£¡£¡£¡£¡£¡£×êÑÐÍŶÓÄæÏòÁ˲¶»ñµ½µÄ·ì϶ÀûÓÃÑù±¾£¬£¬£¬£¬£¬£¬²¢½«Æä³ÁдΪÆëÈ«µÄPoC¡£¡£¡£¡£¡£¡£


   Ô­ÎÄÁ´½Ó£º
https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/


2¡¢×êÑÐÍŶӷ¢ÏÖNotPetyaºÍIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ESET×êÑÐÍŶӷ¢ÏÖ¶ñÒâÈí¼þNotPetyaºÍºóÃÅIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö¶ñÒâÈí¼þ¶¼±»ÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µÄÖ¸±ê¡£¡£¡£¡£¡£¡£×êÑÐÍŶÓͨ¹ý¶ÈÎöTeleBotsʹÓõÄкóÃÅWin32/ExaramelÈ·ÈÏÁËÕâЩÁªÏµ£¬£¬£¬£¬£¬£¬ÔÚÕâ֮ǰ×êÑÐÍŶÓÖ»Äܲ²âËüÃǵĹØÁª¡£¡£¡£¡£¡£¡£ÐµÄÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬£¬ExaramelºÍIndustroyerÖ®¼äÓµÓкÜÇ¿µÄ´úÂëÀàËÆÐÔºÍÐÐΪ£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃÇÀ´×ÔÓÚͳһ¿ª·¢Õß¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-backdoor-ties-notpetya-and-industroyer-to-telebots-group/


3¡¢×êÑÐÍŶÓ×ܽá´ÓǰËÄÄêÄÚº­ºÉÀ¼»îÔ¾µÄAPT×éÖ¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚºÉÀ¼µÄ»îÔ¾APT×éÖ¯µÄ×ÛÊö£¬£¬£¬£¬£¬£¬¸Ã×ÛÊöͨ¹ý×ܽá´ÓǰËÄÄêÄÚ£¨2014Äê9ÔÂÖÁ2018Äê9Ô£©ºÉÀ¼µÄ¸ß¼¶ÍøÂçÍþв»î¶¯£¬£¬£¬£¬£¬£¬¸ÅÊöÁ˺ÉÀ¼µÄAPT×éÖ¯¼°Æä»îÔ¾¹¦·ò¡¢ÖØÒªÕë¶ÔµÄÖ¸±êµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩAPT×éÖ¯Ô̺¬BlackOasis¡¢Sofacy¡¢Hades¡¢Buhtrap¡¢The Lamberts¡¢Turla¡¢Gatak¡¢Putter PandaºÍAnimal Farm¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://securelist.com/threats-in-the-netherlands/88185/


4¡¢McAfee°ä²¼¹ØÓÚÀÕË÷Èí¼þGandCrab v5.0.2µÄ·ÖÎö»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

McAfee Labs°ä²¼¹ØÓÚÀÕË÷Èí¼þGandCrab v5µÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬±¾Ô³õGandCrabÒѾ­¸üÐÂÖÁ°æ±¾5.0.2¡£¡£¡£¡£¡£¡£´Ó°æ±¾4ÆðÍ·£¬£¬£¬£¬£¬£¬GandCrabÆðͷͨ¹ýFallout EK½øÐзַ¢£»£»£»£»£»£»£»£»ÔÚ°æ±¾5ÖУ¬£¬£¬£¬£¬£¬GandCrabÓÖÓë¶ñÒâÈí¼þ¼ÓÃÜ·þÎñNTCrypt½øÐкÏ×÷¡£¡£¡£¡£¡£¡£NTCrypt¿ÉÒÔΪ¶ñÒâÈí¼þÌṩ»ìºÏÒÔÌӱܼì²â¡£¡£¡£¡£¡£¡£ÕâÖÖÓëÆäËü¶ñÒâÈí¼þ½øÐнáÃ˵ÄÐÐΪʹµÃÆä¹¥»÷»î¶¯µÄÔËÓªÔ½·¢·½±ã£¬£¬£¬£¬£¬£¬²¢ÇÒ¿¿µÃסµÄÁªÃËÄܹ»Ô¤·À²»ÊÜÐÅÀµµÄ¹©¸øÉ̺ͷÖÏúÉÌ£¬£¬£¬£¬£¬£¬´Ó¶ø×î´óÏ޶ȵؽµµÍ·çÏÕ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securingtomorrow.mcafee.com/mcafee-labs/rapidly-evolving-ransomware-gandcrab-version-5-partners-with-crypter-service-for-obfuscation/


5¡¢TalosÍŶӷ¢ÏÖÖØÒªÕë¶ÔAndroidµÄÐÂľÂíGPlayed

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

˼¿ÆTalos·¢ÏÖÖØÒªÕë¶ÔAndroidƽ̨µÄÐÂÌØÂåÒÁľÂíGPlayed¡£¡£¡£¡£¡£¡£GPlayedÓµÓкܶàÄÚÖÃÖ°ÄÜ£¬£¬£¬£¬£¬£¬²¢ÇÒ¼«¶È½Ã½Ý£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ô¶³Ì¼ÓÔØ²å¼þ¡¢×¢Èë¾ç±¾ÉõÖÁ±àÒëеÄ.NET´úÂë¡£¡£¡£¡£¡£¡£×êÑÐÍŶӷ¢ÏֵĶñÒâÑù±¾Ê¹ÓÃÁËÀàËÆÓÚGoogle AppsµÄͼ±ê£¬£¬£¬£¬£¬£¬¼Ù×°³ÉGoogle Play MarketplaceÒÔºýŪÓû§¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÔÚXamarin»·¾³ÏÂÓÃ.NET±àдµÄ£¬£¬£¬£¬£¬£¬ÆäÖ÷DLLÊÇReznov.DLL£¬£¬£¬£¬£¬£¬¸ÃDLLÖÐÔ̺¬Ä¾ÂíµÄÖ÷Ìâ¸ùÀàeClient¡£¡£¡£¡£¡£¡£¸ÃÑù±¾ÖØÒªÕë¶Ô¶íÓïÓû§£¬£¬£¬£¬£¬£¬·ÖÎöÅú×¢¸ÃľÂí»¹´¦ÓÚ²âÊԽ׶Ρ£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/10/gplayedtrojan.html


6¡¢ÄÏ·ÇÍйܷþÎñÉÌHetznerÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ÄÏ·ÇÍøÂçÍйܷþÎñÉÌHetznerÔÚ´Óǰ12¸öÔÂÄÚµÚ¶þ´ÎÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£¡£ÈëÇÖ²úÉúÔÚ10ÔÂ5ÈÕÐÇÆÚÎ壬£¬£¬£¬£¬£¬¹¥»÷ÕßÉè·¨½Ó¼ûÁ˲¿ÃÅÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µØÖ·¡¢Éí·ÝºÅÂë¡¢Ôöֵ˰ºÅÂëÒÔ¼°ÒøÐÐÕ˺ŵÈ£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÈκÎÖ§¸¶ÐÅÏ¢ºÍÃÜÂëÐÅϢй¶¡£¡£¡£¡£¡£¡£ÉÏÒ»´ÎºÚ¿ÍÈëÇÖ²úÉúÔÚ2017Äê11Ô£¬£¬£¬£¬£¬£¬Ô¼4ÍòÃûÓû§µÄÐÅÏ¢±»ÇÔ£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ã»ÓÐй©µÚ¶þ´Î¹¥»÷µÄÓ°ÏìÁìÓò¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-breach-web-hosting-provider-for-the-second-time-in-the-past-year/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù