¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181016

°ä²¼¹¦·ò 2018-10-16
1¡¢Malwarebytes Labs°ä²¼2018 Q3ÍøÂç·¸×ïÕ½ÊõÓë¼¼Êõµ÷²é»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Malwarebytes Labs°ä²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸×ïÕ½ÊõÓë¼¼Êõµ÷²é»ã±¨ £¬£¬£¬£¬£¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó £¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμӿìÁËËûÃǵĶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÍþвÇ÷ÏòÔ̺¬¶ñÒâÍÚ¿óÈí¼þºÍ·ì϶ÀûÓù¤¾ß°ü±äµÃ³ÉÊì £¬£¬£¬£¬£¬ÀÕË÷Èí¼þÎȲ½Ôö³¤ £¬£¬£¬£¬£¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯ÆðÍ·¸´Ëյȡ£¡£¡£¡£¡£¡£¡£¡£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔö³¤ÁË55% £¬£¬£¬£¬£¬Ïà±ÈÖ®ÏÂÕë¶ÔÏû·ÑÕßµÄÍþв½öÔö³¤4% £¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÔÚ×·Çó¸ü´óµÄÀûÒæ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/


2¡¢Branch.io·þÎñ±»ÆØ´æÔÚXSS·ì϶ £¬£¬£¬£¬£¬6.85ÒÚÓû§ÒÉÃæ¶Ô·çÏÕ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

vpnMentorµÄ°²È«×êÑÐÈËÔ±·¢ÏÖBranch.io·þÎñ´æÔÚXSS·ì϶ £¬£¬£¬£¬£¬ºÜ¶àʹÓø÷þÎñµÄ´óÐÍÍøÕ¾¶¼Êܵ½Ó°Ïì £¬£¬£¬£¬£¬Ô̺¬Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ £¬£¬£¬£¬£¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶½Ó¼ûÓû§µÄÅäÖÃÎļþºÍ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»¸Ã·ì϶Òѽ¨¸´ £¬£¬£¬£¬£¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§²é³­×Ô¼ºµÄÕË»§²¢ÇÒÅú¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/


3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´Ðеķì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓë·ÖÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ß·çÏÕ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ִÐÐËÁÒâ´úÂë»òµ¼Ö»ؾø·þÎñ£¨DoS£© £¬£¬£¬£¬£¬¸øµ±¾Ö»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11Öн¨¸´ÁËÕâЩ·ì϶ £¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐÐÉý¼¶¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹Ã»ÓйØÓÚÕâЩ·ì϶ÔÚÒ°±í±»ÀûÓõĻ㱨¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/


4¡¢ÎÚ¿ËÀ¼µ±¾Ö»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÎÚ¿ËÀ¼°²È«¾Ö£¨SBU£©°µÊ¾×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£SBUר¼ÒÖ¸³ö £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ £¬£¬£¬£¬£¬ÆäÖ°ÄÜÔ̺¬Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´Ôì¡¢¼à¿ØÓû§ÐÐΪºÍÀ¹½ØÃÜÂëµÈ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝSBUºÍÒ»¸ö°²È«³§É̵ĵ÷²é £¬£¬£¬£¬£¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬SBU»¹·¢ÏÖÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÓй¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html


5¡¢¿¨°Í˹»ùÅû¶·¸×ïÍÅ»ïDustSquadµÄй¤¾ßOctopus

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒÅû¶·¸×ïÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£OctopusÖØÒªÕë¶ÔÖÐÑǵØÓòµÄ±í½»²¿ÃÅ £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü £¬£¬£¬£¬£¬Æä¹¦·ò´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ £¬£¬£¬£¬£¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â £¬£¬£¬£¬£¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£¡£¡£¡£¡£¡£¡£¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖÓÆ¾ÃÐÔ £¬£¬£¬£¬£¬Æä·þÎñÆ÷¶ËÊÇPHPµÄ £¬£¬£¬£¬£¬²¿ÊðÔÚ·ÖÆç¹ú¶È/µØÓòµÄóÒ×ÍйܷþÎñÖС£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/octopus-infested-seas-of-central-asia/88200/


6¡¢³¬¹ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉÏÏúÊÛ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄ×êÑÐÈËÔ±ÔÚ°µÍøÂÛ̳ÉÏ·¢ÏÖÒ»¸öÔ̺¬´óÁ¿Ñ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÔÚÏúÊÛ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼Ô̺¬ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±º¹ÇàºÍÆäËüͶƱÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾½øÐÐÁËÉó²é £¬£¬£¬£¬£¬È·ÈÏÕâЩÊý¾ÝÓÐЧ²¢ÇÒ¸ÃÊý¾Ý¿âÓµÓи߶ȵĿÉÐŶÈ¡£¡£¡£¡£¡£¡£¡£¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´ £¬£¬£¬£¬£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´·ÛËéÑ¡¾Ù»ò½øÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù