IBM½¨¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸ö·ì϶£»£»£»£»£»TA505ÐÂÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬£¬£¬£¬ÖØÒª·Ö·¢GelupºÍFlowerPippi
°ä²¼¹¦·ò 2019-07-05
IBM½¨¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Êý¾Ý·ÖÎö¹¤¾ßPlanning Analytics¡¢Êý¾Ý±£»£»£»£»£»¤Æ½Ì¨Security GuardiumºÍWebͼÏñ²é¿´Æ÷Daeja ViewONEµÈ¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇSpectrum ProtectÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2019-4087£©£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8·Ö¡£¡£¡£¡£¡£Æ¾¾ÝIBMµÄ±íÊö£¬£¬£¬£¬£¬£¬£¬Í¨¹ý·¢Ë͹ý³¤µÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜ»áÒç³ö»º³åÇø²¢ÔÚÓµÓÐÊ·ýIDȨÏÞµÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬»òµ¼Ö·þÎñÆ÷/´æ´¢´úÀí±ÀÀ£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚSpectrum ProtectÖеIJ»ÕýÈ·Ììǵ²é³£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬7.1ºÍ8.1¡£¡£¡£¡£¡£ÁíÒ»¸öÑϳÁµÄ·ì϶ÊÇSecurity GuardiumÖеÄÎļþÉÏ´«·ì϶£¨CVE-2019-4292£©£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8·Ö£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾Îª10.5¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/ibm-patches-critical-high-severity-flaws-in-spectrum-protect/146201/
2¡¢TA505ÐÂÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬£¬£¬£¬ÖØÒª·Ö·¢GelupºÍFlowerPippi
Ç÷Ïò¿Æ¼¼×êÑÐÍŶÓÔÚ6Ô·ݹ۲쵽TA505µÄ¶à¸ö¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷»î¶¯ÖØÒªÕë¶Ô°¢ÁªÇõºÍÉ³ÌØ°¢À²®µÈÖж«¹ú¶ÈÒÔ¼°Ó¡¶È¡¢ÈÕ±¾¡¢°¢¸ùÍ¢¡¢·ÆÂɱöºÍº«¹úµÈÆäËü¹ú¶È¡£¡£¡£¡£¡£×êÑÐÍŶӼì²âµ½Ò»¸öеĶñÒâÈí¼þ¹¤¾ßGelup£¨Trojan.Win32.GELUP.A£©£¬£¬£¬£¬£¬£¬£¬Gelup¿ÉÈÆ¹ýUAC²¢¼ÓÔØÆäËüpayload£¬£¬£¬£¬£¬£¬£¬ÀýÈçFlawedAmmyy RAT¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬TA505»¹Ê¹ÓÃÁËÁíÒ»¸ö¹¤¾ßFlowerPippi£¨Backdoor.Win32.FLOWERPIPPI.A£©£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇÒ»¸öеĺóÃźÍÏÂÔØÆ÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/latest-spam-campaigns-from-ta505-now-using-new-malware-tools-gelup-and-flowerpippi/
3¡¢SodinokibiÐÂÑù±¾ÀûÓÃWindows·ì϶½øÐÐÌáȨ
¿¨°Í˹»ù°ä²¼¹ØÓÚÀÕË÷Èí¼þSodinokibiÐÂÑù±¾µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖSodinokibiÀûÓÃWindowsÖеķì϶£¨CVE-2018-8453£©½øÐÐÌáȨ¡£¡£¡£¡£¡£Æ¾¾Ý¿¨°Í˹»ùµÄÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þµÄϰȾÊÂÎñ±é²¼È«Çò£¬£¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅλÓÚÑÇÌ«µØÓò£ºÖйų́Í壨17.56£¥£©¡¢ÖйúÏã¸ÛÒÔ¼°º«¹ú£¨8.78£¥£©¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖ¸ÃÀÕË÷Èí¼þÔÚ×¢²á±íÖд洢Á˹«Ô¿ºÍ¼ÓÃܵÄ˽Կ¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ»¹»á¼ø±ð¼üÅ̲¼¾Ö£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¶íÂÞ˹¡¢ÎÚ¿ËÀ¼µÈ¹ú¶ÈµÄÍÆËã»úÉ϶ôÖÆÔËÐÓ×£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-exploits-windows-bug-to-elevate-privileges/
4¡¢ÒøÐÐľÂíTrickbotÐÂÔöä¯ÀÀÆ÷CookieÇÔȡģ¿£¿£¿£¿£¿£¿£¿é
×êÑÐÈËÔ±Brad Duncan·¢ÏÖÒøÐÐľÂíTrickbotÐÂÔöÒ»¸öcookieÇÔȡģ¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¸ÃÄ£¿£¿£¿£¿£¿£¿£¿éÆëÈ«¶ÀÁ¢£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ´øÓÐ×Ô¼ºµÄÅäÖÃÎļþ¡£¡£¡£¡£¡£ÁíÒ»Ãû×êÑÐÈËÔ±Vitali Kremez֤ʵÁ˸ÃÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬²¢²¹³ä³ÆÐÂÄ£¿£¿£¿£¿£¿£¿£¿éµÄ¹¹½¨ÈÕÆÚÊÇ6ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»Õë¶ÔËùÓеÄÖØÒªWebä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬£¬Ô̺¬Chrome¡¢Firefox¡¢Internet ExplorerºÍMicrosoft Edge¡£¡£¡£¡£¡£Í¨¹ýÇÔÈ¡cookie£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»»ñȡָ±êµÄÍøÕ¾µÇ¼״̬¡¢Æ«ºÃ¡¢¸öÐÔ»¯ÄÚÈÝ»ò¸ú×ÙÓû§µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/trickbot-trojan-updated-with-standalone-cookie-stealing-module-1831b2a8
5¡¢BianLianбäÖÖÔö³¤ÆÁϼÔìºÍ´´½¨SSH·þÎñÆ÷Ö°ÄÜ
FortiGuard Labs×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíBianLianµÄбäÖÖ£¬£¬£¬£¬£¬£¬£¬¸Ã±äÖÖÔ̺¬Á½¸öÐÂÄ£¿£¿£¿£¿£¿£¿£¿é£ºÆÁϼÔìºÍ´´½¨SSH·þÎñÆ÷¡£¡£¡£¡£¡£¸ÃбäÖÖÒÔAPKµÄ´ó¾Ö·Ö·¢£¬£¬£¬£¬£¬£¬£¬²¢¾¹ýÑϳÁ»ìºÏ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÌìÉú¸÷ÀàËæ»úº¯ÊýÒÔ°µ²ØÄ¾ÂíµÄÕæÊµÖ°ÄÜ¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¸³ö¸Ã±äÖֿɰµ²ØÍ¼±ê²¢ÉêÇëAndroid¸¨ÖúÖ°ÄܵÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡´°¿ÚÄÚÈݺÍÓû§ÔÚÆäËüÀûÓÃÖÐÊäÈëµÄ¿¨ºÅºÍÃÜÂë¡£¡£¡£¡£¡£¸Ã±äÖÖ´´½¨µÄSSH·þÎñÆ÷Äܹ»´úÀíת·¢ÆäC2ͨѶ£¬£¬£¬£¬£¬£¬£¬ÒÔÌӱܼì²â¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/new-bianlian-variant-comes-with-screen-recording-and-creating-ssh-server-capabilities-5f772c50
6¡¢ÓÌËûÖÝÒ»ºÚ¿ÍÒòDDoSÓÎÏ·¹«Ë¾±»ÅÐÈëÓü27¸öÔÂ
Ò»ÃûÀ´×ÔÓÌËûÖݵÄ23ËêºÚ¿Í£¨Austin Thompson£©ÒòÔÚ2013Äê12ÔÂÖÁ2014Äê1ÔÂÆÚ¼ä¶Ô¶à¸öÓÎϷƽ̨ÌáÒéDDoS¹¥»÷±»ÅÐÈëÓü27¸öÔ¡£¡£¡£¡£¡£ÊÜÆä¹¥»÷µÄÓÎϷƽ̨Ô̺¬EAµÄOriginƽ̨¡¢Ë÷ÄáµÄPlayStationÍøÂçÒÔ¼°ValveµÄSteamƽ̨µÈ¡£¡£¡£¡£¡£Æ¾¾ÝÃÀ¹ú˾·¨²¿ÖÜÈý°ä²¼µÄÐÂΟ壬£¬£¬£¬£¬£¬£¬ThompsonµÄÐÐΪÖÁÉÙµ¼ÖÂÁË9.5ÍòÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£³ýÁËÈëÓüÖ®±í£¬£¬£¬£¬£¬£¬£¬Ë¾·¨²¿»¹ºÅÁî±»¸æÏòDaybreak Games£¨ÔË÷ÄáÔÚÏßÓéÀÖ¹«Ë¾£©Ö§¸¶9.5ÍòÃÀÔªµÄÅâ³¥½ð¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/christmas-ddos-attacks.html


¾©¹«Íø°²±¸11010802024551ºÅ