»ÝÆÕÔÙ´ÎÖҸ沿ÃÅSSD½«ÔÚÔËÐÐ4ÍòÓ×ʱºó³öÏÖ¹ÊÕÏ £»£»£» £»£»ºÚ¿Íͨ¹ý½Ù³Ö·ÓÉÆ÷DNS´«²¼OskiľÂí

°ä²¼¹¦·ò 2020-03-25

1.GE¹©¸øÉÌÔâºÚ¿ÍÈëÇÖµ¼ÖÂÔ±¹¤ÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ͨÓÃµçÆø£¨GE£©°µÊ¾ÔÚÒ»¼Ò·þÎñÌṩÉÌÔâµ½ºÚ¿ÍÈëÇÖºóÆäÏÖÈΡ¢Ç°ÈÎÔ±¹¤ÒÔ¼°ÓйØÊÜÒæÈ˵ÄÓ×ÎÒÉí·ÝÐÅϢй¶¡£¡£¡£ ¡£¡£GEÔÚÏò¼ÓÀû¸£ÄáÑÇÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÊý¾Ýй¶֪ͨÖгÆ£¬ £¬£¬£¬£¬£¬Æä·þÎñÌṩÉ̼ÑÄÜÒµÎñÁ÷³Ì·þÎñÓÐÏÞ¹«Ë¾£¨Canon Business Process Services£¬ £¬£¬£¬£¬£¬Inc.£©µÄÒ»¸öÓÊÏäÕË»§ÔÚ2ÔÂ3ÈÕÖÁ14ÈÕÖ®¼äÔâδÊÚȨ½Ó¼û£¬ £¬£¬£¬£¬£¬¸ÃÕË»§Ô̺¬²¿ÃÅGEÔ±¹¤ºÍÓйØÊÜÒæÈ˵ÄÎļþ£¬ £¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§ºÅÂë¡¢¹¤×Ê±í¡¢¼ÝÕÕ¡¢»¤ÕÕ¡¢ÉúÈÕ¡¢³É»éÖ¤Ã÷µÈ£¬ £¬£¬£¬£¬£¬GEµÄϵͳδÊܵ½ÊÂÎñÓ°Ïì¡£¡£¡£ ¡£¡£GEûÓÐй©ÊÜÓ°ÏìµÄ¾ßÌåÈËÊý£¬ £¬£¬£¬£¬£¬Canon°µÊ¾½«Í¨¹ýÒ»¼ÒÃûΪExperianµÄ¹«Ë¾Ãâ·ÑΪÊÜÓ°ÏìµÄÓ×ÎÒÌṩÁ½ÄêµÄÉí·Ý± £»£»£» £»£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tech-giant-ge-discloses-data-breach-after-service-provider-hack/


2.FireEyeÖÒ¸æÕë¶ÔICSµÄºÚ¿Í¹¤¾ßÔÚ·ºÀÄ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


FireEye°²È«×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬ £¬£¬£¬£¬£¬Õë¶Ô¹¤Òµ½ÚÔìϵͳ£¨ICS£©µÄºÚ¿Í¹¤¾ßÔÚ·ºÀÄ£¬ £¬£¬£¬£¬£¬Õâ½µµÍÁ˹¥»÷ÕßµÄ×¼ÈëÃż÷£¬ £¬£¬£¬£¬£¬²¢Ôö³¤Á˹¤ÒµÆóÒµµÄ·çÏÕ¡£¡£¡£ ¡£¡£ÔÚ×î½üµÄÒ»Ïî×êÑÐÖУ¬ £¬£¬£¬£¬£¬FireEye·ÖÎöÁ˽üÄêÀ´°ä²¼µÄÓµÓÐÕë¶ÔICSÖ°ÄܵÄËùÓкڿ͹¤¾ß£¬ £¬£¬£¬£¬£¬¹ÌȻһЩ¹¤¾ßÔçÔÚ2004Äê¾ÍÒÑ´´½¨£¬ £¬£¬£¬£¬£¬µ«´óÎÞÊý¶¼ÊÇÔÚ´Óǰ10ÄêÖпª·¢µÄ¡£¡£¡£ ¡£¡£FireEye°µÊ¾´óÎÞÊýºÚ¿Í¹¤¾ß¶¼Ó빩¸øÉÌÎ޹أ¬ £¬£¬£¬£¬£¬ÖØÒªÉ¨ÃèICSÍøÂçÉϵÄͨÓÃÖ¸±ê£¬ £¬£¬£¬£¬£¬µ«Ò²ÓÐÕë¶ÔÌØ¶¨ICS¹©¸øÉÌ¿ª·¢µÄ¹¤¾ß£¬ £¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÖÐ60%¶¼ÊÇÕë¶ÔÎ÷ÃÅ×Ó¡£¡£¡£ ¡£¡£Æ¾¾ÝFireEyeµÄ˵·¨£¬ £¬£¬£¬£¬£¬´óÎÞÊýICSºÚ¿Í¹¤¾ß¶¼ÊÇ»ùÓÚµ±½ñÈýÖÖ×îÊ¢ÐеÄÉøÈë²âÊÔ¿ò¼ÜÄ£¿£¿ £¿£¿£¿ £¿£¿é-Metasploit¡¢Core ImpactºÍImmunity Canvas¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fireeye-warns-about-the-proliferation-of-ready-made-ics-hacking-tools/


3.WildPressure¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬Õë¶ÔÖж«¹¤Òµ×éÖ¯


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊҵݲȫר¼Ò·¢ÏÖÕë¶ÔÖж«¹¤Òµ×éÖ¯µÄAPT¹¥»÷»î¶¯WildPressure¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±ÔÚ2019Äê8Ô³õ´Î·¢ÏÖÁËWildPressure£¬ £¬£¬£¬£¬£¬Æäʱ×êÑÐÈËÔ±¼ì²âµ½Ò»¸öеĶñÒâÈí¼þMilum¡£¡£¡£ ¡£¡£MilumÊÇÒ»¸ö³ÉÊìµÄC++ľÂí£¬ £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓëÒÑÖªµÄÈκι¥»÷»î¶¯¾ùûÓÐÀàËÆµÄ´úÂ룬 £¬£¬£¬£¬£¬Ò²Ã»Óй¥»÷Ö¸±êÉϵĽ»²æ¡£¡£¡£ ¡£¡£ÏÖʵÉÏ£¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±½öÔÚÒ»¸ö¹ú¶ÈÖз¢ÏÖÁË3¸ö¶ÀÁ¢µÄÑù±¾¡£¡£¡£ ¡£¡£µ±Ç°ÈÔ²»Ã÷ÏÔ¹¥»÷Õß´«²¼MilumľÂíµÄ·½Ê½£¬ £¬£¬£¬£¬£¬²¢ÇÒÎÞ·¨½«Æä¹éÒò£¬ £¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±ÒÔΪ¹¥»÷Õß¿ÉÄÜ»áÔÚÆäËü¹¥»÷»î¶¯ÖгÁ¸´Ê¹ÓøÃľÂí¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/wildpressure-targets-industrial-in-the-middle-east/96360/


4.ºÚ¿Íͨ¹ý½Ù³Ö·ÓÉÆ÷DNS´«²¼OskiľÂí


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚ×î½üµÄ¹¥»÷»î¶¯ÖУ¬ £¬£¬£¬£¬£¬ºÚ¿Íͨ¹ý½Ù³Ö·ÓÉÆ÷µÄDNSÉèÖÃÔÚÓû§µÄWebä¯ÀÀÆ÷ÉÏÏÔʾÐéαµÄCOVID-19¾¯±¨²¢·Ö·¢ÐÅÏ¢ÇÔȡľÂíOski¡£¡£¡£ ¡£¡£Ä¿Ç°Éв»ÖªÂ·¹¥»÷ÕßÈôºÎ»ñµÃ¶Ô·ÓÉÆ÷µÄ½Ó¼ûºÍ¸ü¸ÄÆäDNSÅäÖ㬠£¬£¬£¬£¬£¬µ«¿ÉÄÜÊÇͨ¹ýÈõÃÜÂëÀ´½øÐÐÔ¶³Ì½Ó¼û¡£¡£¡£ ¡£¡£¾ßÌåÀ´Ëµ£¬ £¬£¬£¬£¬£¬¹¥»÷Õß½«Â·ÓÉÆ÷µÄDNS·þÎñÆ÷¸ü¸ÄΪ109.234.35.230ºÍ94.103.82.249£¬ £¬£¬£¬£¬£¬µ±WindowsÔËÐÐNCSI̽ÕëÀ´²é³­ÍÆËã»úÊÇ·ñÒÑÏνӵ½»¥ÁªÍøÊ±£¬ £¬£¬£¬£¬£¬¶ñÒâDNS·þÎñÆ÷½«Æä·¢Ë͵½¶ñÒâIP 176.113.81.159£¬ £¬£¬£¬£¬£¬¸ÃIPÉϵÄÍøÕ¾ÒªÇóÓû§ÏÂÔØ²¢×°ÖöñÒâµÄ¡°Emergency-COVID-19 Informator¡±»ò¡°COVID-19 Inform App¡±£¬ £¬£¬£¬£¬£¬¸Ã·¨Ê½ÏÖʵÉÏÊÇÐÅÏ¢ÇÔȡľÂíOski¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-hijack-routers-dns-to-spread-malicious-covid-19-apps/


5.΢Èí°ä²¼AstarothľÂíй¥»÷Á´µÄ·ÖÎö»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾Ý΢ÈíDefender ATPÍŶӵÄÒ»·Ý×êÑл㱨£¬ £¬£¬£¬£¬£¬AstarothľÂíÔÚ2Ô³õ±äµÃ»îÔ¾£¬ £¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßÒýÈëÁËм¼Êõʹ¹¥»÷Á´Ô½·¢Òñ±Î¡£¡£¡£ ¡£¡£Astaroth´Ë¿ÌÅׯúÁËÒÀÀµWindowsÖÎÀí¹¤¾ßºÅÁîÐУ¨WMIC£©µÄÓйØÌӱܼ¼Êõ£¬ £¬£¬£¬£¬£¬×ªÏòÀÄÓñ¸ÓÃÊý¾ÝÁ÷£¨ADS£©À´°µ²Ø¶ñÒâºÉÔØÒÔ¼°ÀÄÓúϷ¨¹ý³ÌExtExport.exe£¨Ò»ÖÖ¼«¶È²»³£¼ûµÄ¹¥»÷ý½é£©À´¼ÓÔØÓÐЧºÉÔØ¡£¡£¡£ ¡£¡£¹¥»÷Á´Ê¼ÓÚÆÏÌÑÑÀÓïµÄµç×ÓÓʼþ£¬ £¬£¬£¬£¬£¬ÓʼþÖÐÔ̺¬Ö¸ÏòÍйܴ浵ÎļþµÄURLÁ´½Ó£¬ £¬£¬£¬£¬£¬ÎļþÖÐÔ̺¬ÓÕµ¼ÐÔµÄLNKÎļþ£¬ £¬£¬£¬£¬£¬µã»÷ʱLNKÎļþ½«ÔËÐлìºÏµÄBATºÅÁî¡£¡£¡£ ¡£¡£BATºÅÁîŲÓÃexplorer.exeÀ´ÔËÐÐJavaScriptÎļþ£¬ £¬£¬£¬£¬£¬²¢Ê¹ÓÃGetObject¼¼ÊõÔÚÄÚ´æÖÐÔËÐиü´óµÄÖ÷JavaScript£¬ £¬£¬£¬£¬£¬¶øºóÖ÷¾ç±¾Å²ÓÃBITSAdminµÄ¶à¸öÊ·ý´ÓC2ÏÂÔØ¶à¸ö¶þ½øÔìBlob£¬ £¬£¬£¬£¬£¬²¢½áºÏÈý¸öBlobÐγɲ¢¼ÓÔØµÚÒ»½×¶Î¶ñÒâ´úÂ룬 £¬£¬£¬£¬£¬×îºó¶ÁÈ¡ADSÁ÷²¢½âÃÜΪAstarothµÄDLL£¬ £¬£¬£¬£¬£¬·´Éä¼ÓÔØµ½userinit.exeÖÓ×£¡£¡£ ¡£¡£ÔÚÕâ¸ö¹ý³ÌÖÐAstaroth²»»á½Ó´¥´ÅÅÌ£¬ £¬£¬£¬£¬£¬Ö±½Ó¼ÓÔØµ½ÄÚ´æÖÓ×£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2020/03/23/latest-astaroth-living-off-the-land-attacks-are-even-more-invisible-but-not-less-observable/


6.»ÝÆÕÔÙ´ÎÖҸ沿ÃÅSSD½«ÔÚÔËÐÐ4ÍòÓ×ʱºó³öÏÖ¹ÊÕÏ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


»ÝÆÕÔÙ´ÎÖÒ¸æÆä¿Í»§£¬ £¬£¬£¬£¬£¬Ä³Ð©´®ÐÐÏνӵÄSCSI¹Ì̬ӲÅÌ»áÔÚÔËÐÐ4ÍòÓ×ʱ£¨Ï൱ÓÚ4Äê206Ìì16¸öÓ×ʱ£©ºó³öÏÖ¹ÊÕÏ£¬ £¬£¬£¬£¬£¬Êý¾ÝºÍÓ²Å̾ùÎÞ·¨¸´Ô­¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÓÚ2019Äê11Ô°䲼ÁËÀàËÆµÄ²¼¸æ£¬ £¬£¬£¬£¬£¬Æäʱ²¿ÃÅSSDÔÚÔËÐÐ32768Ó×ʱºó²úÉú¹ÊÕÏ¡£¡£¡£ ¡£¡£ÕâÒ»´ÎÊÜÓ°ÏìµÄSSDÐͺÅÔ̺¬EK0800JVYPN¡¢EO1600JVYPP¡¢MK0800JVYPQºÍMO1600JVYPR£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬¶àÖÖHP·þÎñÆ÷ºÍ´æ´¢²úÆ·£¬ £¬£¬£¬£¬£¬ÈçHP ProLiant¡¢Synergy¡¢Apollo 4200µÈ¡£¡£¡£ ¡£¡£HPE¹À¼Æ£¬ £¬£¬£¬£¬£¬Î´´ò²¹¶¡µÄSSD×îÔ罫ÔÚ2020Äê10ÔÂÆðÍ·³öÏÖ¹ÊÕÏ£¬ £¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÀûÓù̼þ¸üС£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-warns-of-new-bug-that-kills-ssd-drives-after-40-000-hours/