2019ÄêÀ¬»øÓʼþºÍ´¹µö¹¥»÷»ã±¨£»£» £» £»£»£»£»£»×êÑÐÈËÔ±ÑÝʾÕë¶ÔPowerPointµÄÊó±êÐüÍ£¹¥»÷

°ä²¼¹¦·ò 2020-04-10

1.FireEyeÅû¶COVID-19µ¼ÖµÄÍþвµÄ¸ñ¾Ö±ä¶¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝFireEyeµÄÒ»·ÝÍþв×êÑв©¿Í £¬£¬£¬£¬£¬Ö»¹ÜCOVID-19¶Ô8827Ì«Ñô¼¯ÍÅÉç»áºÍ¾­¼Ã²úÉúÁ˾޴óÓ°Ïì £¬£¬£¬£¬£¬µ«Æä¶ÔÍøÂçÍþв¸ñ¾ÖµÄÓ°ÏìÒÀÈ»ÓÐÏÞ¡£¡£ ¡£¡£¡£ÔÚ´óÎÞÊýÇé¿öÏ £¬£¬£¬£¬£¬ÍøÂç¹¥»÷ÕßµÄÐÐΪ·½Ê½ÓëÒÔǰһÑù £¬£¬£¬£¬£¬µ«¸ü¶àµØÀûÓÃCOVID-19Σ»£» £» £»£»£»£»£»ú×÷ΪһÖÖÉç»á¹¤³Ì¼¿Á©À´ÎüÒýÓû§¡£¡£ ¡£¡£¡£Ö»¹ÜÈç´Ë £¬£¬£¬£¬£¬COVID-19ÈÔÖ»Õ¼°Ù·ÖÖ®¶þµÄ¶ñÒâµç×ÓÓʼþÁ÷Á¿¡£¡£ ¡£¡£¡£FireEyeĿǰÔÚ×·×ÙµÄÍþв¸ñ¾ÖµÄ³Á´ó±ä¶¯Ô̺¬£ºÔ¶³ÌÀͶ¯Á¦µÄºöÈ»´óÁ¿Ôö³¤Å¤×ªÁËÆóÒµÍøÂçµÄÐÔÖʺʹàÈõÐÔ£»£» £» £»£»£»£»£»¹¥»÷ÕßÔÚÀûÓÃCOVID-19¼°ÓйØÖ÷Ìâ×÷ΪÉç»á¹¤³ÌѧսÊõ£»£» £» £»£»£»£»£»Ò½ÁƱ£½¡ÔËÓª £¬£¬£¬£¬£¬ÓйصÄÔì×÷¡¢ÎïÁ÷ºÍÖÎÀí×éÖ¯ÒÔ¼°²Î¼ÓÓ¦¶ÔΣ»£» £» £»£»£»£»£»úÈ·µ±²¿ÃÅÃűäµÃÔ½À´Ô½³ÁÒª £¬£¬£¬£¬£¬²¢ÇÒÈÝÒ×Ôâ·êÖîÈçÀÕË÷Èí¼þÖ®ÀàµÄ·ÛËéÐÔ¹¥»÷µÈ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2020/04/limited-shifts-in-cyber-threat-landscape-driven-by-covid-19.html


2.¿¨°Í˹»ù°ä²¼2019ÄêÀ¬»øÓʼþºÍ´¹µö¹¥»÷»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù°ä²¼2019ÄêÀ¬»øÓʼþºÍ´¹µö¹¥»÷»ã±¨ £¬£¬£¬£¬£¬»ã±¨Ö¸³ö2019ÄêÀ¬»øÓʼþռȫÇòÓʼþÁ÷Á¿ÖеıÈÀýΪ56.51% £¬£¬£¬£¬£¬±È2018ÄêÔö³¤4.03¸ö°Ù·Öµã¡£¡£ ¡£¡£¡£2019ÄêÀ¬»øÓʼþµÄ×î´óÆðÔ´¹úÊÇÖйú£¨21.26%£©¡£¡£ ¡£¡£¡£44%µÄÀ¬»øÓʼþ´óÓײ»µ½2KB¡£¡£ ¡£¡£¡£À¬»øÓʼþÖÐ×î³£¼ì²âµ½µÄ·ì϶ÀûÓÃÊÇExploit.MSOffice.CVE-2017-11882¡£¡£ ¡£¡£¡£2019Ä꿨°Í˹»ùµÄ·´´¹µöϵͳ±»´¥·¢ÁË467188119´Î £¬£¬£¬£¬£¬¹²ÓÐ17%µÄÓû§Ôâµ½´¹µö¹¥»÷¡£¡£ ¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬2019ÄêµÄÖØÒªÇ÷ÏòÊÇ¶ÔÆóÒµ²¿ÃŵĹ¥»÷ÊýÁ¿Ôö³¤¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/spam-report-2019/96527/


3.Äá²´¶ûISP VianetÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬170Íò¿Í»§Êý¾Ýй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Äá²´¶û»¥ÁªÍø·þÎñÌṩÉÌVianet CommunicationsÈ·ÈÏÆäÐÅϢϵͳÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬¿Í»§µÄÓ×ÎÒÐÅÏ¢±»ÇÔ¡£¡£ ¡£¡£¡£ºÚ¿ÍÔÚTwitterÕÊ»§ÉÏÐû³ÆÇÔÈ¡ÁË170ÍòVianet¿Í»§µÄÊý¾Ý £¬£¬£¬£¬£¬Ô̺¬ËûÃǵÄÐÕÃû¡¢ÊÖ»úºÅÂë¡¢µØÖ·ºÍµç×ÓÓʼþµØÖ·¡£¡£ ¡£¡£¡£ºÚ¿ÍµÄÍÆÎÄÖл¹Ô̺¬ÍйÜÔÚÑó´ÐÍøÂçÉϵÄй¶Êý¾ÝÁ´½Ó¡£¡£ ¡£¡£¡£VianetÔÚÆä¹Ù·½ÉêÃ÷ÖÐÈ·ÈÏÁËÕâÒ»ÊÂÎñ £¬£¬£¬£¬£¬²¢°µÊ¾ÒѾ­È·¶¨ÁËй¶µÄ±¾Ô­ºÍ²ÉÈ¡Êʵ±µÄ´ëÊ©À´¼ÓÇ¿°²È«ÐÔ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.nepalitelecom.com/2020/04/vianet-customer-data-leaks-hack.html


4.ºÚ¿ÍÔÚ°µÍøÂÛ̳ÏúÊÛ5.2ÍòÒÁÀʹ«ÃñµÄÉí·ÝÖ¤ÕÕÆ¬


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛ5.2ÍòÒÁÀʹ«ÃñµÄÉí·ÝÐÅÏ¢ £¬£¬£¬£¬£¬Æ¾¾ÝHackread.com¿´µ½µÄÑù±¾Êý¾Ý £¬£¬£¬£¬£¬Äܹ»È·ÈϺڿÍÔÚÏúÊÛ8.17GBµÄÊý¾Ý£¨Ô̺¬4.5Íò¸öÎļþ£© £¬£¬£¬£¬£¬ÕâЩÎļþÔ̺¬ÒÁÀʹ«ÃñµÄÉí·ÝÖ¤¡¢µ®ÉúÖ¤Ã÷¡¢»¤Õպͽè¼Ç¿¨µÈµÄ¸±±¾¡£¡£ ¡£¡£¡£¸üÔã¸âµÄÊÇ £¬£¬£¬£¬£¬Éí·ÝÖ¤³ÖÓÐÈ˵Ä×ÔÅÄÕÕÒ²Ô̺¬ÔÚÏúÊÛµÄÊý¾ÝÖÓ×£¡£ ¡£¡£¡£°²È«×êÑÐÔ±Mohammad Jorjandi³ÆÕâЩÐÅÏ¢ÊÇ´Ó¼¸¸ö·ÖÆçµÄÍøÕ¾ÍøÂçµÄ £¬£¬£¬£¬£¬Ô̺¬ÔÚÏ߸æ°×ºÍʵÓ÷¨Ê½Æ½Ì¨Niazpardaz[.]irºÍ±ÈÌØ±ÒÂòÂôÍøÕ¾Arzi24[.]com¡£¡£ ¡£¡£¡£ÕâЩÊý¾ÝµÄÊÛ¼ÛΪ0.2¸ö±ÈÌØ±Ò £¬£¬£¬£¬£¬Ô¼ºÏ1463ÃÀÔª¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/iranian-id-cards-selfies-sold-dark-web-hacking-forum/


5.×êÑÐÈËÔ±ÑÝʾÕë¶ÔPowerPointµÄÊó±êÐüÍ£¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±Mandar SatamÕë¶ÔÒ»ÖÖÐµĹ¥»÷ý½é·¢³öÖÒ¸æ £¬£¬£¬£¬£¬¸Ã¹¥»÷ý½éʹºÚ¿ÍÖ»Ð轫Êó±êÐüÍ£ÔÚ³¬Îı¾Á´½ÓÉϼ´¿É°Ñ³ÖPowerPointÏÂÔØ²¢ÆðÍ·×°ÖöñÒâÈí¼þ¡£¡£ ¡£¡£¡£¸Ã¹¥»÷¼¼ÊõµÄÈ·±ØÒªÊܺ¦Õßµã»÷Ò»¸öµ¯³ö¶Ô»°¿òÀ´ÔËÐлò×°Ö÷¨Ê½ £¬£¬£¬£¬£¬ÓÉÓÚÕâ¸öÔ­Òò £¬£¬£¬£¬£¬Î¢Èí²»»á½«ÆäÊÓΪ·ì϶¡£¡£ ¡£¡£¡£Satam°µÊ¾·ì϶´æÔÚÓÚPowerPointµÄOpen XML Slide ShowÎļþ£¨³ÆÎªPPSX£©ÖÐ £¬£¬£¬£¬£¬SatamÔÚPoCÖÐÈÆ¹ýÁË΢ÈíÓÚ2017ÄêÖ´ÐеÄPowerPointÏÞ¶È¡£¡£ ¡£¡£¡£Í¨¹ý½«¡°ÔËÐз¨Ê½¡±»¥»»Îª¡°HyperLink To¡± £¬£¬£¬£¬£¬¸ÃPoCÄܹ»´ÓÔ¶³Ì·þÎñÆ÷ÖÐÔËÐпÉÖ´ÐÐÎļþ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/powerpoint-weakness-mouse-over-attack/154589/


6.Android¶ñÒâÈí¼þxHelper £¬£¬£¬£¬£¬ÒÑϰȾ4.5Íǫ̀É豸


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Android¶ñÒâÈí¼þxHelperÓÚ2019Äê3Ô³õ´Î±»·¢ÏÖ £¬£¬£¬£¬£¬Ëüʱʱ¼Ù×°³ÉϵͳÇå½à¹¤¾ßͨ¹ýµÚÈý·½½øÐÐÏÂÔØºÍ×°Öᣡ£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»¼à¶½Óû§¡¢ÇÔÈ¡Êý¾ÝÒÔ¼°ÏÂÔØºÍÖ´ÐÐÆäËü¶ñÒⷨʽ £¬£¬£¬£¬£¬Ô̺¬¸æ°×ºÍTrojan-Dropper.AndroidOS.Necro.z¡£¡£ ¡£¡£¡£xHelperÖÁÉÙÒѾ­Ï°È¾ÁË4.5Íǫ̀É豸 £¬£¬£¬£¬£¬ÆäÖдóÎÞÊýϰȾ²úÉúÔÚ¶íÂÞ˹¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þÎÞ·¨Í¨¹ýɾ³ý»ò¸´Ô­³ö³§ÉèÖÃÀ´¶Ï¸ù¡£¡£ ¡£¡£¡£¿£¿£¿£¿£¿¨°Í˹»ù×êÑÐÈËÔ±Igor GolovinÔÚÒ»·Ý²©¿ÍÎÄÕÂÖа䷢Á˶ԸöñÒâÈí¼þÓÆ¾ÃÐÔ»úÔìµÄ·ÖÎö¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-is-why-the-vicious-xhelper-malware-resists-factory-wipes-and-reboots/