¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180820

°ä²¼¹¦·ò 2018-08-20

¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯


Ç÷Ïò¿Æ¼¼µÄ°²È«×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÔÚÀûÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕ·ì϶£¨CVE-2018-8373£©ÌáÒé¹¥»÷»î¶¯ £¬¸Ã·ì϶ÊÇÒ»¸öuse-after-free·ì϶ £¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÍÆËã»úÉÏÔËÐÐshellcode¡£ÔÚ×îа汾µÄWindowsÖÐ £¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÅäÖÃÖнûÓÃÁËVBScript £¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£Î¢ÈíÒÑÔÚ8Ô°²È«¸üÐÂÖн¨¸´ÁË´Ë·ì϶¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃÓïÒôÐÅÏä½Ù³ÖPayPalºÍWhatsAppÕË»§


°²È«×êÑÐÈËÔ±Martin Vigo³Æ¹¥»÷Õß¿ÉÀûÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§ £¬ÈçPayPalºÍWhatsAppµÈ¡£´óÎÞÊýÔËÓªÉ̲»½öÖ§³Öͨ¹ýÊÖ»ú½Ó¼ûÓïÒôÐÅÏä £¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃ±í²¿µç»°ºÅÂë½Ó¼ûÓïÒôÐÅÏä¡£ºÜ¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂë £¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈµ¥Ò»ÃÜÂë¡£×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓÃÓïÒôÐÅÏäÀ´³ÁÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂë £¬²¢×îÖÕ½Ù³ÖÓû§µÄPayPalºÍWhatsAppÕË»§¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora


Salesforce×êÑÐÈËÔ±Vishal Thakur·¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£µ½2018Äê7ÔÂµ× £¬×êÑÐÈËÔ±¹Û²ìµ½¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÍÆËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖÐ £¬×î³õµÄϰȾý½éÊÇÍøÂç´¹µöÓʼþ £¬ÆäÔ̺¬Á½¸öÓÐЧºÉÔØ £¬Ò»¸öÊÇÖØÒªÓÃÓÚÇÔÈ¡Óû§Í´´¦µÄľÂí £¬ÀýÈç±¾µØÕË»§ºÍä¯ÀÀÆ÷µÄÍ´´¦µÈ¡£ÁíÒ»¸öÓÐЧºÉÔØÊÇÀÕË÷Èí¼þAurora £¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/


¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA


×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£Ä¿Ç°»¹²»ÖªÂ·MAFIAÈôºÎ½øÈëÓû§µÄϵͳ £¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹µö»î¶¯ÊµÏÖÕâÒ»²½µÄ¡£MAFIAÀûÓÃOpenSSLÀ´¼ÓÃÜÎļþ £¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ £¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©´óÃû¡£ÓÉÓÚÆä¼ÓÃܹý³ÌºÜÂý £¬Óû§¿Éͨ¹ýÖÕÖ¹Æä¹ý³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø¹ØÍÆËã»úÀ´×èÖ¹Ëü¡£MAFIAʹÓÃTor´úÀí½øÐÐC2ͨѶ £¬Æäͨ¹ýHTTP GETÒªÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html


¡¾¶ñÒâÈí¼þ¡¿×êÑлú¹¹°ä²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄ·ÖÎö»ã±¨


Cyberbit×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²â¼¼Êõ¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬ÆäÔ̺¬ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÍÆËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûÍ´´¦µÈÄ£¿é¡£×êÑÐÈËÔ±·¢ÏÖTrickbotµÄбäÖÖѡȡ¹ý³ÌÍڿյĴúÂë×¢Èë¼¼Êõ £¬´óÎÞÊý°²È«²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸ö°²È«·ì϶


8ÔÂ19ÈÕProject InsecurityµÄÁ½Ãû°²È«×êÑÐÈËÔ±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ´æÔÚÒ»¸ö±¾µØÎļþй¶·ì϶¡£TRSϵͳÊÇÖ¸µçÐÅÖм̷þÎñ £¬ÓÃÓÚÔ®ÊÖ¶úÁû»ò˵»°×è°­µÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨ÖúÉ豸²¦´òµç»°¡£¼ÓÄôóµÄËùÓÐÖØÒªISP¶¼ÊÜÓ°Ïì £¬Ô̺¬Rogers¡¢TelusºÍBCEµÈ £¬ÕâЩISPµÄ·þÎñ¶ÔÏóº­¸ÇÁ˳¬¹ý3000Íò¼ÓÄôó¹«Ãñ¡£ËùÓеÄÖØÒª¼ÓÄôóISP¶¼ÒѾ­½¨¸´Á˸÷ì϶¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/