¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181016

Ðû²¼Ê±¼ä 2018-10-16
1¡¢Malwarebytes LabsÐû²¼2018 Q3ÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Malwarebytes LabsÐû²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ£¬£¬£¬£¬£¬ £¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó£¬£¬£¬£¬£¬ £¬ÍøÂç·¸·¨·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμÓËÙÁËËûÃǵĶñÒâ»î¶¯¡£¡£¡£±¾¼¾¶ÈµÄÍþвÇ÷ÊÆ°üÀ¨¶ñÒâÍÚ¿óÈí¼þºÍÎó²îʹÓù¤¾ß°ü±äµÃ³ÉÊ죬£¬£¬£¬£¬ £¬ÀÕË÷Èí¼þÎȲ½ÔöÌí£¬£¬£¬£¬£¬ £¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯×îÏÈËÕÐѵÈ¡£¡£¡£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔöÌíÁË55%£¬£¬£¬£¬£¬ £¬Ïà±ÈÖ®ÏÂÕë¶ÔÏûºÄÕßµÄÍþв½öÔöÌí4%£¬£¬£¬£¬£¬ £¬ÕâÒâζ׏¥»÷ÕßÕýÔÚ×·Çó¸ü´óµÄÀûÒæ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/


2¡¢Branch.ioЧÀͱ»ÆØ±£´æXSSÎó²î£¬£¬£¬£¬£¬ £¬6.85ÒÚÓû§ÒÉÃæÁÙΣº¦

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

vpnMentorµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Branch.ioЧÀͱ£´æXSSÎó²î£¬£¬£¬£¬£¬ £¬Ðí¶àʹÓøÃЧÀ͵ĴóÐÍÍøÕ¾¶¼Êܵ½Ó°Ï죬£¬£¬£¬£¬ £¬°üÀ¨Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ£¬£¬£¬£¬£¬ £¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæÁÙΣº¦¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î»á¼ûÓû§µÄÉèÖÃÎļþºÍÏêϸÐÅÏ¢¡£¡£¡£ËäÈ»¸ÃÎó²îÒÑÐÞ¸´£¬£¬£¬£¬£¬ £¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§¼ì²é×Ô¼ºµÄÕË»§²¢ÇÒÐÞ¸ÄÃÜÂë¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/


3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´ÐеÄÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓëÆÊÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ßΣº¦Îó²î¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©£¬£¬£¬£¬£¬ £¬¸øÕþ¸®»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´Î£º¦¡£¡£¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬ £¬½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£ÏÖÔÚ»¹Ã»ÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/


4¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÎÚ¿ËÀ¼Çå¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷¡£¡£¡£SBUר¼ÒÖ¸³ö£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬Æä¹¦Ð§°üÀ¨Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍ×èµ²ÃÜÂëµÈ¡£¡£¡£Æ¾Ö¤SBUºÍÒ»¸öÇå¾²³§É̵ÄÊӲ죬£¬£¬£¬£¬ £¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬SBU»¹·¢Ã÷ÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÍ̹¤¾ß¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html


5¡¢¿¨°Í˹»ùÅû¶·¸·¨ÍÅ»ïDustSquadµÄй¤¾ßOctopus

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùʵÑéÊÒÅû¶·¸·¨ÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄÊÖÒÕϸ½Ú¡£¡£¡£OctopusÖ÷ÒªÕë¶ÔÖÐÑǵØÇøµÄÍâ½»²¿·Ö£¬£¬£¬£¬£¬ £¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü£¬£¬£¬£¬£¬ £¬Æäʱ¼ä´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ£¬£¬£¬£¬£¬ £¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â£¬£¬£¬£¬£¬ £¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£¡£¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖ³¤ÆÚÐÔ£¬£¬£¬£¬£¬ £¬ÆäЧÀÍÆ÷¶ËÊÇPHPµÄ£¬£¬£¬£¬£¬ £¬°²ÅÅÔÚ²î±ð¹ú¼Ò/µØÇøµÄÉÌÒµÍйÜЧÀÍÖС£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/octopus-infested-seas-of-central-asia/88200/


6¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿Ö°Ô±ÔÚ°µÍøÂÛ̳ÉÏ·¢Ã÷Ò»¸ö°üÀ¨´ó×ÚÑ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ¡£¡£¡£Ñо¿Ö°Ô±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾¾ÙÐÐÁËÉó²é£¬£¬£¬£¬£¬ £¬È·ÈÏÕâЩÊý¾ÝÓÐÓò¢ÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶÈ¡£¡£¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´£¬£¬£¬£¬£¬ £¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆËðÑ¡¾Ù»ò¾ÙÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/


ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí