¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181207

Ðû²¼Ê±¼ä 2018-12-07
1¡¢ÃÀDHSºÍFBIÍŽáÐû²¼Õë¶ÔÀÕË÷Èí¼þSamSamµÄÍþв¾¯±¨

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹úDHSÏÂÊô¹ú¼ÒÍøÂçÇå¾²ºÍͨѶ¼¯³ÉÖÐÐÄ£¨NCCIC£©ÍŽáFBIÅäºÏÐû²¼ÀÕË÷Èí¼þSamSamжñÒâÔ˶¯µÄ¾¯±¨¡£SamSamÖ÷ÒªÕë¶ÔÃÀ¹ú £¬Ãé×¼¶à¸öÐÐÒµ £¬°üÀ¨Ò»Ð©Òªº¦»ù´¡ÉèÊ©¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔWindows·þÎñÆ÷ £¬Æ¾Ö¤FBIµÄÆÊÎö £¬×Ô2016ÄêÄêÖÐÒÔÀ´ £¬¹¥»÷Õßͨ¹ýRDPЭÒéÈëÇÖÊܺ¦ÕßµÄÍøÂ硣ͨ³£ÇéÐÎϹ¥»÷ÕßʹÓñ©Á¦ÆÆ½â¹¥»÷»ò±»µÁƾ֤¾ÙÐÐÈëÇÖ £¬µ«FBIµÄÆÊÎöÅú×¢¹¥»÷Õß»¹´Ó°µÍøÊг¡ÉϹºÖÃÁËһЩ±»µÁµÄRDPƾ֤¡£DHSºÍFBI½¨ÒéÓû§ºÍÖÎÀíÔ±Ìáǰ½ÓÄÉÇå¾²²½·¥À´Ô¤·À¸Ã¹¥»÷¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/alerts/AA18-337A


2¡¢ÃÀIRS³Æ2018ÄêÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿ÔöÌíÁè¼Ý60%

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ƾ֤ÃÀ¹ú¹ú˰¾Ö£¨IRS£©µÄ˵·¨ £¬ËäÈ»2015Äê¡¢2016ÄêºÍ2017ÄêµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿³ÊϽµÇ÷ÊÆ £¬µ«ÔÚ2018ÄêIRSÊÓ²ìµ½ÍøÂç´¹ÂÚÕ©Æ­ÊýÄ¿ÔöÌíÁè¼Ý60% £¬´Ó2017ÄêµÄÔ¼1200Æð´ËÀàÊÂÎñÔöÌíµ½2018Äê1ÔÂÖÁ10ÔµÄÁè¼Ý2000Æð¡£IRSÌåÏÖÕ©Æ­Õßͨ¹ý¶ÔÄÉ˰È˾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷ £¬ÊÔͼÇÔÈ¡ËûÃǵÄ×ʽðºÍ˰ÎñÊý¾Ý¡£×î½üµÄ¶ñÒâÔ˶¯¾ÍʹÓÃÁËÖîÈç¡°IRSÖ÷Ҫ֪ͨ¡±¡¢¡°IRSÄÉ˰ÈË֪ͨ¡±µÈÖ÷Ìâ¾ÙÐÐÕ©Æ­¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/irs-warns-of-60-percent-surge-in-email-phishing-scams-during-2018-524126.shtml


3¡¢³¯ÏÊAPT¹¥»÷Ô˶¯STOLEN PENCIL £¬Ö÷ÒªÃé׼ѧÊõ»ú¹¹

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ƾ֤NETSCOUTµÄ×îÐÂÑо¿ £¬×Ô2018Äê5ÔÂÒÔÀ´Ò»¸öеÄAPT¹¥»÷Ô˶¯STOLEN PENCILÖ÷ÒªÕë¶ÔѧÊõ»ú¹¹¡£¸Ã¹¥»÷Ô˶¯¿ÉÄÜÀ´×ÔÓÚ³¯ÏÊ £¬Æä³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹ÂÚÓʼþ £¬²¢ÓÕʹÓû§×°ÖöñÒâµÄChrome²å¼þ¡£Ðí¶à²î±ð´óѧµÄÊܺ¦Õß¶¼ÊÇÉúÎ﹤³ÌרҵµÄ £¬Õâ¿ÉÄÜÅú×¢Îú¹¥»÷ÕßµÄÄîÍ·¡£¹¥»÷ÕßʹÓÃÄÚÖõÄWindowsÖÎÀí¹¤¾ßºÍÏֳɵÄÉÌÒµÈí¼þÀ´ÌӱܹéÒò £¬²¢ÇÒʹÓÃRDPÀ´»á¼ûÊÜѬȾµÄϵͳ £¬¶ø²»ÊǺóÃźÍRAT¡£Ã»ÓÐÖ¤¾ÝÅú×¢ÓÐÊý¾Ý±»ÇÔ £¬Ê¹µÃSTOLEN PENCILµÄÄîÍ·»¹²»Ê®Ã÷È·È·¡£

  

Ô­ÎÄÁ´½Ó£º

https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/


4¡¢½©Ê¬ÍøÂçѬȾÁè¼Ý2Íò¸öWordPressÍøÕ¾ £¬C2·þÎñÆ÷ÓëHostSailorÓйØ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ƾ֤DefiantµÄÐÂÑо¿±¨¸æ £¬Ò»¸öÓÉÁè¼Ý2Íò¸öWordPressÍøÕ¾×é³ÉµÄ½©Ê¬ÍøÂçÕý±»ÓÃÓÚ¹¥»÷ºÍѬȾÆäËüµÄWordPressÍøÕ¾¡£¸Ã½©Ê¬ÍøÂç»á¶ÔÆäËüWordPressÍøÕ¾¾ÙÐб©Á¦ÆÆ½â¹¥»÷ £¬Ö±µ½·¢Ã÷ÓÐÓõÄÓû§ÕË»§¡£ÕâÖÖ±¬ÆÆ¹¥»÷Õë¶ÔWordPressµÄXML-RPCʵÏÖ £¬ÓÉÓÚXML-RPCĬÈϲ»»á¶ÔAPIÇëÇóµÄËÙÂʾÙÐÐÏÞÖÆ £¬Òò´Ë¹¥»÷Õß¿ÉÒÔÒ»Ö±¾ÙÐÐʵÑé¡£¸Ã½©Ê¬ÍøÂçʹÓÃÁË4¸öC2·þÎñÆ÷ £¬ÕâЩC2ͨ¹ý¶íÂÞ˹Best-Proxies.ruµÄÊðÀí·þÎñÆ÷·¢³öÖ¸Áî¡£¹¥»÷ÕßÒ»¹²Ê¹ÓÃÁË1.4Íò¶à¸öÊðÀí·þÎñÆ÷À´ÒþÄäC2·þÎñÆ÷µÄλÖà £¬ÆäÖÐÈý¸öC2·þÎñÆ÷ÓëHostSailor¹«Ë¾ÓйØ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.wordfence.com/blog/2018/12/wordpress-botnet-attacking-wordpress/


5¡¢ÎÚ¿ËÀ¼SBUÖ¸Ôð¶íÂÞ˹Ç鱨»ú¹¹¹¥»÷¸Ã¹ú˾·¨ÏµÍ³

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÎÚ¿ËÀ¼SBUÐû³Æ×èÖ¹Á˶íÂÞ˹Ç鱨»ú¹¹ÌᳫµÄÕë¶Ô¸Ã¹ú˾·¨²¿·ÖITϵͳµÄÍøÂç¹¥»÷Ô˶¯¡£¹¥»÷Õßͨ¹ýÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷·Ö·¢¶ñÒâµÄ»á¼ÆÎĵµ £¬ÕâЩÎĵµÖаüÀ¨ÓÃÓÚÇÔÈ¡Êý¾ÝºÍÆÆËð˾·¨ÏµÍ³µÄ¶ñÒâÈí¼þ¡£ÎÚ¿ËÀ¼Ç徲ר¼Ò·¢Ã÷¸Ã¹¥»÷Ô˶¯ÖеÄC&C»ù´¡ÉèʩʹÓÃÁ˶íÂÞ˹µÄIPµØµã¡£ÎÚ¿ËÀ¼SSIPºÍ¹ú¼Ò˾·¨ÐÐÕþ²¿·ÖÅɺÏ×èÖ¹Á˸ù¥»÷¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78726/cyber-warfare-2/sbu-russia-cyber-attack.html


6¡¢ESET·¢Ã÷21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×å £¬¾ùΪOpenSSHºóÃÅľÂí

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÔÚÒ»·Ý³¤´ï53Ò³µÄ±¨¸æÖÐ £¬ESETÏêϸÏÈÈÝÁË21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×å £¬ÕâЩ¶ñÒâÈí¼þ¶¼ÊÇOpenSSH¿Í»§¶ËµÄľÂí»¯°æ±¾¡£ÆäÖÐһЩ¶ñÒâÈí¼þºÜÊǼòÆÓ £¬µ«Ò²ÓÐһЩºÜÊÇÖØ´ó £¬¿ÉÄÜÀ´×ÔÓÚÓÐÂÄÀúµÄ¶ñÒâÈí¼þ¿ª·¢Ö°Ô±¡£ÕâЩ¶ñÒâÈí¼þ¶¼Êǵڶþ½×¶Î¹¤¾ß £¬¿ÉÒÔ°²ÅÅÔÚ¸üÖØ´óµÄ½©Ê¬ÍøÂçÔ˶¯ÖÐ £¬ÓÃÀ´Ìæ»»Õý³£µÄOpenSSH°æ±¾¡£ESETÌåÏÖÆäÖÐ18¸ö¼Ò×å¶¼¾ßÓÐÆ¾Ö¤ÇÔÈ¡¹¦Ð§ £¬²¢ÇÒ17¸ö¼Ò×å¾ßÓкóÃÅģʽ £¬¿ÉÔÊÐíÒþÄäµÄ¶ñÒâÅþÁ¬¡£±¨¸æÖаüÀ¨ÁËÕâЩ¶ñÒâÈí¼þµÄIoCÖ¸±ê¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf


ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí