¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181207

°ä²¼¹¦·ò 2018-12-07
1¡¢ÃÀDHSºÍFBI½áºÏ°ä²¼Õë¶ÔÀÕË÷Èí¼þSamSamµÄÍþв¾¯±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úDHSÏÂÊô¹ú¶ÈÍøÂ簲ȫºÍͨѶ¼¯³ÉÖÐÐÄ£¨NCCIC£©½áºÏFBI¹²Í¬°ä²¼ÀÕË÷Èí¼þSamSamжñÒâ»î¶¯µÄ¾¯±¨¡£¡£¡£¡£¡£¡£¡£¡£SamSamÖØÒªÕë¶ÔÃÀ¹ú£¬£¬£¬£¬£¬¶Ô×¼¶à¸öÐÐÒµ£¬£¬£¬£¬£¬Ô̺¬Ò»Ð©¹Ø¼ü»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒªÕë¶ÔWindows·þÎñÆ÷£¬£¬£¬£¬£¬Æ¾¾ÝFBIµÄ·ÖÎö£¬£¬£¬£¬£¬×Ô2016ÄêÄêÖÐÒÔÀ´£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýRDPºÍ̸ÈëÇÖÊܺ¦ÕßµÄÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£Í¨³£Çé¿öϹ¥»÷ÕßʹÓñ©Á¦ÆÆ½â¹¥»÷»ò±»µÁÍ´´¦½øÐÐÈëÇÖ£¬£¬£¬£¬£¬µ«FBIµÄ·ÖÎöÅú×¢¹¥»÷Õß»¹´Ó°µÍøÊг¡ÉϲɰìÁËһЩ±»µÁµÄRDPÍ´´¦¡£¡£¡£¡£¡£¡£¡£¡£DHSºÍFBI½¨ÒéÓû§ºÍÖÎÀíÔ±Ìáǰ²ÉÈ¡°²È«´ëÊ©À´Ô¤·À¸Ã¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/alerts/AA18-337A


2¡¢ÃÀIRS³Æ2018ÄêÍøÂç´¹µö¹¥»÷ÊýÁ¿Ôö³¤³¬¹ý60%

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ƾ¾ÝÃÀ¹ú¹ú˰¾Ö£¨IRS£©µÄ˵·¨£¬£¬£¬£¬£¬¹ÌÈ»2015Äê¡¢2016ÄêºÍ2017ÄêµÄÍøÂç´¹µö¹¥»÷ÊýÁ¿³Ê½µÂäÇ÷Ïò£¬£¬£¬£¬£¬µ«ÔÚ2018ÄêIRS¹Û²ìµ½ÍøÂç´¹µöÚ¿Æ­ÊýÁ¿Ôö³¤³¬¹ý60%£¬£¬£¬£¬£¬´Ó2017ÄêµÄÔ¼1200Æð´ËÀàÊÂÎñÔö³¤µ½2018Äê1ÔÂÖÁ10Ôµij¬¹ý2000Æð¡£¡£¡£¡£¡£¡£¡£¡£IRS°µÊ¾Ú¿Æ­Õßͨ¹ý¶ÔÄÉ˰È˽øÐÐÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬ÊÔͼÇÔÈ¡ËûÃǵÄ×ʽðºÍ˰ÎñÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£×î½üµÄ¶ñÒâ»î¶¯¾ÍʹÓÃÁËÖîÈç¡°IRS³ÁҪ֪ͨ¡±¡¢¡°IRSÄÉ˰ÈË֪ͨ¡±µÈÖ÷Ìâ½øÐÐÚ¿Æ­¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/irs-warns-of-60-percent-surge-in-email-phishing-scams-during-2018-524126.shtml


3¡¢³¯ÏÊAPT¹¥»÷»î¶¯STOLEN PENCIL£¬£¬£¬£¬£¬ÖØÒª¶Ô׼ѧÊõ»ú¹¹

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝNETSCOUTµÄ×îÐÂ×êÑУ¬£¬£¬£¬£¬×Ô2018Äê5ÔÂÒÔÀ´Ò»¸öеÄAPT¹¥»÷»î¶¯STOLEN PENCILÖØÒªÕë¶ÔѧÊõ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯¿ÉÄÜÀ´×ÔÓÚ³¯ÏÊ£¬£¬£¬£¬£¬Æä³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹µöÓʼþ£¬£¬£¬£¬£¬²¢ÓÕʹÓû§×°ÖöñÒâµÄChrome²å¼þ¡£¡£¡£¡£¡£¡£¡£¡£ºÜ¶à·ÖÆç´óѧµÄÊܺ¦Õß¶¼ÊÇÉúÎ﹤³ÌרҵµÄ£¬£¬£¬£¬£¬Õâ¿ÉÄܽ²ÁËÈ»¹¥»÷Õߵ͝»ú¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÄÚÖõÄWindowsÖÎÀí¹¤¾ßºÍÏֳɵÄóÒ×Èí¼þÀ´ÌӱܹéÒò£¬£¬£¬£¬£¬²¢ÇÒʹÓÃRDPÀ´½Ó¼ûÊÜϰȾµÄϵͳ£¬£¬£¬£¬£¬¶ø²»ÊǺóÃźÍRAT¡£¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÖ¤¾ÝÅú×¢º±¼û¾Ý±»ÇÔ£¬£¬£¬£¬£¬Ê¹µÃSTOLEN PENCILµÄ¶¯»ú»¹²»¼«¶ÈÃ÷È·¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/


4¡¢½©Ê¬ÍøÂçϰȾ³¬¹ý2Íò¸öWordPressÍøÕ¾£¬£¬£¬£¬£¬C2·þÎñÆ÷ÓëHostSailorÓйØ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝDefiantµÄÐÂ×êÑл㱨£¬£¬£¬£¬£¬Ò»¸öÓɳ¬¹ý2Íò¸öWordPressÍøÕ¾×é³ÉµÄ½©Ê¬ÍøÂçÕý±»ÓÃÓÚ¹¥»÷ºÍϰȾÆäËüµÄWordPressÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç»á¶ÔÆäËüWordPressÍøÕ¾½øÐб©Á¦ÆÆ½â¹¥»÷£¬£¬£¬£¬£¬Ö±µ½·¢ÏÖÓÐЧµÄÓû§ÕË»§¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ±¬ÆÆ¹¥»÷Õë¶ÔWordPressµÄXML-RPCʵÏÖ£¬£¬£¬£¬£¬ÓÉÓÚXML-RPCĬÈϲ»»á¶ÔAPIÒªÇóµÄËٶȽøÐÐÏÞ¶È£¬£¬£¬£¬£¬Òò¶ø¹¥»÷ÕßÄܹ»Ò»Ïò½øÐг¢ÊÔ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçʹÓÃÁË4¸öC2·þÎñÆ÷£¬£¬£¬£¬£¬ÕâЩC2ͨ¹ý¶íÂÞ˹Best-Proxies.ruµÄ´úÀí·þÎñÆ÷·¢³öÖ¸Áî¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒ»¹²Ê¹ÓÃÁË1.4Íò¶à¸ö´úÀí·þÎñÆ÷À´ÒþÄäC2·þÎñÆ÷µÄµØÎ»£¬£¬£¬£¬£¬ÆäÖÐÈý¸öC2·þÎñÆ÷ÓëHostSailor¹«Ë¾Óйء£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.wordfence.com/blog/2018/12/wordpress-botnet-attacking-wordpress/


5¡¢ÎÚ¿ËÀ¼SBUÔð¹Ö¶íÂÞ˹µý±¨»ú¹¹¹¥»÷¸Ã¹ú˾·¨ÏµÍ³

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÎÚ¿ËÀ¼SBUÐû³Æ×èÖ¹Á˶íÂÞ˹µý±¨»ú¹¹ÌáÒéµÄÕë¶Ô¸Ã¹ú˾·¨²¿ÃÅITϵͳµÄÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÓã²æÊ½ÍøÂç´¹µö¹¥»÷·Ö·¢¶ñÒâµÄ¹ÜÕÊÎĵµ£¬£¬£¬£¬£¬ÕâЩÎĵµÖÐÔ̺¬ÓÃÓÚÇÔÈ¡Êý¾ÝºÍ·ÛËé˾·¨ÏµÍ³µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼°²È«×¨¼Ò·¢Ïָù¥»÷»î¶¯ÖеÄC&C»ù´¡ÉèʩʹÓÃÁ˶íÂÞ˹µÄIPµØÖ·¡£¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼SSIPºÍ¹ú¶È˾·¨ÐÐÕþ²¿ÃŹ²Í¬×èÖ¹Á˸ù¥»÷¡£¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78726/cyber-warfare-2/sbu-russia-cyber-attack.html


6¡¢ESET·¢ÏÖ21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬¾ùΪOpenSSHºóÃÅľÂí

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚÒ»·Ý³¤´ï53Ò³µÄ»ã±¨ÖУ¬£¬£¬£¬£¬ESET¾ßÌå½éÉÜÁË21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬ÕâЩ¶ñÒâÈí¼þ¶¼ÊÇOpenSSH¿Í»§¶ËµÄľÂí»¯°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐһЩ¶ñÒâÈí¼þ¼«¶Èµ¥Ò»£¬£¬£¬£¬£¬µ«Ò²ÓÐһЩ¼«¶È¸´ÔÓ£¬£¬£¬£¬£¬¿ÉÄÜÀ´×ÔÓÚÓо­ÑéµÄ¶ñÒâÈí¼þ¿ª·¢ÈËÔ±¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ¶¼Êǵڶþ½×¶Î¹¤¾ß£¬£¬£¬£¬£¬Äܹ»²¿ÊðÔÚ¸ü¸´ÔӵĽ©Ê¬ÍøÂç»î¶¯ÖУ¬£¬£¬£¬£¬ÓÃÀ´´úÌæÕý³£µÄOpenSSH°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ESET°µÊ¾ÆäÖÐ18¸ö¼Ò×å¶¼ÓµÓÐÍ´´¦ÇÔȡְÄÜ£¬£¬£¬£¬£¬²¢ÇÒ17¸ö¼Ò×åÓµÓкóÃÅģʽ£¬£¬£¬£¬£¬¿ÉÔÊÐíÒþÄäµÄ¶ñÒâÏνӡ£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÖÐÔ̺¬ÁËÕâЩ¶ñÒâÈí¼þµÄIoCÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù