¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190308
°ä²¼¹¦·ò 2019-03-08
ÔÎÄÁ´½Ó£º
https://securelist.com/financial-cyberthreats-in-2018/89788/2¡¢ÐÂÍøÂç¼äµý×éÖ¯Whitefly£¬£¬£¬£¬£¬£¬ÓëÐÂ¼ÓÆÂ¶à¸ö¹¥»÷»î¶¯ÓйØ
ÔÎÄÁ´½Ó£º
https://www.symantec.com/blogs/threat-intelligence/whitefly-espionage-singapore3¡¢×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý
Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þTroldesh£¨±ðÃûShade£©ÔÚ2018ÄêQ4µ½2019ÄêQ1ÆÚ¼äµÄ¼ì²âÊýÁ¿¼±¾çÔö³¤¡£¡£¡£¡£¡£¡£¡£Shadeͨ³£Í¨¹ý´¹µöÓʼþ½øÐд«²¼£¬£¬£¬£¬£¬£¬Æä¸½¼þÊÇÔ̺¬Javascript¾ç±¾µÄzipÎļþ¡£¡£¡£¡£¡£¡£¡£ShadeµÄÖØÒª¹¥»÷Ö¸±êÊÇWindowsϵͳ£¬£¬£¬£¬£¬£¬ÆäѡȡAES 256 CBCËã·¨½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£²¿ÃÅShadeµÄ±äÖÖ´æÔÚÃâ·ÑµÄ½âÃܹ¤¾ß£¬£¬£¬£¬£¬£¬Óû§¿ÉÔÚNoMoreRansom.orgÍøÕ¾ÉÏÕÒµ½ËüÃÇ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/4¡¢×êÑÐÍŶӷ¢ÏÖÊ׸öÀûÓÃSlack API½øÐÐͨѶµÄSLUBºóÃÅ
Ç÷Ïò¿Æ¼¼×êÑÐÍŶӷ¢ÏÖÊ׸öÀûÓÃSlack APIͨѶµÄ¶ñÒâÈí¼þSLUBºóÃÅ¡£¡£¡£¡£¡£¡£¡£SLUBÊÇÒ»¸öÓÃC++±àдµÄ×Ô½ç˵ºóÃÅ£¬£¬£¬£¬£¬£¬ÆäÔ̺¬¾²Ì¬Á´½Ó¿âcurl£¨ÓÃÓÚÖ´ÐÐHTTPÒªÇ󣩡¢boost£¨ÓÃÓÚ´ÓgistƬ¶ÎÖÐÌáÈ¡ºÅÁºÍJsonCpp£¨ÓÃÓÚ½âÎöslackͨѶ£©¡£¡£¡£¡£¡£¡£¡£¸ÃºóÃÅͨ¹ýË®¿Ó¹¥»÷´«²¼£¬£¬£¬£¬£¬£¬²¢ÇÒÀûÓÃÁË΢ÈíÔÚ2018Äê5Ô½¨¸´µÄVBScriptÒýÇæ·ì϶£¨CVE-2018-8174£©½øÐÐϰȾ¡£¡£¡£¡£¡£¡£¡£¸ÃºóÃÅ»¹»á´ÓGithub¸ßµÍÔØÒ»¸öÌØ¶¨µÄgistƬ¶Î²¢ÌáÈ¡ÓйغÅÁî¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/new-slub-backdoor-uses-github-communicates-via-slack/5¡¢ÐÂľÂíPirate Matryoshka£¬£¬£¬£¬£¬£¬ÀûÓú£µÁÍå½øÐзַ¢

¿¨°Í˹»ù×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓú£µÁÍå·Ö·¢ÐÂľÂíPirate Matryoshka¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí¼Ù×°³ÉÆÆ½âÈí¼þµÄ×°ÖÃÎļþ£¬£¬£¬£¬£¬£¬µ±Óû§ÔËÐиÃÎļþʱ£¬£¬£¬£¬£¬£¬½«»áÏÔʾһ¸öαÔìµÄº£µÁÍåµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£¡£¡£Ò»µ©Óû§ÊäÈëÕË»§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻá½Ù³ÖÓû§µÄÕË»§²¢ÉÏ´«¸ü¶àµÄ¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×°ÖÃÎļþ»¹Ä¬Èϰó¸¿ÁËÆäËüÈí¼þ£¬£¬£¬£¬£¬£¬ÆäÖÐÎå·ÖÖ®Ò»ÊǸæ°×Èí¼þ¡¢½Ù³Öä¯ÀÀÆ÷Ö÷Ò³µÄ¶ñÒâÈí¼þÒÔ¼°Ä¾ÂíµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/pirate-matryoshka-malware/25905/6¡¢Ë¼¿Æ½¨¸´Nexus»¥»»»úÖеĶþÊ®¶à¸ö°²È«·ì϶
˼¿Æ±¾Öܽ¨¸´ÁËNexus»¥»»»úÖеĶþÊ®¶à¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬·ì϶ÁìÓòÔ̺¬DoS¡¢ËÁÒâ´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ӰÏìÁËTetration Analytics´úÀí¡¢LDAP¡¢Óû§ÕÊ»§ÖÎÀí½çÃæ¡¢ºÅÁîÐнçÃæ£¨CLI£©µÈ×é¼þ£¬£¬£¬£¬£¬£¬¶à¸ö·ì϶¿ÉÔÊÐí±¾µØ¹¥»÷Õß½øÐÐÌáȨ¡¢ÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡¢×°ÖöñÒâÈí¼þ¡¢»ñÈ¡³ÁÒªÅäÖÃÎļþµÄ½Ó¼ûȨÏÞ»ò½øÐÐÊÜÏÞshellÌÓÒÝ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Ë¼¿Æ»¹½¨ÒéÓû§²ÉÈ¡´ëÊ©±£»£»£»£»£»£»£»£»¤²¿ÊðÁËPOAPµÄÍøÂç»ò½ûÓøÃÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/82120/breaking-news/cisco-nexus-flaws-2.htmlÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ