¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181207

°ä²¼¹¦·ò 2018-12-07
1¡¢ÃÀDHSºÍFBI½áºÏ°ä²¼Õë¶ÔÀÕË÷Èí¼þSamSamµÄÍþв¾¯±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úDHSÏÂÊô¹ú¶ÈÍøÂ簲ȫºÍͨѶ¼¯³ÉÖÐÐÄ£¨NCCIC£©½áºÏFBI¹²Í¬°ä²¼ÀÕË÷Èí¼þSamSamжñÒâ»î¶¯µÄ¾¯±¨¡£SamSamÖØÒªÕë¶ÔÃÀ¹ú£¬¶Ô×¼¶à¸öÐÐÒµ£¬Ô̺¬Ò»Ð©¹Ø¼ü»ù´¡ÉèÊ©¡£¹¥»÷ÕßÖØÒªÕë¶ÔWindows·þÎñÆ÷£¬Æ¾¾ÝFBIµÄ·ÖÎö£¬×Ô2016ÄêÄêÖÐÒÔÀ´£¬¹¥»÷Õßͨ¹ýRDPºÍ̸ÈëÇÖÊܺ¦ÕßµÄÍøÂ硣ͨ³£Çé¿öϹ¥»÷ÕßʹÓñ©Á¦ÆÆ½â¹¥»÷»ò±»µÁÍ´´¦½øÐÐÈëÇÖ£¬µ«FBIµÄ·ÖÎöÅú×¢¹¥»÷Õß»¹´Ó°µÍøÊг¡ÉϲɰìÁËһЩ±»µÁµÄRDPÍ´´¦¡£DHSºÍFBI½¨ÒéÓû§ºÍÖÎÀíÔ±Ìáǰ²ÉÈ¡°²È«´ëÊ©À´Ô¤·À¸Ã¹¥»÷¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/alerts/AA18-337A


2¡¢ÃÀIRS³Æ2018ÄêÍøÂç´¹µö¹¥»÷ÊýÁ¿Ôö³¤³¬¹ý60%

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ƾ¾ÝÃÀ¹ú¹ú˰¾Ö£¨IRS£©µÄ˵·¨£¬¹ÌÈ»2015Äê¡¢2016ÄêºÍ2017ÄêµÄÍøÂç´¹µö¹¥»÷ÊýÁ¿³Ê½µÂäÇ÷Ïò£¬µ«ÔÚ2018ÄêIRS¹Û²ìµ½ÍøÂç´¹µöÚ¿Æ­ÊýÁ¿Ôö³¤³¬¹ý60%£¬´Ó2017ÄêµÄÔ¼1200Æð´ËÀàÊÂÎñÔö³¤µ½2018Äê1ÔÂÖÁ10Ôµij¬¹ý2000Æð¡£IRS°µÊ¾Ú¿Æ­Õßͨ¹ý¶ÔÄÉ˰È˽øÐÐÍøÂç´¹µö¹¥»÷£¬ÊÔͼÇÔÈ¡ËûÃǵÄ×ʽðºÍ˰ÎñÊý¾Ý¡£×î½üµÄ¶ñÒâ»î¶¯¾ÍʹÓÃÁËÖîÈç¡°IRS³ÁҪ֪ͨ¡±¡¢¡°IRSÄÉ˰ÈË֪ͨ¡±µÈÖ÷Ìâ½øÐÐÚ¿Æ­¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/irs-warns-of-60-percent-surge-in-email-phishing-scams-during-2018-524126.shtml


3¡¢³¯ÏÊAPT¹¥»÷»î¶¯STOLEN PENCIL£¬ÖØÒª¶Ô׼ѧÊõ»ú¹¹

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝNETSCOUTµÄ×îÐÂ×êÑУ¬×Ô2018Äê5ÔÂÒÔÀ´Ò»¸öеÄAPT¹¥»÷»î¶¯STOLEN PENCILÖØÒªÕë¶ÔѧÊõ»ú¹¹¡£¸Ã¹¥»÷»î¶¯¿ÉÄÜÀ´×ÔÓÚ³¯ÏÊ£¬Æä³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹µöÓʼþ£¬²¢ÓÕʹÓû§×°ÖöñÒâµÄChrome²å¼þ¡£ºÜ¶à·ÖÆç´óѧµÄÊܺ¦Õß¶¼ÊÇÉúÎ﹤³ÌרҵµÄ£¬Õâ¿ÉÄܽ²ÁËÈ»¹¥»÷Õߵ͝»ú¡£¹¥»÷ÕßʹÓÃÄÚÖõÄWindowsÖÎÀí¹¤¾ßºÍÏֳɵÄóÒ×Èí¼þÀ´ÌӱܹéÒò£¬²¢ÇÒʹÓÃRDPÀ´½Ó¼ûÊÜϰȾµÄϵͳ£¬¶ø²»ÊǺóÃźÍRAT¡£Ã»ÓÐÖ¤¾ÝÅú×¢º±¼û¾Ý±»ÇÔ£¬Ê¹µÃSTOLEN PENCILµÄ¶¯»ú»¹²»¼«¶ÈÃ÷È·¡£

  

Ô­ÎÄÁ´½Ó£º

https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/


4¡¢½©Ê¬ÍøÂçϰȾ³¬¹ý2Íò¸öWordPressÍøÕ¾£¬C2·þÎñÆ÷ÓëHostSailorÓйØ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝDefiantµÄÐÂ×êÑл㱨£¬Ò»¸öÓɳ¬¹ý2Íò¸öWordPressÍøÕ¾×é³ÉµÄ½©Ê¬ÍøÂçÕý±»ÓÃÓÚ¹¥»÷ºÍϰȾÆäËüµÄWordPressÍøÕ¾¡£¸Ã½©Ê¬ÍøÂç»á¶ÔÆäËüWordPressÍøÕ¾½øÐб©Á¦ÆÆ½â¹¥»÷£¬Ö±µ½·¢ÏÖÓÐЧµÄÓû§ÕË»§¡£ÕâÖÖ±¬ÆÆ¹¥»÷Õë¶ÔWordPressµÄXML-RPCʵÏÖ£¬ÓÉÓÚXML-RPCĬÈϲ»»á¶ÔAPIÒªÇóµÄ¿ìÂʽøÐÐÏÞ¶È£¬Òò¶ø¹¥»÷ÕßÄܹ»Ò»Ïò½øÐг¢ÊÔ¡£¸Ã½©Ê¬ÍøÂçʹÓÃÁË4¸öC2·þÎñÆ÷£¬ÕâЩC2ͨ¹ý¶íÂÞ˹Best-Proxies.ruµÄ´úÀí·þÎñÆ÷·¢³öÖ¸Áî¡£¹¥»÷ÕßÒ»¹²Ê¹ÓÃÁË1.4Íò¶à¸ö´úÀí·þÎñÆ÷À´ÒþÄäC2·þÎñÆ÷µÄµØÎ»£¬ÆäÖÐÈý¸öC2·þÎñÆ÷ÓëHostSailor¹«Ë¾ÓйØ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.wordfence.com/blog/2018/12/wordpress-botnet-attacking-wordpress/


5¡¢ÎÚ¿ËÀ¼SBUÔð¹Ö¶íÂÞ˹µý±¨»ú¹¹¹¥»÷¸Ã¹ú˾·¨ÏµÍ³

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÚ¿ËÀ¼SBUÐû³Æ×èÖ¹Á˶íÂÞ˹µý±¨»ú¹¹ÌáÒéµÄÕë¶Ô¸Ã¹ú˾·¨²¿ÃÅITϵͳµÄÍøÂç¹¥»÷»î¶¯¡£¹¥»÷Õßͨ¹ýÓã²æÊ½ÍøÂç´¹µö¹¥»÷·Ö·¢¶ñÒâµÄ¹ÜÕÊÎĵµ£¬ÕâЩÎĵµÖÐÔ̺¬ÓÃÓÚÇÔÈ¡Êý¾ÝºÍ·ÛËé˾·¨ÏµÍ³µÄ¶ñÒâÈí¼þ¡£ÎÚ¿ËÀ¼°²È«×¨¼Ò·¢Ïָù¥»÷»î¶¯ÖеÄC&C»ù´¡ÉèʩʹÓÃÁ˶íÂÞ˹µÄIPµØÖ·¡£ÎÚ¿ËÀ¼SSIPºÍ¹ú¶È˾·¨ÐÐÕþ²¿ÃŹ²Í¬×èÖ¹Á˸ù¥»÷¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78726/cyber-warfare-2/sbu-russia-cyber-attack.html


6¡¢ESET·¢ÏÖ21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬¾ùΪOpenSSHºóÃÅľÂí

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÒ»·Ý³¤´ï53Ò³µÄ»ã±¨ÖУ¬ESET¾ßÌå½éÉÜÁË21¸öÐÂLinux¶ñÒâÈí¼þ¼Ò×壬ÕâЩ¶ñÒâÈí¼þ¶¼ÊÇOpenSSH¿Í»§¶ËµÄľÂí»¯°æ±¾¡£ÆäÖÐһЩ¶ñÒâÈí¼þ¼«¶Èµ¥Ò»£¬µ«Ò²ÓÐһЩ¼«¶È¸´ÔÓ£¬¿ÉÄÜÀ´×ÔÓÚÓо­ÑéµÄ¶ñÒâÈí¼þ¿ª·¢ÈËÔ±¡£ÕâЩ¶ñÒâÈí¼þ¶¼Êǵڶþ½×¶Î¹¤¾ß£¬Äܹ»²¿ÊðÔÚ¸ü¸´ÔӵĽ©Ê¬ÍøÂç»î¶¯ÖУ¬ÓÃÀ´´úÌæÕý³£µÄOpenSSH°æ±¾¡£ESET°µÊ¾ÆäÖÐ18¸ö¼Ò×å¶¼ÓµÓÐÍ´´¦ÇÔȡְÄÜ£¬²¢ÇÒ17¸ö¼Ò×åÓµÓкóÃÅģʽ£¬¿ÉÔÊÐíÒþÄäµÄ¶ñÒâÏνÓ¡£»ã±¨ÖÐÔ̺¬ÁËÕâЩ¶ñÒâÈí¼þµÄIoCÖ¸±ê¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù