¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190131
°ä²¼¹¦·ò 2019-01-31
°²È«×êÑÐÔ±Oliver Hough·¢ÏÖÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearch·þÎñÆ÷δÊÜÃÜÂë±£»¤£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬Ô̺¬ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍ¹¤×÷°¸Àý¡£Æ¾¾Ý¹¦·ò´Á£¬ÕâЩÊý¾Ý¿É×·ÒäÖÁ2018Äê10Ô¡£¾¹ýµ÷²é£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓɱ¨´ðÃýÎóµ¼Öµġ£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/2¡¢Å·ÖÞ·¨ÂÉ»ú¹¹ÔÚµ÷²éʹÓùýwebstresser.orgµÄÓû§
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80435/cyber-crime/europol-ddos-for-hire.html3¡¢ÒÁÀÊAPT39жñÒâ»î¶¯£¬ÖØÒªÕë¶ÔÖж«µçÐÅÐÐÒµ

FireEye°ä²¼¹ØÓÚÒÁÀÊAPT39жñÒâ»î¶¯µÄ·ÖÎö»ã±¨¡£ÓëÆäËüÒÁÀÊAPT×éÖ¯·ÖÆçµÄÊÇ£¬APT39¸ü²à³ÁÓÚÇÔÈ¡Ó×ÎÒÐÅÏ¢£¬ÒÔ±ãΪÒÁÀÊµÄ¼à¿Ø¡¢¸ú×ٺͼල»î¶¯Ìṩ֧³Ö¡£¹ÌÈ»APT39µÄÖ¸±ê±é²¼È«Çò£¬µ«Æä»î¶¯ÖØÒª¼¯ÖÐÔÚÖж«µØÓò£¬²¢ÇÒÓÅÏÈÕë¶ÔµçÐÅÐÐÒµ£¬´Ë±í£¬Ò²¶Ô×¼ÓÎÀÀÒµºÍIT¹«Ë¾¡£APT39ÖØÒªÊ¹ÓÃSEAWEEDºÍCACHEMONEYºóÃÅÒÔ¼°POWBATºóÃÅ¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html4¡¢Altran Technologies¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷
·¨¹ú¹¤³ÌÕ÷ѯ¹«Ë¾Altran TechnologiesÔâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷£¬ÆäÔÚһЩŷÖÞ¹ú¶ÈµÄÔËÓª»î¶¯Êܵ½Ó°Ï졣ΪÁ˱£»¤¿Í»§µÄÊý¾ÝºÍ×ʲú£¬Altranһʱ¹Ø¹ØÁËÍøÂçºÍÀûÓ÷¨Ê½¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ1ÔÂ24ÈÕ£¬µ«¸Ã¹«Ë¾²¢Ã»ÓÐÅû¶ÓйØÏ¸½Ú£¬²¢³ÆÊÂÎñ»¹ÔÚµ÷²éÖ®ÖС£Æ¾¾ÝÉÏ´«µ½VirusTotalµÄ¶ñÒâÑù±¾£¬LockerGoga»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lockedÀ©´óÃû¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/altran-technologies-hit-by-lockergoga-ransomware-attack-e1f905705¡¢ÀÕË÷Èí¼þJobCrypterбäÖÖ£¬¿É½ØÈ¡ÆÁÄ»ÐÅÏ¢
Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þJobCrypterµÄÒ»¸öбäÖÖ£¬¸Ã±äÖÖÓµÓжî±íµÄ¼ÓÃܲãºÍ¸ü³¤µÄÃÜÔ¿£¬»¹Äܹ»Í¨¹ýSMTP½«Ö¸±êÉ豸µÄÆÁÄ»½ØÍ¼·¢ËÍÖÁÖ¸¶¨µÄµç×ÓÓÊÏä¡£¸Ã±äÖÖ»áÏȽ«Îļþ½øÐÐBase64±àÂ룬¶øºóʹÓÃTriple DESËã·¨½øÐмÓÃÜ£¬×îºóÔÙ½øÐÐÒ»´ÎBase64±àÂ룬ÃÜÔ¿ÓÉ67λÊý×Ö×é³É¡£¸Ã±äÖÖÒªÇóÊÜϰȾµÄÓû§ÔÚ24Ó×ʱÄÚÖ§¸¶1000Å·ÔªµÄÊê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.scmagazineuk.com/new-jobcrypter-ransomware-variant-captures-screenshots-infected-devices/article/15241996¡¢Î÷ÃÅ×Ó½¨¸´S7-1500 PLCÖеÄÁ½¸öDoS·ì϶
Î÷ÃÅ×Ó½¨¸´Simatic S7-1500¿É±à³ÌÂß¼½ÚÔìÆ÷£¨PLC£©ÖеÄÁ½¸ö¿Éµ¼ÖÂDoSµÄ°²È«·ì϶¡£ÕâÁ½¸ö·ì϶£¨CVE-2018-16558ºÍCVE-2018-16559£©ÊÇÓÉPositive TechnologiesµÄ×êÑÐÈËÔ±·¢Ïֵ쬯äCVSS v3.0µÃ·Ö¾ùΪ7.5¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòTCP¶Ë¿Ú80»ò443·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢·ì϶¡£Î÷ÃÅ×ÓÔÚSimatic S7-1500¹Ì¼þ°æ±¾2.5Öн¨¸´ÁËÕâЩ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://cert-portal.siemens.com/productcert/pdf/ssa-180635.pdfÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ