¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190308
°ä²¼¹¦·ò 2019-03-08
ÔÎÄÁ´½Ó£º
https://securelist.com/financial-cyberthreats-in-2018/89788/2¡¢ÐÂÍøÂç¼äµý×éÖ¯Whitefly£¬ÓëÐÂ¼ÓÆÂ¶à¸ö¹¥»÷»î¶¯ÓйØ
ÔÎÄÁ´½Ó£º
https://www.symantec.com/blogs/threat-intelligence/whitefly-espionage-singapore3¡¢×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý
Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þTroldesh£¨±ðÃûShade£©ÔÚ2018ÄêQ4µ½2019ÄêQ1ÆÚ¼äµÄ¼ì²âÊýÁ¿¼±¾çÔö³¤¡£Shadeͨ³£Í¨¹ý´¹µöÓʼþ½øÐд«²¼£¬Æä¸½¼þÊÇÔ̺¬Javascript¾ç±¾µÄzipÎļþ¡£ShadeµÄÖØÒª¹¥»÷Ö¸±êÊÇWindowsϵͳ£¬ÆäѡȡAES 256 CBCËã·¨½øÐмÓÃÜ¡£²¿ÃÅShadeµÄ±äÖÖ´æÔÚÃâ·ÑµÄ½âÃܹ¤¾ß£¬Óû§¿ÉÔÚNoMoreRansom.orgÍøÕ¾ÉÏÕÒµ½ËüÃÇ¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/4¡¢×êÑÐÍŶӷ¢ÏÖÊ׸öÀûÓÃSlack API½øÐÐͨѶµÄSLUBºóÃÅ
Ç÷Ïò¿Æ¼¼×êÑÐÍŶӷ¢ÏÖÊ׸öÀûÓÃSlack APIͨѶµÄ¶ñÒâÈí¼þSLUBºóÃÅ¡£SLUBÊÇÒ»¸öÓÃC++±àдµÄ×Ô½ç˵ºóÃÅ£¬ÆäÔ̺¬¾²Ì¬Á´½Ó¿âcurl£¨ÓÃÓÚÖ´ÐÐHTTPÒªÇ󣩡¢boost£¨ÓÃÓÚ´ÓgistƬ¶ÎÖÐÌáÈ¡ºÅÁºÍJsonCpp£¨ÓÃÓÚ½âÎöslackͨѶ£©¡£¸ÃºóÃÅͨ¹ýË®¿Ó¹¥»÷´«²¼£¬²¢ÇÒÀûÓÃÁË΢ÈíÔÚ2018Äê5Ô½¨¸´µÄVBScriptÒýÇæ·ì϶£¨CVE-2018-8174£©½øÐÐϰȾ¡£¸ÃºóÃÅ»¹»á´ÓGithub¸ßµÍÔØÒ»¸öÌØ¶¨µÄgistƬ¶Î²¢ÌáÈ¡ÓйغÅÁî¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/new-slub-backdoor-uses-github-communicates-via-slack/5¡¢ÐÂľÂíPirate Matryoshka£¬ÀûÓú£µÁÍå½øÐзַ¢

¿¨°Í˹»ù×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÀûÓú£µÁÍå·Ö·¢ÐÂľÂíPirate Matryoshka¡£¸ÃľÂí¼Ù×°³ÉÆÆ½âÈí¼þµÄ×°ÖÃÎļþ£¬µ±Óû§ÔËÐиÃÎļþʱ£¬½«»áÏÔʾһ¸öαÔìµÄº£µÁÍåµÇÂ¼Ò³Ãæ¡£Ò»µ©Óû§ÊäÈëÕË»§ÃûºÍÃÜÂ룬¹¥»÷Õ߾ͻá½Ù³ÖÓû§µÄÕË»§²¢ÉÏ´«¸ü¶àµÄ¶ñÒâÎļþ¡£´Ë±í£¬×°ÖÃÎļþ»¹Ä¬Èϰó¸¿ÁËÆäËüÈí¼þ£¬ÆäÖÐÎå·ÖÖ®Ò»ÊǸæ°×Èí¼þ¡¢½Ù³Öä¯ÀÀÆ÷Ö÷Ò³µÄ¶ñÒâÈí¼þÒÔ¼°Ä¾ÂíµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/pirate-matryoshka-malware/25905/6¡¢Ë¼¿Æ½¨¸´Nexus»¥»»»úÖеĶþÊ®¶à¸ö°²È«·ì϶
˼¿Æ±¾Öܽ¨¸´ÁËNexus»¥»»»úÖеĶþÊ®¶à¸ö°²È«·ì϶£¬·ì϶ÁìÓòÔ̺¬DoS¡¢ËÁÒâ´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¡£ÕâЩ·ì϶ӰÏìÁËTetration Analytics´úÀí¡¢LDAP¡¢Óû§ÕÊ»§ÖÎÀí½çÃæ¡¢ºÅÁîÐнçÃæ£¨CLI£©µÈ×é¼þ£¬¶à¸ö·ì϶¿ÉÔÊÐí±¾µØ¹¥»÷Õß½øÐÐÌáȨ¡¢ÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡¢×°ÖöñÒâÈí¼þ¡¢»ñÈ¡³ÁÒªÅäÖÃÎļþµÄ½Ó¼ûȨÏÞ»ò½øÐÐÊÜÏÞshellÌÓÒÝ¡£´Ë±í£¬Ë¼¿Æ»¹½¨ÒéÓû§²ÉÈ¡´ëÊ©±£»¤²¿ÊðÁËPOAPµÄÍøÂç»ò½ûÓøÃÖ°ÄÜ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/82120/breaking-news/cisco-nexus-flaws-2.htmlÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ