2018ÄêIoT¹¥»÷Ôö³¤217.5£¥£»¼äµýÈí¼þExodus£»ÒøÐÐľÂíAnubisϰȾ300¶à¼Ò½ðÈÚ»ú¹¹
°ä²¼¹¦·ò 2019-04-01
¡ª άËûÃüÖðÈÕ°²È«¼òѶ ¡ª
1.ÄáÈÕÀûÑǹúÃñÒé»áNASS¹ÙÍø±»Ö²Èë´¹µö´úÂë
MalwareHunterTeam×êÑÐÍŶӷ¢ÏÖÄáÈÕÀûÑǹúÃñÒé»á£¨NASS£©¹ÙÍøÉÏÍйÜÁËÒ»¸ö¼Ù×°³É¹ú¼Ê¿ìµÝ·þÎñDHLµÄ´¹µöÒ³Ãæ£¬¸ÃÒ³ÃæÖÁÉÙ´æÔÚÁËÁ½ÖܵŦ·ò£¬ÖØÒªÇÔÈ¡Óû§µÄDHLÕË»§Í´´¦¡£Õâ¸ö´¹µöÒ³Ãæu.php´æÔÚÓÚ¶à¸ö±»ÉøÈëµÄºÏ·¨ÍøÕ¾ÉÏ£¬Ô̺¬onlinequranglobal[.]com¡¢pioneer-sys[.]netµÈ¡£×êÑÐÍŶӻ¹³ÆNASSµÄ¹ÙÍøÖ®Ç°¾ÍÔøÍйܹý¶à¸ö¶ñÒâÕ¾µã¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ironically-phishing-kit-hosted-on-nigerian-government-site/
2.GOG Galaxy¶à¸ö·ì϶£¬¿Éµ¼ÖÂÌáȨ¡¢ÐÅϢй¶¼°DoS
˼¿ÆTalosÅû¶GOG GalaxyÖеĶà¸ö°²È«·ì϶£¬GOG GalaxyÊÇÒ»¸öÊ¢ÐеÄÓÎϷƽ̨£¬×êÑÐÈËÔ±ÔÚÆä¿Í»§¶Ë°æ±¾1.2.48.36Öз¢ÏÖ6¸ö·ì϶£¬Ô̺¬4¸öÌáȨ·ì϶£¨CVE-2018-4048~CVE-2018-4051£©¡¢1¸öÐÅϢй¶·ì϶£¨CVE-2018-4052£©ºÍ1¸ö¿Éµ¼ÖÂDoSµÄ·ì϶£¨CVE-2018-4053£©¡£ËùÓзì϶¶¼ÒÑÔÚ×îа汾µÄGOG GalaxyÖеõ½½¨¸´£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/gog-galaxy-riddled-with-multilple-security-vulnerabilities-859d95fd
3.SonicWallл㱨³Æ2018ÄêIoT¹¥»÷Ôö³¤217.5£¥
ƾ¾ÝSonicWallµÄÄê¶ÈÍøÂçÍþв»ã±¨£¨2019°æ£©£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬±È2017ÄêµÄ1030Íò´ÎÔö³¤ÁË217.5£¥¡£ÕâÒ»Ôö³¤µÄÔÒòÊÇIoTÉ豸Ôì×÷ÉÌδÄÜÖ´ÐÐÊʵ±µÄ°²È«½ÚÔ졣ȫÇò³¬¹ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØÖ·Ô´ÓÚÃÀ¹ú£¬Æä´ÎÊÇÖйú£¨13%£©¡£´Ë±í£¬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´Î´¹µö¹¥»÷£¬±È2017Äê½µÂä4.1£¥¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/
4.Google PlayÖз¢ÏÖмäµýÈí¼þExodus£¬ÖØÒªÕë¶ÔÒâ´óÀû
×êÑÐÈËÔ±ÔÚGoogle Play StoreÖз¢ÏÖÒ»¸ö¼äµýÈí¼þExodus¡£Exodus¼Ù×°³ÉÒâ´óÀûÒÆ¶¯Í¨Ñ¶É̵ĴÙÏú/ÓªÏúAPP»òÊÖ»ú»úÄÜÓÅ»¯¹¤¾ß£¬ÖØÒªÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬Ô̺¬¹àÒô¡¢µç»°¡¢ä¯ÀÀº¹Çà¡¢ÈÕÀú¡¢µØÀíµØÎ»¡¢Facebook MessengerÈÕÖ¾¡¢WhatsApp̸ÌìÐÅÏ¢ºÍ¶ÌÐŵȡ£Exodus»¹»áÔÚÊÜϰȾµÄÉ豸ÉÏ´´½¨Ò»¸öshellºóÃÅ¡£Exodusͨ¹ýCheckValidTargetÖ°ÄܶÔ×¼ÌØ¶¨µÄÒâ´óÀûÓû§£¬µ«×êÑÐÈËÔ±³Æ¸ÃÖ°Äܲ»ÄÜÕý³£¹¤×÷£¬Òò¶øÆäËûÓû§Ò²»áÊܵ½ÇÖº¦¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/83102/breaking-news/exodus-malware-google-play.html
5.ÒøÐÐľÂíAnubis£¬×Ô2017ÄêÀ´ÒÑϰȾ300¶à¼Ò½ðÈÚ»ú¹¹
AndroidÒøÐÐľÂíAnubisÖØÒªÍ¨¹ýGoogle Play Store·Ö·¢£¬×Ô2017ÄêÒÔÀ´£¬AnubisÒѾϰȾÁËÈ«Çò³¬¹ý300¼Ò½ðÈÚ»ú¹¹¡£Anubisͨ³£¼Ù×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊµÓÃÓ×¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍ̸ÌìAPPµÈ£¬ÆäÖØÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£2019Äê3Ô£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67
6.΢ÈíÊÕÊÜÒÁÀÊPhosphorus APTµÄ99¸ö¹¥»÷ÓòÃû
΢Èí°ä·¢Òѳɹ¦ÊÕÊÜÒÁÀÊPhosphorus APT£¨ÓÖ³ÆAPT35£©ËùʹÓõÄ99¸ö¹¥»÷ÓòÃû¡£Æ¾¾ÝÓйØÎļþ£¬Î¢ÈíÏòÃÀ¹ú´¦Ëù·¨ÔºÌá³öÉêÊö£¬³ÆÕâЩÓòÃûÓë¸ÃAPT×éÖ¯µÄ·¸·¨ÈëÇֻÓйء£ÔÚ·¨ÔººÅÁîµÄÊÚȨÏ£¬Î¢ÈíÊÕÊÜÁËÕâЩ¹¥»÷ÓòÃû²¢½«À´×ÔÊÜϰȾÉ豸µÄÁ÷Á¿³Á¶¨ÏòÖÁsinkhole¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/83128/apt/phosphorus-apt-seized-domains.html


¾©¹«Íø°²±¸11010802024551ºÅ