IBM½¨¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸ö·ì϶£»TA505ÐÂÀ¬»øÓʼþ»î¶¯£¬ÖØÒª·Ö·¢GelupºÍFlowerPippi
°ä²¼¹¦·ò 2019-07-05
IBM½¨¸´¶à¸öÊý¾Ý´æ´¢ºÍÖÎÀí¹¤¾ßÖеÄ7¸ö·ì϶£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Êý¾Ý·ÖÎö¹¤¾ßPlanning Analytics¡¢Êý¾Ý±£»¤Æ½Ì¨Security GuardiumºÍWebͼÏñ²é¿´Æ÷Daeja ViewONEµÈ¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇSpectrum ProtectÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2019-4087£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8·Ö¡£Æ¾¾ÝIBMµÄ±íÊö£¬Í¨¹ý·¢Ë͹ý³¤µÄÒªÇó£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜ»áÒç³ö»º³åÇø²¢ÔÚÓµÓÐÊ·ýIDȨÏÞµÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬»òµ¼Ö·þÎñÆ÷/´æ´¢´úÀí±ÀÀ£¡£¸Ã·ì϶ԴÓÚSpectrum ProtectÖеIJ»ÕýÈ·Ììǵ²é³£¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬7.1ºÍ8.1¡£ÁíÒ»¸öÑϳÁµÄ·ì϶ÊÇSecurity GuardiumÖеÄÎļþÉÏ´«·ì϶£¨CVE-2019-4292£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8·Ö£¬ÊÜÓ°ÏìµÄ°æ±¾Îª10.5¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/ibm-patches-critical-high-severity-flaws-in-spectrum-protect/146201/
2¡¢TA505ÐÂÀ¬»øÓʼþ»î¶¯£¬ÖØÒª·Ö·¢GelupºÍFlowerPippi
Ç÷Ïò¿Æ¼¼×êÑÐÍŶÓÔÚ6Ô·ݹ۲쵽TA505µÄ¶à¸ö¹¥»÷»î¶¯£¬ÕâЩ¹¥»÷»î¶¯ÖØÒªÕë¶Ô°¢ÁªÇõºÍÉ³ÌØ°¢À²®µÈÖж«¹ú¶ÈÒÔ¼°Ó¡¶È¡¢ÈÕ±¾¡¢°¢¸ùÍ¢¡¢·ÆÂɱöºÍº«¹úµÈÆäËü¹ú¶È¡£×êÑÐÍŶӼì²âµ½Ò»¸öеĶñÒâÈí¼þ¹¤¾ßGelup£¨Trojan.Win32.GELUP.A£©£¬Gelup¿ÉÈÆ¹ýUAC²¢¼ÓÔØÆäËüpayload£¬ÀýÈçFlawedAmmyy RAT¡£´Ë±í£¬TA505»¹Ê¹ÓÃÁËÁíÒ»¸ö¹¤¾ßFlowerPippi£¨Backdoor.Win32.FLOWERPIPPI.A£©£¬¸Ã¶ñÒâÈí¼þÊÇÒ»¸öеĺóÃźÍÏÂÔØÆ÷¡£
ÔÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/latest-spam-campaigns-from-ta505-now-using-new-malware-tools-gelup-and-flowerpippi/
3¡¢SodinokibiÐÂÑù±¾ÀûÓÃWindows·ì϶½øÐÐÌáȨ
¿¨°Í˹»ù°ä²¼¹ØÓÚÀÕË÷Èí¼þSodinokibiÐÂÑù±¾µÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±·¢ÏÖSodinokibiÀûÓÃWindowsÖеķì϶£¨CVE-2018-8453£©½øÐÐÌáȨ¡£Æ¾¾Ý¿¨°Í˹»ùµÄÒ£²âÊý¾Ý£¬¸ÃÀÕË÷Èí¼þµÄϰȾÊÂÎñ±é²¼È«Çò£¬ÆäÖдó²¿ÃÅλÓÚÑÇÌ«µØÓò£ºÖйų́Í壨17.56£¥£©¡¢ÖйúÏã¸ÛÒÔ¼°º«¹ú£¨8.78£¥£©¡£×êÑÐÈËÔ±»¹·¢ÏÖ¸ÃÀÕË÷Èí¼þÔÚ×¢²á±íÖд洢Á˹«Ô¿ºÍ¼ÓÃܵÄ˽Կ¡£¸ÃÀÕË÷Èí¼þ»¹»á¼ø±ð¼üÅ̲¼¾Ö£¬²¢ÔÚ¶íÂÞ˹¡¢ÎÚ¿ËÀ¼µÈ¹ú¶ÈµÄÍÆËã»úÉ϶ôÖÆÔËÐС£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-exploits-windows-bug-to-elevate-privileges/
4¡¢ÒøÐÐľÂíTrickbotÐÂÔöä¯ÀÀÆ÷CookieÇÔȡģ¿é
×êÑÐÈËÔ±Brad Duncan·¢ÏÖÒøÐÐľÂíTrickbotÐÂÔöÒ»¸öcookieÇÔȡģ¿é¡£¸ÃÄ£¿éÆëÈ«¶ÀÁ¢£¬²¢ÇÒ´øÓÐ×Ô¼ºµÄÅäÖÃÎļþ¡£ÁíÒ»Ãû×êÑÐÈËÔ±Vitali Kremez֤ʵÁ˸ÃÄ£¿é£¬²¢²¹³ä³ÆÐÂÄ£¿éµÄ¹¹½¨ÈÕÆÚÊÇ6ÔÂ27ÈÕ£¬ËüÄܹ»Õë¶ÔËùÓеÄÖØÒªWebä¯ÀÀÆ÷£¬Ô̺¬Chrome¡¢Firefox¡¢Internet ExplorerºÍMicrosoft Edge¡£Í¨¹ýÇÔÈ¡cookie£¬¹¥»÷ÕßÄܹ»»ñȡָ±êµÄÍøÕ¾µÇ¼״̬¡¢Æ«ºÃ¡¢¸öÐÔ»¯ÄÚÈÝ»ò¸ú×ÙÓû§µÈ¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/trickbot-trojan-updated-with-standalone-cookie-stealing-module-1831b2a8
5¡¢BianLianбäÖÖÔö³¤ÆÁϼÔìºÍ´´½¨SSH·þÎñÆ÷Ö°ÄÜ
FortiGuard Labs×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíBianLianµÄбäÖÖ£¬¸Ã±äÖÖÔ̺¬Á½¸öÐÂÄ£¿é£ºÆÁϼÔìºÍ´´½¨SSH·þÎñÆ÷¡£¸ÃбäÖÖÒÔAPKµÄ´ó¾Ö·Ö·¢£¬²¢¾¹ýÑϳÁ»ìºÏ£¬ÀýÈçÌìÉú¸÷ÀàËæ»úº¯ÊýÒÔ°µ²ØÄ¾ÂíµÄÕæÊµÖ°ÄÜ¡£×êÑÐÈËÔ±Ö¸³ö¸Ã±äÖֿɰµ²ØÍ¼±ê²¢ÉêÇëAndroid¸¨ÖúÖ°ÄܵÄȨÏÞ£¬ÒÔ»ñÈ¡´°¿ÚÄÚÈݺÍÓû§ÔÚÆäËüÀûÓÃÖÐÊäÈëµÄ¿¨ºÅºÍÃÜÂë¡£¸Ã±äÖÖ´´½¨µÄSSH·þÎñÆ÷Äܹ»´úÀíת·¢ÆäC2ͨѶ£¬ÒÔÌӱܼì²â¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/new-bianlian-variant-comes-with-screen-recording-and-creating-ssh-server-capabilities-5f772c50
6¡¢ÓÌËûÖÝÒ»ºÚ¿ÍÒòDDoSÓÎÏ·¹«Ë¾±»ÅÐÈëÓü27¸öÔÂ
Ò»ÃûÀ´×ÔÓÌËûÖݵÄ23ËêºÚ¿Í£¨Austin Thompson£©ÒòÔÚ2013Äê12ÔÂÖÁ2014Äê1ÔÂÆÚ¼ä¶Ô¶à¸öÓÎϷƽ̨ÌáÒéDDoS¹¥»÷±»ÅÐÈëÓü27¸öÔ¡£ÊÜÆä¹¥»÷µÄÓÎϷƽ̨Ô̺¬EAµÄOriginƽ̨¡¢Ë÷ÄáµÄPlayStationÍøÂçÒÔ¼°ValveµÄSteamƽ̨µÈ¡£Æ¾¾ÝÃÀ¹ú˾·¨²¿ÖÜÈý°ä²¼µÄÐÂΟ壬ThompsonµÄÐÐΪÖÁÉÙµ¼ÖÂÁË9.5ÍòÃÀÔªµÄËðʧ¡£³ýÁËÈëÓüÖ®±í£¬Ë¾·¨²¿»¹ºÅÁî±»¸æÏòDaybreak Games£¨ÔË÷ÄáÔÚÏßÓéÀÖ¹«Ë¾£©Ö§¸¶9.5ÍòÃÀÔªµÄÅâ³¥½ð¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/christmas-ddos-attacks.html


¾©¹«Íø°²±¸11010802024551ºÅ