¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180717
°ä²¼¹¦·ò 2018-07-17¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ¶íÂÞ˹·¸×ïÍÅ»ïAPT28µÄй¥»÷»î¶¯
CSE Cybsec Z-Lab°²È«×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹·¸×ïÍÅ»ïAPT28µÄй¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£6Ô·Ý×êÑÐÈËÔ±·¢ÏÖһЩжñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬£¬·ÖÎöÅú×¢ËüÃÇÊÇAPT28ʹÓõĺóÃÅX-AgentµÄбäÖÖ£¬£¬£¬£¬£¬£¬¸Ã±äÖÖÊÇÒ»¸öWindows°æ±¾µÄ±äÖÖ£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚÕë¶ÔÒâ´óÀû¾ü¹¤ÆóÒµMarina Militare¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±½«APT28µÄÕâ´ÎÍøÂç¼äµý»î¶¯³ÆÎªÂÞÂí¼ÙÈջ¡£¡£¡£¡£¡£¡£¡£¡£¸ü¶à¾ßÌåÐÅÏ¢£¨Ô̺¬IoCºÍYara¹æ¶¨£©Çë½Ó¼ûÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74460/apt/operation-roman-holiday-apt28.html
¡¾Íþвµý±¨¡¿¾Ý±¨Â·¶íÂÞ˹ÔÚÊÀ½ç±ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷
Ī˹¿ÆÊ±±¨±¨Â·³Æ£¬£¬£¬£¬£¬£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂ簲ȫÊýÃÅ£¬£¬£¬£¬£¬£¬¸Ã²¿ÃÅÔÚÊÀ½ç±ÆÚ¼ä¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸×ï»î¶¯£¬£¬£¬£¬£¬£¬È·±£Á˽ÇÖðµÄ°²È«¡£¡£¡£¡£¡£¡£¡£¡£FireEyeÄÏÅ·¼¼Êõ×ܼàDavid Grout°µÊ¾¹ÌÈ»ÕâÒ»Êý×ֺܸߣ¬£¬£¬£¬£¬£¬µ«²¢²»³öºõÒâÁÏ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷¿ÉÄÜÔ̺¬ÔÚ½ÇÖðǰ¼¸ÖÜ¾ÍÆðÍ·µÄÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ÀýÈçÁ®¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÊÀ½ç±Ö÷ÌâÓйصĴÙÏú»î¶¯£¨Èç¹ú¶È¶ÓÇòÒ£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/
¡¾Íþвµý±¨¡¿FBIͳ¼Æ³ÆBECڿƻ¹²µ¼Ö³¬¹ý120ÒÚÃÀÔªµÄËðʧ
ƾ¾ÝFBIÉÏÖܰ䲼µÄÒ»·Ýµ÷Ñл㱨£¬£¬£¬£¬£¬£¬ÓÉBECºÍEACڿƻµ¼ÖµÄËðʧ³¬¹ý120ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨»ùÓÚFBIÏÂÊôµÄ»¥ÁªÍø·¸×ïͶËßÖÐÐÄIC3ÒÔ¼°¹ú¼Ê·¨ÂÉ»ú¹¹ºÍ½ðÈÚ»ú¹¹ÔÚ2013Äê10ÔÂÖÁ2018Äê5ÔÂÆÚ¼äÍøÂçµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ´ËÆÚ¼ä£¬£¬£¬£¬£¬£¬È«Çò¹²ÓÐ7.8Íò¶àÆðÓйØÍ¶Ëߣ¬£¬£¬£¬£¬£¬ÆäÖг¬¹ý4.1ÍòÆð²úÉúÔÚÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£¡£Êܺ¦µÄÓ×ÎÒ¼°ÆóÒµµÄËðʧ¿ÉÄܸߴï125ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£Ïà±È֮ϣ¬£¬£¬£¬£¬£¬FBI֮ǰµÄ»ã±¨£¨º¸Ç2013Äê10ÔÂÖÁ2016Äê12Ô£©³ÆÈ«Çò¹²²úÉúÔ¼4ÍòÆðÊÂÎñ£¬£¬£¬£¬£¬£¬Ëðʧ×ܶîΪ53ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/bec-scam-losses-top-12-billion-fbi
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±³ÆÊýÍǫ̀´ó»ªDVRµÄµÇ¼ÃÜÂë±»ZoomEyeÊÕ¼
NewSky SecurityµÄ°²È«×êÑÐÔ±Ankit Anubhav·¢ÏÖÊýÍǫ̀´ó»ªDVRµÄµÇ¼ÃÜÂë±»ZoomEyeÊÕ¼¡£¡£¡£¡£¡£¡£¡£¡£´ó»ªDVRÖдæÔÚ·ì϶£¨CVE-2013-6117£©£¬£¬£¬£¬£¬£¬¹ÌÈ»½¨¸´²¹¶¡ÒѰ䲼¶àÄ꣬£¬£¬£¬£¬£¬µ«ÈÔÓдóÁ¿É豸ûÓнøÐиüС£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢»ñÈ¡Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬Óû§ÃûºÍÃÜÂëµÈ¡£¡£¡£¡£¡£¡£¡£¡£ZoomEye»º´æÁËɨÃèÕâЩÉ豸µÄ¶Ë¿Úʱ·µ»ØµÄµÇ¼ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Anubhav³ÆÔ¼ÓÐ1.5Íò¸ö´ó»ªDVRʹÓÃÈõÃÜÂëadmin£¬£¬£¬£¬£¬£¬Áí±í³¬¹ý1.3Íò¸öÉ豸ʹÓÃÈõÃÜÂë123456¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/passwords-for-tens-of-thousands-of-dahua-devices-cached-in-iot-search-engine/
¡¾°²È«·ì϶¡¿×êÑÐÍŶӰ䲼¹ØÓÚDHCP¿Í»§¶Ë·ì϶£¨CVE-2018-1111£©µÄ·ÖÎö»ã±¨
Paloalto NetworksµÄUnit42×êÑÐÍŶӰ䲼¹ØÓÚDHCP¿Í»§¶ËÈí¼þ°üÖеĺÅÁî×¢Èë·ì϶£¨CVE-2018-1111£©µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚ¶à¸öRed Hat Linux°æ±¾µÄDHCP¿Í»§¶ËÈí¼þ°üµÄNetworkManager¾ç±¾ÖÓ×£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý¶ñÒâDHCP·þÎñÆ÷»ò±¾µØ¶ñÒâDHCPÏìÓ¦°üÀ´ÀûÓø÷ì϶£¬£¬£¬£¬£¬£¬´Ó¶øÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄPoCÓÚ2018Äê5ÔÂ16ÈÕ±»¹«¿ª°ä²¼¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£Ë¼¿¼µ½NetworkManager±»Ê¹ÓÃµÄ¿í·ºÐÔ£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://researchcenter.paloaltonetworks.com/2018/07/unit42-analysis-dhcp-client-script-code-execution-vulnerability-cve-2018-1111/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þMagniberÔÚÑÇÖÞÀ©´óÆä¹¥»÷ÁìÓò
Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þMagniberÀ©´óÁËÆä¹¥»÷ÁìÓò£¬£¬£¬£¬£¬£¬´ÓÖ»Õë¶Ôº«¹úµ½Õë¶Ô¸ü¶àÖÐÎÄ£¨Öйú¡¢ÐÂ¼ÓÆÂ£©ºÍÂíÀ´ÓÂíÀ´Î÷ÑÇ¡¢ÎÄÀ³£©µÄÓû§¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹³Æ¸Ã¶ñÒâÈí¼þµÄÔ´´úÂë´Ë¿ÌÖÊÁ¿¸ü¸ß£¬£¬£¬£¬£¬£¬ÀûÓöàÖÖ»ìºÏ¼¼Êõ²¢ÇÒ²»ÔÙÒÀÀµÓÚC&C»òÓ²±àÂëÃÜÔ¿À´ÊµÏÔìä¼ÓÃÜ·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£ÐµÄMagniber¹¥»÷»î¶¯ÀûÓÃIE·ì϶£¨CVE-2018-8174£©½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/threat-analysis/2018/07/magniber-ransomware-improves-expands-within-asia/


¾©¹«Íø°²±¸11010802024551ºÅ