¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190131
Ðû²¼Ê±¼ä 2019-01-31
Çå¾²Ñо¿Ô±Oliver Hough·¢Ã÷ÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearchЧÀÍÆ÷δÊÜÃÜÂë±£»£»£»¤£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍÊÂÇé°¸Àý¡£¡£¡£¡£Æ¾Ö¤Ê±¼ä´Á£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿É×·ËÝÖÁ2018Äê10Ô¡£¡£¡£¡£¾ÓÉÊӲ죬£¬£¬£¬£¬£¬£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓÉÈËΪ¹ýʧµ¼Öµġ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/2¡¢Å·ÖÞÖ´·¨»ú¹¹ÕýÔÚÊÓ²ìʹÓùýwebstresser.orgµÄÓû§
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80435/cyber-crime/europol-ddos-for-hire.html3¡¢ÒÁÀÊAPT39жñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖж«µçÐÅÐÐÒµ

FireEyeÐû²¼¹ØÓÚÒÁÀÊAPT39жñÒâ»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£ÓëÆäËüÒÁÀÊAPT×éÖ¯²î±ðµÄÊÇ£¬£¬£¬£¬£¬£¬£¬APT39¸ü×ÅÖØÓÚÇÔȡСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãΪÒÁÀÊµÄ¼à¿Ø¡¢¸ú×ٺͼàÊӻÌṩ֧³Ö¡£¡£¡£¡£ËäÈ»APT39µÄÄ¿µÄ±é²¼È«Çò£¬£¬£¬£¬£¬£¬£¬µ«Æä»î¶¯Ö÷Òª¼¯ÖÐÔÚÖж«µØÇø£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÅÏÈÕë¶ÔµçÐÅÐÐÒµ£¬£¬£¬£¬£¬£¬£¬±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ò²Ãé×¼ÂÃÓÎÒµºÍIT¹«Ë¾¡£¡£¡£¡£APT39Ö÷ҪʹÓÃSEAWEEDºÍCACHEMONEYºóÃÅÒÔ¼°POWBATºóÃÅ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html4¡¢Altran Technologies¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷

·¨¹ú¹¤³Ì×Éѯ¹«Ë¾Altran TechnologiesÔâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÔÚһЩŷÖÞ¹ú¼ÒµÄÔËÓª»î¶¯Êܵ½Ó°Ïì¡£¡£¡£¡£ÎªÁ˱£»£»£»¤¿Í»§µÄÊý¾ÝºÍ×ʲú£¬£¬£¬£¬£¬£¬£¬AltranÔÝʱ¹Ø±ÕÁËÍøÂçºÍÓ¦ÓóÌÐò¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ1ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾²¢Ã»ÓÐÅû¶Ïà¹ØÏ¸½Ú£¬£¬£¬£¬£¬£¬£¬²¢³ÆÊÂÎñ»¹ÔÚÊÓ²ìÖ®ÖС£¡£¡£¡£Æ¾Ö¤ÉÏ´«µ½VirusTotalµÄ¶ñÒâÑù±¾£¬£¬£¬£¬£¬£¬£¬LockerGoga»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lockedÀ©Õ¹Ãû¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/altran-technologies-hit-by-lockergoga-ransomware-attack-e1f905705¡¢ÀÕË÷Èí¼þJobCrypterбäÖÖ£¬£¬£¬£¬£¬£¬£¬¿É½ØÈ¡ÆÁÄ»ÐÅÏ¢

Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þJobCrypterµÄÒ»¸öбäÖÖ£¬£¬£¬£¬£¬£¬£¬¸Ã±äÖÖ¾ßÓÐÌØÁíÍâ¼ÓÃܲãºÍ¸ü³¤µÄÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔͨ¹ýSMTP½«Ä¿µÄ×°±¸µÄÆÁÄ»½ØÍ¼·¢ËÍÖÁÖ¸¶¨µÄµç×ÓÓÊÏä¡£¡£¡£¡£¸Ã±äÖÖ»áÏȽ«Îļþ¾ÙÐÐBase64±àÂ룬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃTriple DESËã·¨¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬×îºóÔÙ¾ÙÐÐÒ»´ÎBase64±àÂ룬£¬£¬£¬£¬£¬£¬ÃÜÔ¿ÓÉ67λÊý×Ö×é³É¡£¡£¡£¡£¸Ã±äÖÖÒªÇóÊÜѬȾµÄÓû§ÔÚ24СʱÄÚÖ§¸¶1000Å·ÔªµÄÊê½ð¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.scmagazineuk.com/new-jobcrypter-ransomware-variant-captures-screenshots-infected-devices/article/15241996¡¢Î÷ÃÅ×ÓÐÞ¸´S7-1500 PLCÖеÄÁ½¸öDoSÎó²î
Î÷ÃÅ×ÓÐÞ¸´Simatic S7-1500¿É±à³ÌÂß¼¿ØÖÆÆ÷£¨PLC£©ÖеÄÁ½¸ö¿Éµ¼ÖÂDoSµÄÇå¾²Îó²î¡£¡£¡£¡£ÕâÁ½¸öÎó²î£¨CVE-2018-16558ºÍCVE-2018-16559£©ÊÇÓÉPositive TechnologiesµÄÑо¿Ö°Ô±·¢Ã÷µÄ£¬£¬£¬£¬£¬£¬£¬ÆäCVSS v3.0µÃ·Ö¾ùΪ7.5¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòTCP¶Ë¿Ú80»ò443·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢Îó²î¡£¡£¡£¡£Î÷ÃÅ×ÓÔÚSimatic S7-1500¹Ì¼þ°æ±¾2.5ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cert-portal.siemens.com/productcert/pdf/ssa-180635.pdfÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí