¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181030

°ä²¼¹¦·ò 2018-10-30
1¡¢AvastÅû¶Õë¶ÔÓ¢ÐÛͬÃËÍæ¼ÒµÄÍøÂç´¹µö»î¶¯

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Avast×êÑÐÍŶÓÔÚ2018ÄêÏļ¾Ä©¹Û²ìµ½Õë¶ÔÓ¢ÐÛͬÃËÍæ¼ÒµÄÒ»¸öÐÂÍøÂç´¹µö»î¶¯ ¡£¹¥»÷ÕßÖØÒªÕë¶ÔÎ÷Å·µØÓò £¬´óÎÞÊý¹¥»÷²úÉúÔÚ·¨¹ú £¬Æä´ÎÊǵ¹úºÍÎ÷°àÑÀ ¡£¸Ã´¹µöÍøÕ¾ÍйÜÔÚÃâ·ÑµÄÍйܷþÎñÉÌ000webhostÉÏ £¬ÒÔ½Ú¼ó¿ªÖ§ £¬²¢ÇÒ´¹µöÍøÕ¾Í¨³£²»»áÕ¼ÓÃÌ«¶à´ÅÅ̿ռäºÍ²úÉú½Ï¶àµÄÁ÷Á¿ £¬Òò¶ø¹¥»÷ÕßÍùÍù»áÑ¡ÔñʹÓÃÃâ·ÑµÄÍйܷþÎñ ¡£¸Ã´¹µöÒ³ÃæÔì×÷µÃ¼«¶È¾«²Ê £¬Í¼ÏñÖÊÁ¿Ò²Ã»ÓнµµÍ £¬²¢ÔÚÓû§µã»÷µÇ¼ʱ½«Í´´¦·¢ËÍÖÁ¹¥»÷Õß ¡£

   

Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/league-of-legends-gamers-targeted-by-phishing-scam-avast


2¡¢×êÑÐÈËÔ±·¢ÏÖEmotetÀûÓÃDKIMÈÆ¹ýÓʼþ¹ýÂË´ëÊ©

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018Äê7ÔÂUS-CERTÔø°ä²¼¹ØÓÚÒøÐÐľÂíEmotetµÄ¾¯±¨ £¬²¢Ìá³öÁËÏàÓ¦µÄ·À»¤´ëÊ©½¨Òé £¬ÆäÖÐÒ»ÏÒéÊÇʹÓûùÓÚÓòµÄÐÂÎÅÈÏÖ¤¡¢»ã±¨ºÍÒ»ÖÂÐÔ£¨DMARC£© £¬¸Ã»úÔìÄܹ»Åжϵç×ÓÓʼþÊÇ·ñÀ´×ÔÕæÊµµÄµØÖ· ¡£È»¶ø²»ÐÒµÄÊÇ £¬¹¥»÷ÕßËÆºõÒ²ÔĶÁÁËUS-CERTµÄ¾¯±¨ £¬Emotetͨ¹ýÒ»ÖÖÓò½Ù³Ö¼¼ÊõÀ´ÈƹýDMARC½ÚÔì»úÔì ¡£ÔÚTrickbot¨CEmotet¶ñÒâ»î¶¯ÖÐ £¬ÕâÊÇͨ¹ýд´½¨µÄ×ÓÓò_domainkeyʵÏÖµÄ ¡£
  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malware-distributors-adopt-dkim-to-bypass-mail-filters/


3¡¢ÃÀ¼ÓÖÝÔ¼2800ÃûŮͯ¾üµÄÓ×ÎÒÐÅÏ¢Ôâй¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÀ¹úÄϼÓÖݵİÂÀ¼ÖÎÏØÅ®Í¯¾ü×éÖ¯£¨GSOC£©Ôâµ½ºÚ¿Í¹¥»÷ £¬¸Ã×éÖ¯µÄµç×ÓÓʼþÕË»§Ôâµ½µÚÈý·½Î´ÊÚȨ½Ó¼û £¬Ô¼2800ÃûŮͯ¾ü³ÉÔ±µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜй¶ ¡£±»µÁµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢±£ÏÕºÅÂëºÍÒ½ÁÆÐÅÏ¢ ¡£ÕâЩÐÅÏ¢¿ÉÄܻᱻÓÃÓÚºóÐøµÄÉç½»¹¤³Ì¹¥»÷ºÍÉí·Ý͵ÇÔµÈ ¡£¸ÃÕË»§ÔÚ9ÔÂ30ÈÕÖÁ10ÔÂ1ÈÕÖ»±»½Ù³ÖÁË1Ìì ¡£

  

Ô­ÎÄÁ´½Ó£º

https://abc30.com/4561129/


4¡¢Æ±Îñ¹«Ë¾PaylogicÔâºÚ¿ÍÈëÇÖ £¬Ô¼6.4ÍòÓû§µÄÓ×ÎÒÐÅÏ¢±»µÁ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƱÎñ¹«Ë¾PaylogicÐû³ÆÆäƱÎñϵͳÔâºÚ¿ÍÈëÇÖ £¬²ÎÓëTomorrowland 2014ÒôÀÖ½ÚµÄÔ¼6.4ÍòÃûµç×ÓÎèÇú·ÛË¿µÄÓ×ÎÒÐÅÏ¢±»µÁ ¡£TomorrowlandÊÇÔÚ±ÈÀûʱÓ×ÕòBoom½øÐеĵç×ÓÒôÀÖ½Ú £¬ÊÇÊÀ½çÉÏ×î´óµÄÒôÀÖ½ÚÖ®Ò» ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÐԱ𡢴ºÇïºÍÓÊÕþ±àÂëµÈ £¬µ«²»Ô̺¬Ö§¸¶ÐÅÏ¢¡¢ÃÜÂëºÍÓû§µØÖ· ¡£PaylogicÔÚÉêÃ÷Öв¢Ã»ÓÐй©¹¥»÷µÄ¾ßÌåϸ½Ú ¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/crooks-stole-data-of-64-000-tomorrowland-festival-goers-523493.shtml


5¡¢¼ÓÃÜÇ®±ÒÂòÂôËùMapleChangeÔâºÚ¿Í¹¥»÷ £¬Ëðʧ913¸ö±ÈÌØ±Ò

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¼ÓÃÜÇ®±ÒÂòÂôËùMapleChange³ÆÆäÔâµ½ºÚ¿Í¹¥»÷ £¬¹²Ëðʧ913¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼600ÍòÃÀÔª£© ¡£¸Ãƽ̨¾Ý³ÆÊǼÓÄôóµÄÒ»¸öÓ×ÐÍÂòÂôËù ¡£MapleChangeÔÚTwitterÉϳƾ­¹ý¾ßÌåµÄµ÷²é £¬¸ÃÂòÂôËùÎÞÁ¦¶ÔÓû§½øÐÐÅ⸶ £¬½«²»µÃ²»¹Ø¹Ø £¬Ô̺¬¹Ø¹ØÆäTwitterÕË»§ºÍÍøÕ¾ ¡£ÕâÒ»ÊÂÎñѸËÙÒý·¢Á˶àÈËÒÉ»ó £¬ÒÔΪ¸ÃÓ×ÐÍÂòÂôËù¿ÉÄÜÖ»ÊÇÒ»¸öȦÌ× £¬¸ÃÊÂÎñ¿ÉÄÜ»áÒý·¢ºóÐøµÄÐÌʵ÷²é ¡£

  

Ô­ÎÄÁ´½Ó£º

https://ethereumworldnews.com/maplechange-crypto-exchange-hacked-for-913-bitcoin-btc-exit-scam-likely/


6¡¢×êÑÐÍŶӰ䲼¹ØÓÚÀ¬»øÓʼþµÄ¸½¼þÎļþÀàÐ͵ķÖÎö»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ç÷Ïò¿Æ¼¼×êÑÐÍŶӰ䲼¹ØÓÚÀ¬»øÓʼþµÄ¸½¼þÎļþÀàÐ͵ķÖÎö»ã±¨ £¬2017Äê×î³£¼ûµÄ¶ñÒ⸽¼þµÄÎļþÀàÐÍÊÇ.XLS¡¢.PDF¡¢.JS¡¢.VBS¡¢.DOCX¡¢.DOC¡¢.WSF¡¢.XLSX¡¢.EXEºÍ.HTML £¬µ«ÍøÂç·¸×ï·Ö×ÓÒѾ­À©´óÁËËûÃǵÄÁìÓò £¬ÐµĶñÒ⸽¼þÎļþÀàÐÍÔ̺¬.ARJ¡¢.Z¡¢.IQY¡¢.PUBÒÔ¼°Windows 10ÖеÄÐÂÎļþÀàÐÍSettingContents-ms ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/same-old-yet-brand-new-new-file-types-emerge-in-malware-spam-attachments/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù