¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181022
Ðû²¼Ê±¼ä 2018-10-23
ÉÏÖÜÎåÃÀ¹úÒ½Áưü¹ÜºÍÒ½ÁƽòÌùЧÀÍÖÐÐÄ£¨CMS£©Ðû²¼ÐÂÎųƣ¬£¬£¬£¬£¬ÓëHealthCare.govÏà¹ØµÄÒ»¸öÕþ¸®ÅÌËã»úϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Ô¼7.5ÍòÃûÓû§µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢±»ÇÔ¡£¡£¡£CMSÌåÏÖÔÚ10ÔÂ16ÈÕÈ·ÈÏÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬²¢½ûÓÃÁËÓëÒì³£»£»£»£»£»£»£»î¶¯Ïà¹ØµÄÓû§ÕË»§¡£¡£¡£CMSºÍFBIÕýÔÚÍýÏë֪ͨËùÓÐÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬²¢ÌṩÐÅÓñ£»£»£»£»£»£»£»¤µÈ×ÊÔ´¡£¡£¡£
2£¬£¬£¬£¬£¬Çå¾²³§ÉÌÅû¶Õë¶Ô¹·¹·±ÒµÄÔÚÏßÚ²ÆÀ˳±
Çå¾²³§ÉÌDoctor WebµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶Ô¹·¹·±ÒµÄÔÚÏßթƻ¡£¡£¡£¹¥»÷Õß±»³ÆÎªInvestimer£¨ÓÖÃûHyipblock»òMmpower£©£¬£¬£¬£¬£¬ËûÃÇʹÓðµÍøÊг¡ÉϵÄÖÖÖÖÖ÷Á÷ÉÌҵľÂíÀ´ÇÔÈ¡Óû§µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬°üÀ¨Eredel¡¢AZORult¡¢Kpot¡¢Kratos¡¢N0F1L3¡¢ACRUX¡¢Predator The Thief¡¢ArkeiºÍPonyµÈ¡£¡£¡£Investimerͨ¹ýÖÖÖÖ´¹ÂÚÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬×¨¼ÒÔ¤¼ÆÊÜÓ°ÏìµÄÓû§Áè¼Ý1ÍòÈË£¬£¬£¬£¬£¬×ÜËðʧÁè¼Ý2.3ÍòÃÀÔª¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://news.drweb.com/show/?c=5&i=12886&lng=en
3£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶Õë¶ÔWindowsϵͳµÄÐÂRIDÐ®ÖÆ¹¥»÷
CSLÇå¾²Ñо¿Ö°Ô±Sebasti¨¢nCastro·¢Ã÷Ò»ÖÖÕë¶ÔWindowsÓû§ÕÊ»§²ÎÊýRIDµÄÐ®ÖÆ¹¥»÷¡£¡£¡£RIDÓÃÓÚÐÎòÓû§µÄȨÏÞ×飬£¬£¬£¬£¬°üÀ¨±ê×¼À´±öÕÊ»§501ºÍÖÎÀíÔ±ÕÊ»§500µÈ¡£¡£¡£¹¥»÷Õßͨ¹ýÐÞ¸ÄWindowsÕÊ»§ÐÅÏ¢µÄ×¢²á±íÏ£¬£¬£¬£¬ÎªÖ¸¶¨ÕË»§ÊÚÓè²î±ðµÄRID£¬£¬£¬£¬£¬½ø¶ø»ñµÃϵͳµÄÍêÕû»á¼ûȨÏÞ¡£¡£¡£Ñо¿Ö°Ô±¿ª·¢ÁËÒ»¸ö¿É×Ô¶¯»¯ÊµÑé´Ë¹¥»÷µÄMetasploitÄ£¿£¿£¿£¿érid_hijack¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttp://csl.com.co/rid-hijacking/
4£¬£¬£¬£¬£¬ÃÀWest HavenÊÐÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶2000ÃÀÔªÊê½ð
ÃÀ¹ú¿µÄùµÒ¸ñÖݵÄWest HavenÊÐÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬Õþ¸®ÒÑÏò¹¥»÷ÕßÖ§¸¶ÁË2000ÃÀÔªµÄÊê½ðÒÔ½âËø23̨ЧÀÍÆ÷²¢»Ö¸´¶Ô¶¼»áÏà¹ØÏµÍ³Êý¾ÝµÄ»á¼û¡£¡£¡£¸Ã±ÊÊê½ðÊÇͨ¹ý±ÈÌØ±ÒÖ§¸¶µÄ¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚÉÏÖܶþÉÏÎ磬£¬£¬£¬£¬ÊÐÕþ¹ÙԱͨ¹ýÑо¿ÒÔΪ֧¸¶Êê½ðÊÇ×îºÃµÄ½â¾ö¼Æ»®¡£¡£¡£ÁìÍÁÇå¾²²¿ÒÔΪ¸Ã¹¥»÷À´×ÔÓÚ¾³Í⣬£¬£¬£¬£¬ÏÖÔÚ»¹ÔÚ¼ÌÐø¾ÙÐÐÊӲ졣¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/city-pays-2000-computer-ransomware-attack
5£¬£¬£¬£¬£¬Ñо¿ÍŶÓÅû¶¶à¿îNAS×°±¸ÖеĶà¸öÇå¾²Îó²î
WizCaseÇå¾²Ñо¿Ö°Ô±ÔÚ¶à¿îNAS×°±¸Öз¢Ã÷¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÆ·ÅÆ°üÀ¨Î÷Êý¡¢Íø¼þ¡¢Ï£½ÝºÍMedionµÈ¡£¡£¡£ÕâЩװ±¸¶¼±£´æÒ»¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£ÏÖÔÚÏà¹ØÎó²î£¨CVE-2018-18472ºÍCVE-2018-18471£©»¹Î´»ñµÃÐÞ¸´£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÔÚÏß×°±¸µÄÊýÄ¿´ï½ü200Íǫ̀¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪÆäËüNAS×°±¸ºÜÓпÉÄÜÒ²±£´æÀàËÆµÄÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.wizcase.com/blog/hack-2018/
6£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÔÚ¼ÓÃÜʱÅþÁ¬µ½BleepingComputerÍøÕ¾µÄÐÂÀÕË÷Èí¼þ
Ñо¿Ö°Ô±nao_secºÍKafeine·¢Ã÷ÀÕË÷Èí¼þKraken Cryptor v2.0.6»áÔÚ¼ÓÃܵIJî±ð½×¶ÎÅþÁ¬µ½BleepingComputerÍøÕ¾²¢·¢ËÍÏà¹ØÊý¾Ý¡£¡£¡£¸Ã°æ±¾ÊÇÉÏÖÜÄ©Ðû²¼µÄ£¬£¬£¬£¬£¬Ö÷Ҫͨ¹ý¶ñÒâ¹ã¸æºÍÎó²îʹÓù¤¾ß°üRIG¾ÙÐзַ¢¡£¡£¡£×Ô2018Äê10ÔÂ20ÈÕÒÔÀ´£¬£¬£¬£¬£¬¸Ã°æ±¾ÒÑÔÚÈ«ÌìϹæÄ£ÄÚѬȾÁË217ÃûÓû§¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎú¶ñÒâÈí¼þ¿ª·¢ÕßÕâÑù×öµÄÄ¿µÄ£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÒÔΪÕâ¿ÉÄÜÊǶñÒâµÄÍæÐ¦¡£¡£¡£
https://www.bleepingcomputer.com/news/security/kraken-cryptor-ransomware-connecting-to-bleepingcomputer-during-encryption/
ÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ