¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190108

Ðû²¼Ê±¼ä 2019-01-08
1¡¢AvastÐû²¼2019ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

AvastµÄ2019ÄêÍþÐ²Ì¬ÊÆÕ¹Íû±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚ2019Äê¶Ô¿¹ÐÔAI½«Ó­À´ÀèÃ÷¡£¡£¡£¡£Ñо¿Ö°Ô±Õ¹ÍûDeepAttacks¹¥»÷½«¸üƵÈԵطºÆð£¨ÕâÀ๥»÷ͨ³£Ê¹ÓÃAIÌìÉúµÄÄÚÈÝÀ´ÌÓ±ÜAIÇå¾²¿ØÖƲ½·¥£©¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÎïÁªÍøÍþв½«±äµÃÔ½·¢Öش󣬣¬£¬£¬£¬£¬£¬Â·ÓÉÆ÷Ò²½«Ô½À´Ô½¶àµØ³ÉΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬£¬¹ã¸æ¡¢´¹ÂÚºÍÐéαӦÓý«¼ÌÐøÖ÷µ¼Òƶ¯ÍþвÁìÓò¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://cdn2.hubspot.net/hubfs/486579/Avast_Threat_Landscape_Report_2019.pdf


2¡¢ºÚ¿ÍÈëÇÖ°Ä´óÀûÑÇÔ¤¾¯ÍøÂç·¢ËÍÀ¬»øÓʼþ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

1ÔÂ6ÈÕºÚ¿ÍÈëÇÖ°Ä´óÀûÑÇÀ¥Ê¿À¼µÄEWN£¨ÔçÆÚÔ¤¾¯ÍøÂ磩£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓøÃÍøÂçͨ¹ý¶ÌÐÅ¡¢×ù»úºÍµç×ÓÓʼþÏòÓû§·¢ËÍÀ¬»øÓʼþ¾¯±¨¡£¡£¡£¡£EWNÊǰĴóÀûÑÇAeeris¹«Ë¾ÌṩµÄÒ»ÏîЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÔÊÐí°Ä´óÀûÑÇÒé»á»òµØ·½Õþ¸®¾Í¼«¶ËÌìÆø¡¢»ðÔÖ¡¢ÊèÉ¢ÐÅÏ¢»òʹÊÏìÓ¦·¢³ö½ôÆÈ¾¯±¨¡£¡£¡£¡£ºÚ¿Í·¢Ë͵ľ¯±¨ÖеÄÁ´½ÓÊÇÎÞº¦µÄ£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐСÎÒ˽¼ÒÐÅÏ¢ÔÚ´ËÊÂÎñÖÐÊܵ½Ë𺦡£¡£¡£¡£Æ¾Ö¤EWNµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÊÇʹÓÃÊÚȨÈËµÄÆ¾Ö¤À´½øÈëϵͳµÄ¡£¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎúÕâЩƾ֤ÊÇÔõÑù±»µÁµÄ£¬£¬£¬£¬£¬£¬£¬Ò²²»ÖªµÀÓм¸¶àÈËÊÕµ½Á˾¯±¨¡£¡£¡£¡£¾¯·½ºÍ°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄÈÔÔÚ¼ÌÐøÊӲ졣¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-uses-australian-early-warning-network-to-send-spam-alerts/


3¡¢ETCÔâ11´ÎË«»¨¹¥»÷£¬£¬£¬£¬£¬£¬£¬CoinbaseÒÑÔÝÍ£ETCÉúÒâ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ƾ֤CoinbaseÐû²¼µÄÇå¾²¾¯±¨£¬£¬£¬£¬£¬£¬£¬´Ó01ÔÂ05ÈÕµ½07ÈÕ (¿é¸ß¶È7245623µ½7255998Ö®¼ä)£¬£¬£¬£¬£¬£¬£¬ETCÍøÂç¹²ÔâÊÜÖÁÉÙ11´ÎË«»¨¹¥»÷ (double spending)£¬£¬£¬£¬£¬£¬£¬ËðʧETC 88500ö£¬£¬£¬£¬£¬£¬£¬¼ÛÖµÔ¼46ÍòÃÀÔª¡£¡£¡£¡£CoinbaseÌåÏÖÕâÒ»¹¥»÷ÈÔÔÚ¼ÌÐø£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚCoinbaseÒÑÔÝÍ£ÁËETCµÄÉúÒâ¡£¡£¡£¡£Å·ÖÞBitflyÒ²¶Ô´Ë´Î¹¥»÷·¢³öÁËÔ¤¾¯¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/coinbase-suspends-ethereum-classic-etc-trading-after-double-spend-attacks/


4¡¢Dark OverlordÐû²¼µÚÒ»Åú911ÉñÃØÎļþµÄ½âÃÜÃÜÔ¿

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Dark OverlordÐû²¼Á˵ÚÒ»ÅúÓë911¿ÖÏ®Ïà¹ØµÄ650·ÝÉñÃØÎļþµÄ½âÃÜÃÜÔ¿¡£¡£¡£¡£Ö®Ç°Dark OverlordÉù³Æ´ÓÓ¢¹ú°ü¹Ü¹«Ë¾HiscoxÇÔÈ¡ÁË´ó×ÚÎļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Óë911ËßËϰ¸¼þÏà¹ØµÄÊýÍò¸öÎļþ¡£¡£¡£¡£Dark OverlordÍþв½«Ïò¹«ÖÚÅû¶ÕâЩÎļþ£¬£¬£¬£¬£¬£¬£¬³ý·Ç¸Ã¹«Ë¾Ö§¸¶Ò»±Ê±ÈÌØ±ÒÊê½ð¡£¡£¡£¡£Dark OverlordÐû²¼ÁËÒ»Ïî¡°·Ö²ãÐû²¼ÍýÏ롱£¬£¬£¬£¬£¬£¬£¬¹«ÖÚ¿ÉÒÔÏòÆäÖ§¸¶±ÈÌØ±ÒÒÔ½âËøÕâЩÎļþ£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÅû¶µÄ¼´ÎªµÚÒ»²ãµÄÎļþ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79549/hacking/the-dark-overlord-9-11.html


5¡¢Bankers LifeÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Óû§PIIÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Bankers LifeÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Óû§µÄPIIÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂëºóËÄλÒÔ¼°HumanaÒ½Áưü¹ÜÏà¹ØµÄÐÅÏ¢¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ¿Í»§µÄÍêÕûÉç±£ºÅÂë¡¢ÒøÐÐÕË»§ºÍÐÅÓÿ¨ÐÅÏ¢ÒÔ¼°Ò½ÁÆÐÅÏ¢²¢Î´Êܵ½Ë𺦡£¡£¡£¡£´ËÊÂÎñ±¬·¢ÔÚ2018Äê5ÔÂ30ÈÕºÍ2018Äê9ÔÂ13ÈÕÖ®¼ä£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁËBankers LifeÔ±¹¤µÄƾ֤À´¾ÙÐÐδÊÚȨ»á¼û¡£¡£¡£¡£ÊÜÓ°ÏìÓû§µÄÏêϸÊýÄ¿Éв»ÇåÎú¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/bankers-life-hit-by-data-breach-exposing-pii-of-humana-health-insurance-policy-applicants-ccffd93b


6¡¢Ñо¿ÍŶӷ¢Ã÷жñÒâ»î¶¯Í¬Ê±·Ö·¢VidarºÍGandCrab

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Malwarebytes Labs·¢Ã÷Ò»¸öͬʱ·Ö·¢VidarºÍGandCrabµÄй¥»÷»î¶¯¡£¡£¡£¡£Vidar¿ÉÒÔÇÔÈ¡Óû§µÄä¯ÀÀÆ÷ÀúÊ·¼Í¼£¨°üÀ¨Torä¯ÀÀÆ÷£©£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢ÐÅÓÿ¨ÃÜÂëÒÔ¼°¼´Ê±ÐÂÎŵÈ¡£¡£¡£¡£Vidarͨ¹ýδ¼ÓÃܵÄHTTP POSTÇëÇó½«ÕâЩÊý¾Ý·¢ËÍ»ØC2ЧÀÍÆ÷¡£¡£¡£¡£ÔÚÕâ¸ö¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýFallout EK·Ö·¢VidarºÍÁíÒ»¸öÓÐÓúÉÔØ£ºÀÕË÷Èí¼þGandCrab¡£¡£¡£¡£ÔÚÓû§Êܵ½VidarѬȾºóµÄԼĪ1·ÖÖÓÄÚ£¬£¬£¬£¬£¬£¬£¬Óû§µÄÎļþ¾Í»á±»GandCrab v5.04Ëù¼ÓÃÜ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/threat-analysis/2019/01/vidar-gandcrab-stealer-and-ransomware-combo-observed-in-the-wild/


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí