8827Ì«Ñô¼¯ÍÅ

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍø°²È«×¨Ìâ > °²È«×ÊѶ

Æû³µÔì×÷É̱¾ÌïÔâ·êÀÕË÷Èí¼þ¹¥»÷

×÷ÕߣºË»ºðRoarTalk 2020-06-18

1.png

Ó¢¹ú¹ã²¥¹«Ë¾£¨BBC£©°ä²¼µÄÒ»·Ý»ã±¨³Æ£¬£¬ £¬£¬£¬£¬Æû³µÔì×÷É̱¾ÌïÔâ·êÁËÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬Ëæºó¸Ã¹«Ë¾ÔÚTwitterÉÏ֤ʵÁËÕâÒ»ÐÂÎÅ¡£¡£¡£¡£¡£ÁíÒ»¸öͬÑùÔÚTwitterÉÏÅû¶µÄÀàËÆ¹¥»÷ÊÂÎñÊÇÏ®»÷ÁËEdesur SA£¬£¬ £¬£¬£¬£¬ÕâÊǰ¢¸ùÍ¢EnelÆìϵÄÒ»¼Ò¹«Ë¾£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ²¼ÒËŵ˹°¬Àû˹ÊдÓÊÂÄÜÔ´·ÖÅäÒµÎñ¡£¡£¡£¡£¡£

ƾ¾ÝÍøÉϰ䲼µÄÑù±¾£¬£¬ £¬£¬£¬£¬ÕâЩÊÂÎñ¿ÉÄÜÓëEKANS / SNAKEÀÕË÷Èí¼þ¼Ò×åÓйء£¡£¡£¡£¡£ÔÚÕâÆªÎÄÕÂÖУ¬£¬ £¬£¬£¬£¬ÎÒÃÇ»ØÊ×ÁËÓйØÕâÖÖÀÕË÷Èí¼þµÄÓйØÐÅÏ¢ÒÔ¼°µ½Ä¿Ç°ÎªÖ¹ÎÒÃÇ¿ÉÄܽøÐеķÖÎö¡£¡£¡£¡£¡£

ÀÕË÷Èí¼þµÄÖ¸±ê

°²È«×êÑÐÈËÔ±Vitali Kremez³õ´Î¹«¿ªÌá¼°EKANSÀÕË÷Èí¼þµÄ¹¦·òÄܹ»×·Òäµ½2020Äê1Ô£¬£¬ £¬£¬£¬£¬ÄÇʱVitali Kremez ·ÖÏíÁËÓйØÊ¹ÓÃGOLANG±àдµÄÐÂÐÍÀÕË÷Èí¼þµÄÐÅÏ¢¡£¡£¡£¡£¡£

°²È«¹«Ë¾Dragos Ôڴ˲©¿ÍÖÐ×ö³ö¾ßÌå½éÉÜ¡£¡£¡£¡£¡£

2.png

ͼ1£ºEKANSÊê½ð¼Í¼

6ÔÂ8ÈÕ£¬£¬ £¬£¬£¬£¬Ò»Î»×êÑÐÈËÔ±·ÖÏíÁËÀÕË÷Èí¼þµÄÑù±¾£¬£¬ £¬£¬£¬£¬ÕâЩÑù±¾Ìý˵ÊÇÕë¶Ô±¾ÌïºÍEnelµÄ¡£¡£¡£¡£¡£ÔÚÎÒÃÇÆðÍ·²é¿´´úÂëʱ£¬£¬ £¬£¬£¬£¬ÎÒÃÇÓÐÁËһЩ·¢ÏÖ£¬£¬ £¬£¬£¬£¬Ö¤ÊµÁËÕâÖÖ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£

3.png

ͼ2£º»¥³â²é³­

4.png

ͼ3£ºÕƹÜÖ´ÐÐDNS²éÎʵÄÖ°ÄÜ

Ö¸±ê£º±¾Ìï

¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£¡£¡£¡£¡£] com

Ö¸±ê£ºEnel

¡ñ ½âÎöÄÚ²¿Óò£ºenelint.global

¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£¡£¡£¡£¡£] com

Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©¿ÉÄÜÊǹ¥»÷µÄý½é

Á½¼Ò¹«Ë¾¶¼ÓÐһЩ´øÓÐÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©½Ó¼ûȨÏÞµÄÍÆËã»ú¹«¿ª£¨Çë²ÎÔÄ´Ë´¦£©¡£¡£¡£¡£¡£RDP¹¥»÷ÊÇÀÕË÷Èí¼þ²Ù×÷µÄÖØÒªÇÐÈëµãÖ®Ò»¡£¡£¡£¡£¡£

²»Í⣬£¬ £¬£¬£¬£¬ÕâЩ½ö½öÊÇ´§Ä¦£¬£¬ £¬£¬£¬£¬²»ÄÜÆëȫע¶¨Õâ¾ÍÊÇÍþвÐÐΪÕß¹¥»÷µÄ·½Ê½¡£¡£¡£¡£¡£Ö»ÓнøÐÐÊʵ±µÄÄÚ²¿µ÷²é£¬£¬ £¬£¬£¬£¬ÄÜÁ¦È·ÇмòÖ±¶¨¹¥»÷ÕßÊÇÈôºÎ·ÛËéÍøÂçµÄ¡£¡£¡£¡£¡£

¼ì²â

ÎÒÃÇͨ¹ý´´½¨Ò»¸öαÔìµÄÄÚ²¿·þÎñÆ÷À´²âÊÔÔÚ³¢ÊÔÊÒÖй«¿ªÌṩµÄÀÕË÷Èí¼þÑù±¾£¬£¬ £¬£¬£¬£¬¸Ã·þÎñÆ÷½«ÏìÓ¦¶ñÒâÈí¼þ´úÂëʹÓÃÔ¤ÆÚµÄIPµØÖ·½øÐеÄDNS²éÎÊ¡£¡£¡£¡£¡£¶øºó£¬£¬ £¬£¬£¬£¬ÎÒÃǶÔMalwarebytes Nebula£¨ÎÒÃÇÃæÏòÆóÒµµÄ»ùÓÚÔÆµÄ¶Ëµã±£»£»£»£» £»¤£©½øÐÐÁ˾ݳÆÓë±¾ÌïÓйصÄÑù±¾²âÊÔ¡£¡£¡£¡£¡£

5.png

ͼ4£ºMalwarebytes NebulaÒDZí°åÏÔʾ¼ì²âÁ˾Ö

³¢ÊÔÖ´ÐÐʱ£¬£¬ £¬£¬£¬£¬ÎÒÃǼì²âÓÐЧ¸ºÔØÎª¡° Ransom.Ekans¡±¡£¡£¡£¡£¡£ÎªÁ˲âÊÔ8827Ì«Ñô¼¯ÍÅÁíÒ»¸ö±£»£»£»£» £»¤²ã£¬£¬ £¬£¬£¬£¬ÎÒÃÇ»¹½ûÓÃÁË£¨²»½¨Ò飩¶ñÒâÈí¼þ±£»£»£»£» £»¤£¬£¬ £¬£¬£¬£¬ÒÔʹÐÐΪÒýÇæ²ûÑï×÷Óᣡ£¡£¡£¡£8827Ì«Ñô¼¯ÍÅ·´ÀÕË÷Èí¼þ¼¼Êõ¿ÉÄÜÔÚ²»Ê¹ÓÃÈκÎÊðÃûµÄÇé¿öϸôÀë¶ñÒâÎļþ¡£¡£¡£¡£¡£

ÀÕË÷Èí¼þÍÅ»ïË¿ºÁûÓÐͬÇéÖ®ÐÄ£¬£¬ £¬£¬£¬£¬¼´±ãÔÚÕâ¸öÓ¦¶ÔйÚÒßÇéµÄÌØÊâʱÆÚ£¬£¬ £¬£¬£¬£¬ËûÃÇÅ׳ÖÐøÒÔ´óÐ͹«Ë¾ÎªÖ¸±ê£¬£¬ £¬£¬£¬£¬´Ó¶øÀÕË÷¾Þ¶î×ʽ𡣡£¡£¡£¡£

Ŀǰ£¬£¬ £¬£¬£¬£¬Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©Òѱ»ÈËÃdzÆÎªÊǹ¥»÷Õß×îϲ»¶µÄÍ»ÆÆµã¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬ £¬£¬£¬£¬ÎÒÃÇ×î½ü»¹Ïàʶµ½Ò»¸öÔÊÐíÔ¶³ÌÖ´ÐеÄеÄSMB·ì϶¡£¡£¡£¡£¡£¶ÔÓÚ·ÀÓùÕß¶øÑÔ£¬£¬ £¬£¬£¬£¬³ÁÒªµÄÊÇÒªÕýÈ·±£»£»£»£» £»¤ËùÓÐ×ʲú£¬£¬ £¬£¬£¬£¬¶ÔÆä·ì϶ʵʱ½¨²¹£¬£¬ £¬£¬£¬£¬¶Å¾øÆä¹«¿ªÂ¶³ö¡£¡£¡£¡£¡£

ÈôÊÇÎÒÃÇ·¢ÏÖеÄÓйØÐÅÏ¢£¬£¬ £¬£¬£¬£¬ÎÒÃǽ«¸üд˲©¿ÍÎÄÕ¡£¡£¡£¡£¡££¨³ÖÐø±¨Â·Çë²ÎÕÕÔ­ÎÄ£©

IOCs

±¾ÌïÓйØÑùÆ·£º

EnelÓйصÄÑù±¾£º

enelint.global

²Î¿¼¼°ÆðÔ´£ºhttps://blog.malwarebytes.com/threat-analysis/2020/06/honda-and-enel-impacted-by-cyber-attack-suspected-to-be-ransomware/


£¨×ªÔØÀ´×Ô£ºÌÚÑ¶Íø£©

ÉÏһƪ ÏÂһƪ

7*24Ó×ʱ·þÎñÈÈÏß

400-624-3900


¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿