Ͷ×ÊÕß¹ØÏµ

Ó¢¹ú¹ã²¥¹«Ë¾£¨BBC£©°ä²¼µÄÒ»·Ý»ã±¨³Æ£¬£¬£¬Æû³µÖÆ×÷É̱¾ÌïÔâ·êÁËÍøÂç¹¥»÷£¬£¬£¬Ëæºó¸Ã¹«Ë¾ÔÚTwitterÉÏ֤ʵÁËÕâÒ»ÐÂÎÅ¡£ÁíÒ»¸öͬÑùÔÚTwitterÉÏÅû¶µÄÀàËÆ¹¥»÷ÊÂÎñÊÇÏ®»÷ÁËEdesur SA£¬£¬£¬ÕâÊǰ¢¸ùÍ¢EnelÆìϵÄÒ»¼Ò¹«Ë¾£¬£¬£¬¸Ã¹«Ë¾ÔÚ²¼ÒËŵ˹°¬Àû˹ÊдÓÊÂÄÜÔ´·ÖÅäÒµÎñ¡£
ƾ¾ÝÍøÉϰ䲼µÄÑù±¾£¬£¬£¬ÕâЩÊÂÎñ¿ÉÄÜÓëEKANS / SNAKEÀÕË÷Èí¼þ¼Ò×åÓйء£ÔÚÕâÆªÎÄÕÂÖУ¬£¬£¬ÎÒÃÇ»ØÊ×ÁËÓйØÕâÖÖÀÕË÷Èí¼þµÄÓйØÐÅÏ¢ÒÔ¼°µ½Ä¿Ç°ÎªÖ¹ÎÒÃÇ¿ÉÄܽøÐеķÖÎö¡£
ÀÕË÷Èí¼þµÄÖ¸±ê
°²È«×êÑÐÈËÔ±Vitali Kremez³õ´Î¹«¿ªÌá¼°EKANSÀÕË÷Èí¼þµÄ¹¦·òÄܹ»×·Òäµ½2020Äê1Ô£¬£¬£¬ÄÇʱVitali Kremez ·ÖÏíÁËÓйØÊ¹ÓÃGOLANG±àдµÄÐÂÐÍÀÕË÷Èí¼þµÄÐÅÏ¢¡£
°²È«¹«Ë¾Dragos Ôڴ˲©¿ÍÖÐ×ö³ö¾ßÌå½éÉÜ¡£

ͼ1£º£º£ºEKANSÊê½ð¼Í¼
6ÔÂ8ÈÕ£¬£¬£¬Ò»Î»×êÑÐÈËÔ±·ÖÏíÁËÀÕË÷Èí¼þµÄÑù±¾£¬£¬£¬ÕâЩÑù±¾Ìý˵ÊÇÕë¶Ô±¾ÌïºÍEnelµÄ¡£ÔÚÎÒÃÇÆðÍ·²é¿´´úÂëʱ£¬£¬£¬ÎÒÃÇÓÐÁËһЩ·¢ÏÖ£¬£¬£¬Ö¤ÊµÁËÕâÖÖ¿ÉÄÜÐÔ¡£

ͼ2£º£º£º»¥³â²é³

ͼ3£º£º£ºÕƹÜÖ´ÐÐDNS²éÎʵÄÖ°ÄÜ
Ö¸±ê£º£º£º±¾Ìï
¡ñ Êê½ðµç×ÓÓʼþ£º£º£ºCarrolBidell @ tutanota [¡£] com
Ö¸±ê£º£º£ºEnel
¡ñ ½âÎöÄÚ²¿Óò£º£º£ºenelint.global
¡ñ Êê½ðµç×ÓÓʼþ£º£º£ºCarrolBidell @ tutanota [¡£] com
Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©¿ÉÄÜÊǹ¥»÷µÄý½é
Á½¼Ò¹«Ë¾¶¼ÓÐһЩ´øÓÐÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©½Ó¼ûȨÏÞµÄÍÆËã»ú¹«¿ª£¨Çë²ÎÔÄ´Ë´¦£©¡£RDP¹¥»÷ÊÇÀÕË÷Èí¼þ²Ù×÷µÄÖØÒªÇÐÈëµãÖ®Ò»¡£
²»Í⣬£¬£¬ÕâЩ½ö½öÊÇ´§Ä¦£¬£¬£¬²»ÄÜÆëȫע¶¨Õâ¾ÍÊÇÍþвÐÐΪÕß¹¥»÷µÄ·½Ê½¡£Ö»ÓнøÐÐÊʵ±µÄÄÚ²¿µ÷²é£¬£¬£¬ÄÜÁ¦È·ÇмòÖ±¶¨¹¥»÷ÕßÊÇÈôºÎ·ÛËéÍøÂçµÄ¡£
¼ì²â
ÎÒÃÇͨ¹ý´´½¨Ò»¸öαÔìµÄÄÚ²¿·þÎñÆ÷À´²âÊÔÔÚ³¢ÊÔÊÒÖй«¿ªÌṩµÄÀÕË÷Èí¼þÑù±¾£¬£¬£¬¸Ã·þÎñÆ÷½«ÏìÓ¦¶ñÒâÈí¼þ´úÂëʹÓÃÔ¤ÆÚµÄIPµØÖ·½øÐеÄDNS²éÎÊ¡£¶øºó£¬£¬£¬ÎÒÃǶÔMalwarebytes Nebula£¨ÎÒÃÇÃæÏòÆóÒµµÄ»ùÓÚÔÆµÄ¶Ëµã±£»¤£©½øÐÐÁ˾ݳÆÓë±¾ÌïÓйصÄÑù±¾²âÊÔ¡£

ͼ4£º£º£ºMalwarebytes NebulaÒDZí°åÏÔʾ¼ì²âÁ˾Ö
³¢ÊÔÖ´ÐÐʱ£¬£¬£¬ÎÒÃǼì²âÓÐЧ¸ºÔØÎª¡° Ransom.Ekans¡±¡£ÎªÁ˲âÊÔOG¶«·½ÌüÁíÒ»¸ö±£»¤²ã£¬£¬£¬ÎÒÃÇ»¹½ûÓÃÁË£¨²»½¨Ò飩¶ñÒâÈí¼þ±£»¤£¬£¬£¬ÒÔʹÐÐΪÒýÇæ²ûÑï×÷Óá£OG¶«·½Ìü·´ÀÕË÷Èí¼þ¼¼Êõ¿ÉÄÜÔÚ²»Ê¹ÓÃÈκÎÊðÃûµÄÇé¿öϸôÀë¶ñÒâÎļþ¡£
ÀÕË÷Èí¼þÍÅ»ïË¿ºÁûÓÐͬÇéÖ®ÐÄ£¬£¬£¬¼´±ãÔÚÕâ¸öÓ¦¶ÔйÚÒßÇéµÄÌØÊâʱÆÚ£¬£¬£¬ËûÃÇÈÓ³ÖÐøÒÔ´óÐ͹«Ë¾ÎªÖ¸±ê£¬£¬£¬´Ó¶øÀÕË÷¾Þ¶î×ʽð¡£
Ŀǰ£¬£¬£¬Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©Òѱ»ÈËÃdzÆÎªÊǹ¥»÷Õß×îϲ»¶µÄÍ»ÆÆµã¡£µ«ÊÇ£¬£¬£¬ÎÒÃÇ×î½ü»¹Ïàʶµ½Ò»¸öÔÊÐíÔ¶³ÌÖ´ÐеÄеÄSMB·ì϶¡£¶ÔÓÚ·ÀÓùÕß¶øÑÔ£¬£¬£¬ÖØÒªµÄÊÇÒªÕýÈ·±£»¤ËùÓÐ×ʲú£¬£¬£¬¶ÔÆä·ì϶ʵʱÐÞ²¹£¬£¬£¬¶Å¾øÆä¹«¿ªÂ¶³ö¡£
ÈôÊÇÎÒÃÇ·¢ÏÖеÄÓйØÐÅÏ¢£¬£¬£¬ÎÒÃǽ«¸üд˲©¿ÍÎÄÕ¡££¨³ÖÐø±¨µÀÇë²ÎÕÕÔÎÄ£©
IOCs
±¾ÌïÓйØÑùÆ·£º£º£º
EnelÓйصÄÑù±¾£º£º£º
enelint.global
²Î¿¼¼°ÆðÔ´£º£º£ºhttps://blog.malwarebytes.com/threat-analysis/2020/06/honda-and-enel-impacted-by-cyber-attack-suspected-to-be-ransomware/
£¨×ªÔØÀ´×Ô£º£º£ºÌÚÑ¶Íø£©
400-624-3900
Copyright ? OG¶«·½Ìü °æÈ¨ËùÓÐ ¾©ICP±¸05032414ºÅ
¾©¹«Íø°²±¸11010802024551ºÅ

