¶«É­Æ½Ì¨

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍøÄþ¾²×¨Ìâ > Äþ¾²×ÊѶ

Æû³µÖÆÔìÉ̱¾ÌïÔâÊÜÀÕË÷Èí¼þ¹¥»÷

×÷ÕߣºË»ºðRoarTalk 2020-06-18

1.png

Ó¢¹ú¹ã²¥¹«Ë¾£¨BBC£©Ðû²¼µÄÒ»·Ý³ÂËß³Æ £¬Æû³µÖÆÔìÉ̱¾ÌïÔâÊÜÁËÍøÂç¹¥»÷ £¬Ëæºó¸Ã¹«Ë¾ÔÚTwitterÉÏ֤ʵÁËÕâÒ»ÏûÏ¢¡£ÁíÒ»¸öͬÑùÔÚTwitterÉÏÅû¶µÄÀàËƹ¥»÷ʼþÊÇÏ®»÷ÁËEdesur SA £¬ÕâÊÇ°¢¸ùÍ¢EnelÆìϵÄÒ»¼Ò¹«Ë¾ £¬¸Ã¹«Ë¾ÔÚ²¼ÒËŵ˹°¬Àû˹ÊдÓÊÂÄÜÔ´·ÖÅäÒµÎñ¡£

ƾ¾ÝÍøÉÏÐû²¼µÄÑù±¾ £¬ÕâЩʼþ¿ÉÄÜÓëEKANS / SNAKEÀÕË÷Èí¼þ¼Ò×åÓйØ¡£ÔÚÕâƪÎÄÕÂÖÐ £¬ÎÒÃǻعËÁËÓйØÕâÖÖÀÕË÷Èí¼þµÄÏà¹ØÐÅÏ¢ÒÔ¼°µ½Ä¿Ç°ÎªÖ¹ÎÒÃÇÄܹ»½øÐеķÖÎö¡£

ÀÕË÷Èí¼þµÄÄ¿±ê

Äþ¾²Ñо¿ÈËÔ±Vitali KremezÊ״ιûÈ»Ìá¼°EKANSÀÕË÷Èí¼þµÄʱ¼ä¿ÉÒÔ×·Ëݵ½2020Äê1Ô £¬ÄÇʱVitali Kremez ·ÖÏíÁËÓйØʹÓÃGOLANG±àдµÄÐÂÐÍÀÕË÷Èí¼þµÄÐÅÏ¢¡£

Äþ¾²¹«Ë¾Dragos Ôڴ˲©¿ÍÖÐ×ö³öÏêϸ½éÉÜ¡£

2.png

ͼ1£ºEKANSÊê½ð¼Ç¼

6ÔÂ8ÈÕ £¬Ò»Î»Ñо¿ÈËÔ±·ÖÏíÁËÀÕË÷Èí¼þµÄÑù±¾ £¬ÕâЩÑù±¾¾Ý˵ÊÇÕë¶Ô±¾ÌïºÍEnelµÄ¡£ÔÚÎÒÃÇ¿ªÊ¼¼ì²ì´úÂëʱ £¬ÎÒÃÇÓÐÁËһЩ·¢ÏÖ £¬Ö¤ÊµÁËÕâÖÖ¿ÉÄÜÐÔ¡£

3.png

ͼ2£º»¥³â¼ì²é

4.png

ͼ3£ºÂôÁ¦Ö´ÐÐDNS²éѯµÄ¹¦Ð§

Ä¿±ê£º±¾Ìï

¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£] com

Ä¿±ê£ºEnel

¡ñ ½âÎöÄÚ²¿Óò£ºenelint.global

¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£] com

Ô¶³Ì×ÀÃæЭÒ飨RDP£©¿ÉÄÜÊǹ¥»÷µÄý½é

Á½¼Ò¹«Ë¾¶¼ÓÐһЩ´øÓÐÔ¶³Ì×ÀÃæЭÒ飨RDP£©·ÃÎÊȨÏ޵ļÆËã»ú¹ûÈ»£¨Çë²ÎÔÄ´Ë´¦£©¡£RDP¹¥»÷ÊÇÀÕË÷Èí¼þ²Ù×÷µÄÖ÷ÒªÇÐÈëµãÖ®Ò»¡£

²»Íâ £¬ÕâЩ½ö½öÊÇÍƲâ £¬²»ÄÜÍêÈ«¿Ï¶¨Õâ¾ÍÊÇÍþвÐÐΪÕß¹¥»÷µÄ·½Ê½¡£Ö»ÓнøÐÐÊʵ±µÄÄÚ²¿ÊÓ²ì £¬²ÅÆøÈ·ÇмòÖ±¶¨¹¥»÷ÕßÊÇÈçºÎÆÆ»µÍøÂçµÄ¡£

¼ì²â

ÎÒÃÇͨ¹ý´´½¨Ò»¸öαÔìµÄÄÚ²¿·þÎñÆ÷À´²âÊÔÔÚʵÑéÊÒÖйûÈ»ÌṩµÄÀÕË÷Èí¼þÑù±¾ £¬¸Ã·þÎñÆ÷½«ÏìÓ¦¶ñÒâÈí¼þ´úÂëʹÓÃÔ¤ÆÚµÄIPµØÖ·½øÐеÄDNS²éѯ¡£È»ºó £¬ÎÒÃǶÔMalwarebytes Nebula£¨ÎÒÃÇÃæÏòÆóÒµµÄ»ùÓÚÔƵĶ˵ã±£»¤£©½øÐÐÁ˾ݳÆÓë±¾ÌïÏà¹ØµÄÑù±¾²âÊÔ¡£

5.png

ͼ4£ºMalwarebytes NebulaÒDZí°åÏÔʾ¼ì²â½á¹û

ʵÑéÖ´ÐÐʱ £¬ÎÒÃǼì²âÓÐЧ¸ºÔØΪ¡° Ransom.Ekans¡±¡£ÎªÁ˲âÊÔÎÒÃǵÄÁíÒ»¸ö±£»¤²ã £¬ÎÒÃÇ»¹½ûÓÃÁË£¨²»½¨Ò飩¶ñÒâÈí¼þ±£»¤ £¬ÒÔʹÐÐΪÒýÇæ·¢»Ó×÷Óá£ÎÒÃǵķ´ÀÕË÷Èí¼þ¼¼ÊõÄܹ»ÔÚ²»Ê¹ÓÃÈκÎÇ©ÃûµÄÇé¿öϸôÀë¶ñÒâÎļþ¡£

ÀÕË÷Èí¼þÍÅ»ïË¿ºÁûÓÐâüÒþÖ®ÐÄ £¬¼´Ê¹ÔÚÕâ¸öÓ¦¶ÔйÚÒßÇéµÄÌØÊâʱÆÚ £¬ËûÃÇÈÓ¼ÌÐøÒÔ´óÐ͹«Ë¾ÎªÄ¿±ê £¬´Ó¶øÀÕË÷¾Þ¶î×ʽð¡£

Ä¿Ç° £¬Ô¶³Ì×ÀÃæЭÒ飨RDP£©Òѱ»ÈËÃdzÆΪÊǹ¥»÷Õß×îϲ»¶µÄÍ»ÆƵã¡£µ«ÊÇ £¬ÎÒÃÇ×î½ü»¹Á˽⵽һ¸öÔÊÐíÔ¶³ÌÖ´ÐеÄеÄSMB©¶´¡£¶ÔÓÚ·ÀÓùÕ߶øÑÔ £¬ÖØÒªµÄÊÇÒªÕýÈ·±£»¤ËùÓÐ×ʲú £¬¶ÔÆ䩶´¼°Ê±ÐÞ²¹ £¬¶Å¾øÆä¹ûȻ̻¶¡£

Èç¹ûÎÒÃÇ·¢ÏÖеÄÏà¹ØÐÅÏ¢ £¬ÎÒÃǽ«¸üд˲©¿ÍÎÄÕ¡££¨Á¬Ðø±¨µÀÇë²ÎÕÕÔ­ÎÄ£©

IOCs

±¾ÌïÏà¹ØÑùÆ·£º

EnelÏà¹ØµÄÑù±¾£º

enelint.global

²Î¿¼¼°À´Ô´£ºhttps://blog.malwarebytes.com/threat-analysis/2020/06/honda-and-enel-impacted-by-cyber-attack-suspected-to-be-ransomware/


£¨×ªÔØÀ´×Ô£ºÌÚѶÍø£©

ÉÏһƪ ÏÂһƪ

7*24Сʱ·þÎñÈÈÏß

400-624-3900


ÍøÕ¾µØͼ