Ͷ×ÊÕß¹Øϵ
Ó¢¹ú¹ã²¥¹«Ë¾£¨BBC£©Ðû²¼µÄÒ»·Ý³ÂË߳ƣ¬Æû³µÖÆÔìÉ̱¾ÌïÔâÊÜÁËÍøÂç¹¥»÷£¬Ëæºó¸Ã¹«Ë¾ÔÚTwitterÉÏ֤ʵÁËÕâÒ»ÏûÏ¢¡£ÁíÒ»¸öͬÑùÔÚTwitterÉÏÅû¶µÄÀàËƹ¥»÷ʼþÊÇÏ®»÷ÁËEdesur SA£¬ÕâÊÇ°¢¸ùÍ¢EnelÆìϵÄÒ»¼Ò¹«Ë¾£¬¸Ã¹«Ë¾ÔÚ²¼ÒËŵ˹°¬Àû˹ÊдÓÊÂÄÜÔ´·ÖÅäÒµÎñ¡£
ƾ¾ÝÍøÉÏÐû²¼µÄÑù±¾£¬ÕâЩʼþ¿ÉÄÜÓëEKANS / SNAKEÀÕË÷Èí¼þ¼Ò×åÓйء£ÔÚÕâƪÎÄÕÂÖУ¬ÎÒÃǻعËÁËÓйØÕâÖÖÀÕË÷Èí¼þµÄÏà¹ØÐÅÏ¢ÒÔ¼°µ½Ä¿Ç°ÎªÖ¹ÎÒÃÇÄܹ»½øÐеķÖÎö¡£
ÀÕË÷Èí¼þµÄÄ¿±ê
Äþ¾²Ñо¿ÈËÔ±Vitali KremezÊ״ιûÈ»Ìá¼°EKANSÀÕË÷Èí¼þµÄʱ¼ä¿ÉÒÔ×·Ëݵ½2020Äê1Ô£¬ÄÇʱVitali Kremez ·ÖÏíÁËÓйØʹÓÃGOLANG±àдµÄÐÂÐÍÀÕË÷Èí¼þµÄÐÅÏ¢¡£
Äþ¾²¹«Ë¾Dragos Ôڴ˲©¿ÍÖÐ×ö³öÏêϸ½éÉÜ¡£
ͼ1£ºEKANSÊê½ð¼Ç¼
6ÔÂ8ÈÕ£¬Ò»Î»Ñо¿ÈËÔ±·ÖÏíÁËÀÕË÷Èí¼þµÄÑù±¾£¬ÕâЩÑù±¾¾Ý˵ÊÇÕë¶Ô±¾ÌïºÍEnelµÄ¡£ÔÚÎÒÃÇ¿ªÊ¼¼ì²ì´úÂëʱ£¬ÎÒÃÇÓÐÁËһЩ·¢ÏÖ£¬Ö¤ÊµÁËÕâÖÖ¿ÉÄÜÐÔ¡£
ͼ2£º»¥³â¼ì²é
ͼ3£ºÂôÁ¦Ö´ÐÐDNS²éѯµÄ¹¦Ð§
Ä¿±ê£º±¾Ìï
¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£] com
Ä¿±ê£ºEnel
¡ñ ½âÎöÄÚ²¿Óò£ºenelint.global
¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£] com
Ô¶³Ì×ÀÃæÐÒ飨RDP£©¿ÉÄÜÊǹ¥»÷µÄý½é
Á½¼Ò¹«Ë¾¶¼ÓÐһЩ´øÓÐÔ¶³Ì×ÀÃæÐÒ飨RDP£©·ÃÎÊȨÏ޵ļÆËã»ú¹ûÈ»£¨Çë²ÎÔÄ´Ë´¦£©¡£RDP¹¥»÷ÊÇÀÕË÷Èí¼þ²Ù×÷µÄÖ÷ÒªÇÐÈëµãÖ®Ò»¡£
²»Í⣬ÕâЩ½ö½öÊÇÍƲ⣬²»ÄÜÍêÈ«¿Ï¶¨Õâ¾ÍÊÇÍþвÐÐΪÕß¹¥»÷µÄ·½Ê½¡£Ö»ÓнøÐÐÊʵ±µÄÄÚ²¿ÊӲ죬²ÅÆøÈ·ÇмòÖ±¶¨¹¥»÷ÕßÊÇÈçºÎÆÆ»µÍøÂçµÄ¡£
¼ì²â
ÎÒÃÇͨ¹ý´´½¨Ò»¸öαÔìµÄÄÚ²¿·þÎñÆ÷À´²âÊÔÔÚʵÑéÊÒÖйûÈ»ÌṩµÄÀÕË÷Èí¼þÑù±¾£¬¸Ã·þÎñÆ÷½«ÏìÓ¦¶ñÒâÈí¼þ´úÂëʹÓÃÔ¤ÆÚµÄIPµØÖ·½øÐеÄDNS²éѯ¡£È»ºó£¬ÎÒÃǶÔMalwarebytes Nebula£¨ÎÒÃÇÃæÏòÆóÒµµÄ»ùÓÚÔƵĶ˵㱣»¤£©½øÐÐÁ˾ݳÆÓë±¾ÌïÏà¹ØµÄÑù±¾²âÊÔ¡£
ͼ4£ºMalwarebytes NebulaÒDZí°åÏÔʾ¼ì²â½á¹û
ʵÑéÖ´ÐÐʱ£¬ÎÒÃǼì²âÓÐЧ¸ºÔØΪ¡° Ransom.Ekans¡±¡£ÎªÁ˲âÊÔÎÒÃǵÄÁíÒ»¸ö±£»¤²ã£¬ÎÒÃÇ»¹½ûÓÃÁË£¨²»½¨Ò飩¶ñÒâÈí¼þ±£»¤£¬ÒÔʹÐÐΪÒýÇæ·¢»Ó×÷Óá£ÎÒÃǵķ´ÀÕË÷Èí¼þ¼¼ÊõÄܹ»ÔÚ²»Ê¹ÓÃÈκÎÇ©ÃûµÄÇé¿öϸôÀë¶ñÒâÎļþ¡£
ÀÕË÷Èí¼þÍÅ»ïË¿ºÁûÓÐâüÒþÖ®ÐÄ£¬¼´Ê¹ÔÚÕâ¸öÓ¦¶ÔйÚÒßÇéµÄÌØÊâʱÆÚ£¬ËûÃÇÈÓ¼ÌÐøÒÔ´óÐ͹«Ë¾ÎªÄ¿±ê£¬´Ó¶øÀÕË÷¾Þ¶î×ʽð¡£
Ä¿Ç°£¬Ô¶³Ì×ÀÃæÐÒ飨RDP£©Òѱ»ÈËÃdzÆΪÊǹ¥»÷Õß×îϲ»¶µÄÍ»ÆƵ㡣µ«ÊÇ£¬ÎÒÃÇ×î½ü»¹Á˽⵽һ¸öÔÊÐíÔ¶³ÌÖ´ÐеÄеÄSMB©¶´¡£¶ÔÓÚ·ÀÓùÕ߶øÑÔ£¬ÖØÒªµÄÊÇÒªÕýÈ·±£»¤ËùÓÐ×ʲú£¬¶ÔÆ䩶´¼°Ê±ÐÞ²¹£¬¶Å¾øÆä¹ûȻ̻¶¡£
Èç¹ûÎÒÃÇ·¢ÏÖеÄÏà¹ØÐÅÏ¢£¬ÎÒÃǽ«¸üд˲©¿ÍÎÄÕ¡££¨Á¬Ðø±¨µÀÇë²ÎÕÕÔÎÄ£©
IOCs
±¾ÌïÏà¹ØÑùÆ·£º
EnelÏà¹ØµÄÑù±¾£º
enelint.global
²Î¿¼¼°À´Ô´£ºhttps://blog.malwarebytes.com/threat-analysis/2020/06/honda-and-enel-impacted-by-cyber-attack-suspected-to-be-ransomware/
£¨×ªÔØÀ´×Ô£ºÌÚѶÍø£©
400-624-3900
Copyright ? ¶«Éƽ̨ °æȨËùÓÐ ¾©ICP±¸05032414ºÅ ¾©¹«Íø°²±¸11010802024551ºÅ