ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍøÇ徲רÌâ > Çå¾²×ÊѶ

Æû³µÖÆÔìÉ̱¾ÌïÔâÊÜÀÕË÷Èí¼þ¹¥»÷

×÷ÕߣºË»ºðRoarTalk 2020-06-18

1.png

Ó¢¹ú¹ã²¥¹«Ë¾£¨BBC£©Ðû²¼µÄÒ»·Ý±¨¸æ³Æ£¬Æû³µÖÆÔìÉ̱¾ÌïÔâÊÜÁËÍøÂç¹¥»÷£¬Ëæºó¸Ã¹«Ë¾ÔÚTwitterÉÏ֤ʵÁËÕâÒ»ÐÂÎÅ¡£ÁíÒ»¸öͬÑùÔÚTwitterÉÏÅû¶µÄÀàËƹ¥»÷ÊÂÎñÊÇÏ®»÷ÁËEdesur SA£¬ÕâÊÇ°¢¸ùÍ¢EnelÆìϵÄÒ»¼Ò¹«Ë¾£¬¸Ã¹«Ë¾ÔÚ²¼ÒËŵ˹°¬Àû˹ÊдÓÊÂÄÜÔ´·ÖÅÉÓªÒµ¡£

ƾ֤ÍøÉÏÐû²¼µÄÑù±¾£¬ÕâЩÊÂÎñ¿ÉÄÜÓëEKANS / SNAKEÀÕË÷Èí¼þ¼Ò×åÓйØ¡£ÔÚÕâƪÎÄÕÂÖУ¬ÎÒÃÇ»ØÊ×ÁËÓйØÕâÖÖÀÕË÷Èí¼þµÄÏà¹ØÐÅÏ¢ÒÔ¼°µ½ÏÖÔÚΪֹÎÒÃÇÄܹ»¾ÙÐеÄÆÊÎö¡£

ÀÕË÷Èí¼þµÄÄ¿µÄ

Çå¾²Ñо¿Ö°Ô±Vitali KremezÊ״ιûÕæÌá¼°EKANSÀÕË÷Èí¼þµÄʱ¼ä¿ÉÒÔ×·Ëݵ½2020Äê1Ô£¬ÄÇʱVitali Kremez ·ÖÏíÁËÓйØʹÓÃGOLANG±àдµÄÐÂÐÍÀÕË÷Èí¼þµÄÐÅÏ¢¡£

Çå¾²¹«Ë¾Dragos Ôڴ˲©¿ÍÖÐ×ö³öÏêϸÏÈÈÝ¡£

2.png

ͼ1£ºEKANSÊê½ð¼Í¼

6ÔÂ8ÈÕ£¬Ò»Î»Ñо¿Ö°Ô±·ÖÏíÁËÀÕË÷Èí¼þµÄÑù±¾£¬ÕâЩÑù±¾Ìý˵ÊÇÕë¶Ô±¾ÌïºÍEnelµÄ¡£ÔÚÎÒÃÇ×îÏÈÉó²é´úÂëʱ£¬ÎÒÃÇÓÐÁËһЩ·¢Ã÷£¬Ö¤ÊµÁËÕâÖÖ¿ÉÄÜÐÔ¡£

3.png

ͼ2£º»¥³â¼ì²é

4.png

ͼ3£ºÈÏÕæÖ´ÐÐDNSÅÌÎʵĹ¦Ð§

Ä¿µÄ£º±¾Ìï

¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£] com

Ä¿µÄ£ºEnel

¡ñ ÆÊÎöÄÚ²¿Óò£ºenelint.global

¡ñ Êê½ðµç×ÓÓʼþ£ºCarrolBidell @ tutanota [¡£] com

Ô¶³Ì×ÀÃæЭÒ飨RDP£©¿ÉÄÜÊǹ¥»÷µÄÇ°ÑÔ

Á½¼Ò¹«Ë¾¶¼ÓÐһЩ´øÓÐÔ¶³Ì×ÀÃæЭÒ飨RDP£©»á¼ûȨÏÞµÄÅÌËã»ú¹ûÕ棨Çë²ÎÔÄ´Ë´¦£©¡£RDP¹¥»÷ÊÇÀÕË÷Èí¼þ²Ù×÷µÄÖ÷ÒªÇÐÈëµãÖ®Ò»¡£

²»¹ý£¬ÕâЩ½ö½öÊÇÍƲ⣬²»¿ÉÍêÈ«Ò»¶¨Õâ¾ÍÊÇÍþвÐÐΪÕß¹¥»÷µÄ·½·¨¡£Ö»ÓоÙÐÐÊʵ±µÄÄÚ²¿ÊӲ죬²Å»ªÈ·ÇмòÖ±¶¨¹¥»÷ÕßÊÇÔõÑùÆÆËðÍøÂçµÄ¡£

¼ì²â

ÎÒÃÇͨ¹ý½¨ÉèÒ»¸öαÔìµÄÄÚ²¿·þÎñÆ÷À´²âÊÔÔÚʵÑéÊÒÖйûÕæÌṩµÄÀÕË÷Èí¼þÑù±¾£¬¸Ã·þÎñÆ÷½«ÏìÓ¦¶ñÒâÈí¼þ´úÂëʹÓÃÔ¤ÆÚµÄIPµØµã¾ÙÐеÄDNSÅÌÎÊ¡£È»ºó£¬ÎÒÃǶÔMalwarebytes Nebula£¨ÎÒÃÇÃæÏòÆóÒµµÄ»ùÓÚÔƵĶ˵㱠£»¤£©¾ÙÐÐÁ˾ݳÆÓë±¾ÌïÏà¹ØµÄÑù±¾²âÊÔ¡£

5.png

ͼ4£ºMalwarebytes NebulaÒDZí°åÏÔʾ¼ì²âЧ¹û

ʵÑéÖ´ÐÐʱ£¬ÎÒÃǼì²âÓÐÓøºÔØΪ¡° Ransom.Ekans¡±¡£ÎªÁ˲âÊÔÎÒÃǵÄÁíÒ»¸ö± £»¤²ã£¬ÎÒÃÇ»¹½ûÓÃÁË£¨²»½¨Ò飩¶ñÒâÈí¼þ± £»¤£¬ÒÔʹÐÐΪÒýÇæÊ©Õ¹×÷Óá£ÎÒÃǵķ´ÀÕË÷Èí¼þÊÖÒÕÄܹ»ÔÚ²»Ê¹ÓÃÈκÎÊðÃûµÄÇéÐÎϸôÀë¶ñÒâÎļþ¡£

ÀÕË÷Èí¼þÍÅ»ïË¿ºÁûÓÐÁ¯ÃõÖ®ÐÄ£¬×ÝÈ»ÔÚÕâ¸öÓ¦¶ÔйÚÒßÇéµÄÌØÊâʱÆÚ£¬ËûÃÇÈÓ¼ÌÐøÒÔ´óÐ͹«Ë¾ÎªÄ¿µÄ£¬´Ó¶øÀÕË÷¾Þ¶î×ʽð¡£

ÏÖÔÚ£¬Ô¶³Ì×ÀÃæЭÒ飨RDP£©Òѱ»ÈËÃdzÆΪÊǹ¥»÷Õß×îϲ»¶µÄÍ»ÆƵã¡£¿ÉÊÇ£¬ÎÒÃÇ×î½ü»¹Ïàʶµ½Ò»¸öÔÊÐíÔ¶³ÌÖ´ÐеÄеÄSMBÎó²î¡£¹ØÓÚ·ÀÓùÕ߶øÑÔ£¬Ö÷ÒªµÄÊÇҪ׼ȷ± £»¤ËùÓÐ×ʲú£¬¶ÔÆäÎó²îʵʱÐÞ²¹£¬¶Å¾øÆä¹ûÕæ̻¶¡£

ÈôÊÇÎÒÃÇ·¢Ã÷еÄÏà¹ØÐÅÏ¢£¬ÎÒÃǽ«¸üд˲©¿ÍÎÄÕ¡££¨Ò»Á¬±¨µÀÇë²ÎÕÕÔ­ÎÄ£©

IOCs

±¾ÌïÏà¹ØÑùÆ·£º

EnelÏà¹ØµÄÑù±¾£º

enelint.global

²Î¿¼¼°ÈªÔ´£ºhttps://blog.malwarebytes.com/threat-analysis/2020/06/honda-and-enel-impacted-by-cyber-attack-suspected-to-be-ransomware/


£¨×ªÔØÀ´×Ô£ºÌÚѶÍø£©

ÉÏһƪ ÏÂһƪ

·þÎñÈÈÏß

400-624-3900



ÍøÕ¾µØͼ