免費防毒軟體的三大威脅

這幾年全球重大資安事件頻傳,世界容易遭受駭客病毒攻擊國家,香港、台灣一直也名列前茅,資安意識雖逐年抬頭,但心存僥倖的仍不少,這也是為什麼每次香港、台灣也都會無法幸免於難的主因,在與大家討論到底要使用免費防毒軟體還是付費防毒軟體前,想先問各位兩個簡單的問題,

您(公司)是否願意用很低的金額或無償交換您(公司)的隱私或財產,如個資及重要文件檔案等…,卻只能獲得基本的病毒防護?!

您(公司)會使用一個免費的鎖在您家的大門上,讓提供免費鎖的公司有鑰匙進入您的房子,還是您願意花小錢購買了全功能的鎖而只有您有鑰匙可以進入家門呢?!

我想答案已很清楚了,接下來跟大家分析使用免費防毒軟體及付費防毒軟體的差別,

1. 隱私/財產全都露

天下沒有白吃的午餐,這個道理人人都懂,絕大多數的防毒軟體都是由專業的資安公司所推出,它具有一定的開發以及維護成本,例如研發人員需要撰寫防毒軟體的程式,並且隨時收集最新的病毒資訊,還要發佈更新檔,以提升防毒軟體的防護能力。然而如果消費者選擇的是免費的防毒軟體,那麼這些成本是要如何回收呢?大家可以好好的思考一下….

之前時有所聞,免費的防毒軟體更改使用者條款,放寬使用者個人資料的使用限制,讓廠商可能可以將使用者的瀏覽器歷史記錄、搜尋記錄、GPS定位記錄等無法辨識個人身份的資料,出售給廣告商,用來作為廣告投放的參考依據。請問您在下載或使用這些軟體之前,是否都有仔細的閱讀這些相關的條約內容,還是想快點把軟體程式安裝完,就只是按「Yes」或「同意」;又如果軟體沒有繁體中文的說明,您是否也有耐下心來逐一閱讀呢。如果以上情況您都有的話,那麼”恭喜”您,您己經將您的隱私曝光在陽光下了。

結論:花小錢_即可確保你的隱私安全

2. 當災難發生時,只能坐以待斃

若您不幸遭受資安威脅侵害時,使用免費防毒軟體,則求救無門,只能花錢了事,以2017年讓人聞之色變的勒索病毒為例,通常會向受害者勒索價值 50 至 500 美金不等的贖金,並要求以比特幣付款,如果以美金 50 元來計算的話,大約等於港幣 400 元,已經比一般防毒軟體一年授權的費用還要高了,再加上您不幸被勒索的金額是美金 500 元的話,就等於需要支付港幣 4,000 元;好一點的是您付了錢,勒索者會提供解密金鑰,讓您拿回檔案,算是花錢消災。慘一點的,付了錢,檔案還是付之一炬。請問您是要省一時的小錢保護您的重要檔案資料,還是要花您無法預測且一定得支付的大錢呢? 建議您好好思考這個問題….

反觀,使用付費防毒軟體時,完整的防護功能或機制,除了協助您即時抵禦資安之威脅外,您還也可以跟在地團隊透過客服電話或請他們派專人至公司享受專業的資安服務,讓您或公司的損失可以降至最低。

結論:花小錢_即可享”網路安全”大效益,還能保護重要資料及享有在地且專業的資安團隊服務

3. 軟體或系統的漏洞的潛在資安威脅

天下沒有完美的事物,軟體會有Bug,就跟一般人會說錯話、寫錯字一樣,在所難免。不論是硬體或硬體的因素,系統只要出一次包,就可能影響成千上萬使用者。但其中執行的程式一旦有功能性的失誤,甚至有安全性漏洞,想要修正就沒那麼簡單,來來回回之間,往往耗費許多時間和人力進行。對許多IT人員來說,持續關注系統資安弱點資訊、定期執行漏洞修補,已經成為例行公事之一。從2001到2003年之間,開始有許多惡意程式利用Windows、IE、Outlook Express、Outlook的安全性弱點發動攻擊,肆虐全球個人電腦與伺服器,像是Code Red、Nimda、Blaster、Sasser等蠕蟲。

除了微軟,在個人電腦使用率相當高的數位內容格式Adobe PDF和Flash在2009年之後,也因為漏洞而頻頻遭到攻擊,到了2012年、2013年,Java成為新的苦主,再舉2017年「WanaCrypt0r 2.0」的勒索軟體攻擊感染,近乎所有 Windows 系統及其伺服器版本均受威脅,而這都在在證明知名及很多人在使用的軟體,是駭害的最愛,因為每次出手皆有斬獲,這真的不是危言聳聽。

以上所述,也都不是只具簡單及基本防護功能的免費防毒軟體所能解決的,因此對抗無法預期的軟體或系統漏洞所產生的已知或未知的資安威脅,選擇專業且知名的資安品牌或解決方案來做防護或抵禦是很重要的。

結論:花小錢_買專業知名的資安產品或解決方案,方能高枕無憂

 

 

關於Version 2 Limited

Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

 

關於ESET

ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。 

ESET boosts value proposition for MSPs via new direct plug-in with ConnectWise

ESET today announced the launch of ESET Direct Endpoint Management with ConnectWise, a company that transforms how technology solution providers build, manage, and grow their businesses. The new Remote Management and Monitoring (RMM) plug-in for ConnectWise Automate speeds up and improves installation processes of ESET endpoints for the company’s Managed Service Providers (MSPs).

ESET Direct Endpoint Management establishes a direct connection between ESET endpoints and the ConnectWise Automate console. Built with the ConnectWise equipped partner in mind, the plug-in leverages the existing ConnectWise Agent to simplify deployment and management without sacrificing on performance or functionality.

While ESET currently offers a plug-in that connects ESET Remote Administrator (ERA) and ConnectWise Automate, this new version does not require MSPs to install ERA at all, meaning there are no additional servers or intermediate console to manage.  MSPs can get up and running faster, and stay running with fewer issues caused by complex integration. 

“We’ve had a strong relationship with ESET for many years, and from working with them, we know that we are partnering with a proven and reliable technology company,” said Travis Vigneau, director of channel sales and alliances for ConnectWise. “This new direct plug-in demonstrates ESET’s commitment to constantly improving what they offer to the entire ecosystem.”

“We understand how important our MSPs are and we want to help them overcome any challenges they may face,” said Jeronimo Varela, Director of Global Sales at ESET. “That’s why we’ve focused on developing the very best tools, with world-class protection solutions, to not only ensure our MSPs can deliver top-quality service efficiently, but also so that they can become trusted advisors to their customers.”

To find out more about ESET’s MSP program, please click here.

About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries. 

About ConnectWise

ConnectWise transforms how technology solution providers successfully build, manage and grow their businesses. Our award-winning set of software solutions provides a fully integrated, seamless experience to companies in more than 50 countries, giving them the ability to increase their productivity, efficiency and profitability. When combined with our relentless commitment to innovation, powerful network of ideas and experts, unparalleled passion for our users, and more than 35 years of experience, ConnectWise software solutions deliver the support companies want at each step of their business journey. For more information, visit www.ConnectWise.com.

FriedEx: BitPaymer ransomware the work of Dridex authors

Dridex has been a nightmare for computer users, companies and financial institutions for several years now, so much so that for many, it has become the first thing that comes to mind when talking about banking trojans.

Recent ESET research shows that the authors of the infamous Dridex banking trojan are also behind another high-profile malware family – a sophisticated ransomware detected by ESET products as Win32/Filecoder.FriedEx and Win64/ Filecoder.FriedEx, and also known as BitPaymer.

Dridex

The Dridex banking trojan first appeared in 2014 as a relatively simple bot inspired by older projects, but the authors quickly turned this bot into one of the most sophisticated banking trojans on the market. The development seems to be steady, with new versions of the bot including minor fixes and updates being released on a weekly basis, with occasional breaks. From time to time, the authors introduce a major update that adds some crucial functionality or larger changes. The last major update from version 3 to version 4, released at the beginning of 2017, gained attention for adopting the Atom Bombing injection technique, and later in the year also introducing a new MS Word zero-day exploit, which helped spread the trojan to millions of victims.

As of this writing, the most recent version of Dridex is 4.80 and includes support for webinjects into Chrome version 63. Dridex 4.80 was released on December 14th 2017.

Note: Last year we released a tool that helps identify malicious hooks in popular web browsers. The tool is designed to help incident responders discover potential banking trojan infections, including Dridex.

FriedEx

Initially dubbed BitPaymer, based on text in its ransom demand web site, this ransomware was discovered in early July 2017 by Michael Gillespie. In August, it returned to the spotlight and made headlines by infecting NHS hospitals in Scotland.

FriedEx focuses on higher profile targets and companies rather than regular end users and is usually delivered via an RDP brute force attack. The ransomware encrypts each file with a randomly generated RC4 key, which is then encrypted using the hardcoded 1024-bit RSA public key and saved in the corresponding .readme_txt file.

In December 2017, we took a closer look at one of the FriedEx samples and almost instantly noticed the resemblance of the code to Dridex. Intrigued by the initial findings, we dug deep into the FriedEx samples, and found out that FriedEx uses the same techniques as Dridex to hide as much information about its behavior as possible.

It resolves all system API calls on the fly by searching for them by hash, stores all strings in encrypted form, looks up registry keys and values by hash, etc. The resulting binary is very low profile in terms of static features and it’s very hard to tell what the malware is doing without a deeper analysis.

This prompted yet further analysis, which revealed a number of additional attributes that confirmed our initial suspicions – the two malware families were created by the same developers.

Code Similarities

Figure 1. Comparison of GetUserID function present in both Dridex and FriedEx samples

In Figure 1, we can see a part of a function used for generating UserID that can be found across all Dridex binaries (both loaders and bot modules). As we can see, the very same Dridex-specific function is also used in the FriedEx binaries. The function produces the same results – it generates a string from several attributes of the victim’s machine that serves as a unique identifier of the given victim, either in the botnet in the case of Dridex, or of the ransomware with FriedEx. Indeed, the screenshots would make for a good “Spot the difference” game!

This kind of similarity to Dridex is present throughout the FriedEx binaries and only very few functions that mostly correspond to the specific ransomware functionality are not found in the Dridex sample (i.e. the file encryption loop and creation of ransom message files).

 Figure 2. Comparison of function order in Dridex and FriedEx samples. 
Functions that are missing in the other sample are highlighted in the corresponding color

Another shared feature is the order of the functions in the binaries, which occurs when the same codebase or static library is used in multiple projects. As we can see in Figure 2, while the FriedEx sample seems to be missing some of the functions present in the Dridex sample and vice versa (which is caused by the compiler omitting unreferenced/unused functions), the order remains the same.

Note: Auto-generated function name pairs, based on code addresses (sub_CA5191 and sub_2A56A2, etc), obviously do not match, but the code they refer to does.

It’s also worth mentioning that both Dridex and FriedEx use the same malware packer. However, since the packer is very popular nowadays (probably due to its effectiveness in avoiding detection and hampering analysis) and used by other well-known families like QBot, Emotet or Ursnif, we don’t really consider that alone strong evidence.

PDB paths

When building a Windows executable, the linker may include a PDB (Program Database) path pointing to a file that contains debug symbols that help the developer with debugging and identifying crashes. The actual PDB file is almost never present in malware, because it’s a separate file that doesn’t get into distribution. However, sometimes even just the path, if included, can provide valuable information, because PDB files are located in the same directory as the compiled executable by default and usually also have the same base name followed by the .pdb extension.

As one might guess, PDB paths are not included in malware binaries very often, as the attackers don’t want to give away any information. Fortunately, some samples of both families do include PDB paths.

Figure 3. List of all PDB paths found in the Dridex and FriedEx projects

As you can see in Figure 3, the binaries of both projects are being built in the same, distinctively named directory. Based on a search across all of our malware sample metadata, we have concluded that the path S:\Work\_bin\ is unique to the Dridex and FriedEx projects.

Timestamps

We found several cases of Dridex and FriedEx with the same date of compilation. This could, of course, be coincidence, but after a closer look, we quickly ruled out the “just a coincidence” theory.

Not only do the compilations with the same date have time differences of several minutes at most (which implies Dridex guys probably compile both projects concurrently), but the randomly generated constants are also identical in these samples. These constants change with each compilation as a form of polymorphism, to make the analysis harder and to help avoid detection.

This might be completely randomized in each compilation or based on some variable like the current date.

Figure 4. GetAPIByHash function in Dridex samples with compilation time difference of 3 days. The highlighted constant is different

In Figure 4, we have the comparison of two Dridex loader samples with a three-day difference between compilation timestamps. While the loaders are almost identical with the only difference being their hardcoded data, such as encryption keys and C&C IPs, the constants are different, and so are all the hashes that are based on them. On the other hand, in Figure 5, we can see the comparison of the FriedEx and Dridex loader from the same day (in fact, with timestamps just two minutes apart). Here, the constants are the same, meaning both were probably built during the same compilation session.

Figure 5. GetAPIByHash function in Dridex and FriedEx binaries compiled the same day. 
The highlighted constant is the same in both samples

Compiler information

The compiler information only further supports all the evidence we found so far – the binaries of both Dridex and FriedEx are compiled in Visual Studio 2015. This is confirmed by both the linker version found in the PE Header and Rich Header data.

Figure 6. Rich header data found in Dridex and FriedEx samples

Apart from the obvious similarities with Dridex, we came across a previously unreported 64-bit variant of the ransomware. As the usual 32-bit version of the ransomware can target both x86 and x64 systems, we consider this variant to be a bit of a curiosity.

Conclusion

With all this evidence, we confidently claim that FriedEx is indeed the work of the Dridex developers. This discovery gives us a better picture of the group’s activities – we can see that the group continues to be active and not only consistently updates their banking trojan to maintain its webinject support for the latest versions of Chrome and to introduce new features like Atom Bombing, but that it also follows the latest malware “trends”, creating their own ransomware.

We can only guess what the future will bring, but we can be sure that the Dridex gang isn’t going anywhere anytime soon and that they will keep innovating their old project and possibly extend their portfolio with a new piece here and there.

For a long time, it was believed that the Dridex gang was a one-trick pony that kept their focus on their banking trojan. We have now found that this is not the case and that they can easily adapt to the newest trends and create a different kind of malware that can compete with the most advanced in its category.

IoCs

Win32/Dridex.BE C70BD77A5415B5DCF66B7095B22A0DEE2DDA95A0

Win64/FriedEx.A CF1038C9AED9239B6A54EFF17EB61CAB2EE12141

Win32/FriedEx.A 8AE1C1869C42DAA035032341804AEFC3E7F3CAF1

 

 

About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

 

About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries. 

AV-Comparatives Names ESET Endpoint Security Solution as the Lightest on the Market

Today, global IT security vendor ESET has been awarded top marks by AV-ComparativesESET Endpoint Security has been named the lightest endpoint security solution on the market by the world’s leading security software testers AV-Comparatives. Following a series of performance tests on a number of endpoint security solutions, ESET Endpoint Security was commended for its low system impact.


Using one of the largest sample collections in the world, AV-Comparatives provides the most accurate test by creating a real-world environment and replicating the scenarios faced by everyday users.

ESET Endpoint Security provides businesses comprehensive IT security via multiple layers of protection including trademark NOD32® detection technology combined with machine learning. It protects networks from malware and phishing attacks and stops harmful malware from breaching your system. It provides complete data access protection and fully adjustable scanning, including cloud-powered scanning.


“ESET’s business solution made an impressive run in another of our Business performance tests, reaching the lowest impact score of all tested solutions,” commented Andreas Clementi, CEO at AV-Comparatives.


AV-Comparatives rated ESET’s product at an industry high, with a total score of 98.3 in the industry recognized PC Mark tests. The software was praised as ‘very fast’ for browsing websites, launching applications, installing and uninstalling applications, downloading files, as well as archiving and unarchiving files.


“We pride ourselves on developing products that give the most robust protection to enterprises without slowing down their systems,” said Michal Jankech, Business Product Manager. “AV-Comparatives is the most renowned testing organization out there so it’s great to see that ESET Endpoint Security software has scored as the lightest on the market. Business and consumers can rest assured their systems won’t be impacted and will continue to run at high speeds, all while maintaining the highest level of protection.”

You can read more about ESET Endpoint Security and request a free trial here.

Read the whole report by AV-Comparatives here.
 

About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries. 

Bad Rabbit:勒索病毒Not-Petya變種重現

最新資訊(中歐時間10月27日15:35時):一份新報告指出,美國國家安全局所洩露的駭客工具之一“EternalRomance”,已被利用來在網路上傳播Diskcoder.D。我們透過安裝微軟公司緊急漏洞修復MS17-010(用以彌補美國國家安全局洩露駭客工具所利用的系統漏洞)來確認此訊息,並從而阻止該惡意程式借助IPC$共用資料夾方式進一步散佈。

一款新的勒索病毒於10月24日爆發,已攻擊包括歐洲大部分地鐵系統,其中也包含烏克蘭部分重要基礎通訊設施。有關這一新變種的詳細介紹,請見下文。

藉助對知名網站進行Watering Hole(水坑)攻擊,使使用者在不察覺的情況下自動下載

Bad Rabbit的散佈途徑之一,就是在使用者毫無察覺的情況下自動下載。一些知名網站已被攻陷,HTML文本或某個.js檔之中被植入了Java腳本。

植入腳本後的樣本如下所示:

該腳本向185.149.120[.]3回饋資訊,目前該位址暫無回應。

  • 瀏覽器使用者代理
  • 引用頁
  • 已訪問網站的cookie
  • 已訪問網站的功能變數名稱

透過攻擊伺服器端邏輯運算,認定訪客是否具有攻擊價值,之後再把內容添加到頁面之中。此時可看到彈跳視窗,頁面中央顯示請使用者下載Flash播放機更新版的提示資訊。

點擊“安裝”按鈕後,便開始啟動來自1dnscontrol[.]com的可執行檔下載進程。可執行檔名為install_flash_player.exe,實際就是W32/Diskcoder.D下載器。

最終電腦會出現下列勒索資訊:

 

付款方式頁面如下:

藉助SMB散佈

Win32/Diskcoder.D能夠藉助SMB散佈。與一些公開說法不同的是,該勒索病毒並不像Win32/Diskcoder.C(Not-Petya)爆發時那樣,利用“EternalRomance”漏洞。它會首先掃描內網,查找開放的SMB共用記憶體。目標共用帳號如下:

  • admin
  • atsvc
  • browser
  • eventlog
  • lsarpc
  • netlogon
  • ntsvcs
  • spools
  • samr
  • srvsvc
  • scerpc
  • svcctl
  • wkssvc

在已被攻陷的電腦上啟動Mimikatz,擷取用戶名和密碼。常見容易被攻擊帳號密碼組合如下。



當找到適當組合後,便會在Windows資料夾中釋放infpub.dat檔,通過SCManager和rundll.exe執行。

加密

Win32/Diskcoder.D是Win32/Diskcoder.C的變種,已修復了原有的檔加密缺點。現採用DiskCyptor加密,用於全硬碟加密的一種合法開源軟體。金鑰通過CryptGenRandom生成,並採用RSA 2048位公共金鑰保護。


如同前身一樣,使用了AES-128-CBC演算法加密。


散佈區域


據ESET資料中心統計,烏克蘭只受到攻擊佔總數的12.2%。具體統計資料如下:

  • 俄羅斯:65%
  • 烏克蘭:12.2%
  • 保加利亞:10.2%
  • 土耳其:6.4%
  • 日本:3.8%
  • 其他:2.4%

這與被植入惡意Java腳本的受害網站分佈情況大致吻合。那麼為何烏克蘭相比其他國家受害情況更嚴重呢?

值得一提的是,所有這些大公司都是同時遭受攻擊的。很可能駭客已滲透進公司網路,同時發起Watering Hole(水坑)攻擊以掩人耳目。再沒有什麼比“Flash更新”令其受害更具說服力。ESET目前仍在著手調查,我們將第一時間發佈相關資訊。

樣本

c&C伺服器


付款網站:http://caforssztxqzf2nm[.]onion

植入網址:http://185.149.120[.]3/scholargoogle/

散佈網址:hxxp://1dnscontrol[.]com/flash_install.php

被攻陷網站列表:

hxxp://argumentiru[.]com

hxxp://www.fontanka[.]ru

hxxp://grupovo[.]bg

hxxp://www.sinematurk[.]com

hxxp://www.aica.co[.]jp

hxxp://spbvoditel[.]ru

hxxp://argumenti[.]ru

hxxp://www.mediaport[.]ua

hxxp://blog.fontanka[.]ru

hxxp://an-crimea[.]ru

hxxp://www.t.ks[.]ua

hxxp://most-dnepr[.]info hxxp://osvitaportal.com[.]ua hxxp://www.otbrana[.]com

hxxp://calendar.fontanka[.]ru

hxxp://www.grupovo[.]bg

hxxp://www.pensionhotel[.]cz

hxxp://www.online812[.]ru

hxxp://www.imer[.]ro

hxxp://novayagazeta.spb[.]ru

hxxp://i24.com[.]ua

hxxp://bg.pensionhotel[.]com

hxxp://ankerch-crimea[.]ru

ESET資安產品及企業解決方案能主動偵測已知(如WannaCryptor、Petya)、未知病毒及勒索軟體,抵禦網路攻擊或資安威脅,協助您打造良好的資安環境。

原文出處: https://www.welivesecurity.com/2017/10/24/bad-rabbit-not-petya-back/

關於Version 2 Limited
Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。