GREYCORTEX became a new member of the non-profit Association, EUCYBSEC (European Cyber Security Excellence Center). Interests of the Association are cybersecurity and protection of SCADA systems. EUCYBSEC is aiming to...
GREYCORTEX launched a new 2.3 version MENDEL Analyst. It added standardized support of NetFlow and IPFIX, new ways of data presentation and several performance improvements and more. New features New...
A USEFUL SECURITY PRODUCT THAT OFFERS A WIDE VARIETY OF INTERESTING POSSIBILITIES GREYCORTEX MENDEL is a solution for detection, monitoring and analysis of advanced security incidents in network traffic. This solution is based...
Cybercrime is evolving at drammatic speed and at every moment, hackers and attackers are figuring out new strategies to compromise organizations and industries. The cybersecurity sector must not fall behind...
GREYCORTEX is happy to announce the latest version of GREYCORTEX MENDEL; Version 2.9.0. This version includes several new important features: the first is the Flow Exporter, which gives you the...
GREYCORTEX is happy to announce that CEO and Co-Owner Petr Chaloupka was named to the New Europe 100 (NE100). The list is made up of individuals selected by the Financial...
GREYCORTEX is happy to announce that our MENDEL network security tool is now part of the Brno University of Technology (VUT) cybersecurity program. MENDEL is used as part of the...
Today, global IT security vendor ESET has been awarded top marks by AV-Comparatives. ESET Endpoint Security has been named the lightest endpoint security solution on the market by the world’s leading security software...
Tokyo - NetJapan, Inc. publisher of disk imaging backup, system disaster recovery, and virtualization software, announces the release of ActiveImage Protector™ 2018. NetJapan’s virtual standby availability technology, vStandby™, is now...
最新資訊(中歐時間10月27日15:35時):一份新報告指出,美國國家安全局所洩露的駭客工具之一“EternalRomance”,已被利用來在網路上傳播Diskcoder.D。我們透過安裝微軟公司緊急漏洞修復MS17-010(用以彌補美國國家安全局洩露駭客工具所利用的系統漏洞)來確認此訊息,並從而阻止該惡意程式借助IPC$共用資料夾方式進一步散佈。 一款新的勒索病毒於10月24日爆發,已攻擊包括歐洲大部分地鐵系統,其中也包含烏克蘭部分重要基礎通訊設施。有關這一新變種的詳細介紹,請見下文。 藉助對知名網站進行Watering Hole(水坑)攻擊,使使用者在不察覺的情況下自動下載 Bad Rabbit的散佈途徑之一,就是在使用者毫無察覺的情況下自動下載。一些知名網站已被攻陷,HTML文本或某個.js檔之中被植入了Java腳本。 植入腳本後的樣本如下所示: 該腳本向185.149.120[.]3回饋資訊,目前該位址暫無回應。 瀏覽器使用者代理引用頁已訪問網站的cookie已訪問網站的功能變數名稱 透過攻擊伺服器端邏輯運算,認定訪客是否具有攻擊價值,之後再把內容添加到頁面之中。此時可看到彈跳視窗,頁面中央顯示請使用者下載Flash播放機更新版的提示資訊。 點擊“安裝”按鈕後,便開始啟動來自1dnscontrol[.]com的可執行檔下載進程。可執行檔名為install_flash_player.exe,實際就是W32/Diskcoder.D下載器。 最終電腦會出現下列勒索資訊: 付款方式頁面如下: 藉助SMB散佈 Win32/Diskcoder.D能夠藉助SMB散佈。與一些公開說法不同的是,該勒索病毒並不像Win32/Diskcoder.C(Not-Petya)爆發時那樣,利用“EternalRomance”漏洞。它會首先掃描內網,查找開放的SMB共用記憶體。目標共用帳號如下: adminatsvcbrowsereventloglsarpcnetlogonntsvcsspoolssamrsrvsvcscerpcsvcctlwkssvc 在已被攻陷的電腦上啟動Mimikatz,擷取用戶名和密碼。常見容易被攻擊帳號密碼組合如下。 當找到適當組合後,便會在Windows資料夾中釋放infpub.dat檔,通過SCManager和rundll.exe執行。 加密 Win32/Diskcoder.D是Win32/Diskcoder.C的變種,已修復了原有的檔加密缺點。現採用DiskCyptor加密,用於全硬碟加密的一種合法開源軟體。金鑰通過CryptGenRandom生成,並採用RSA 2048位公共金鑰保護。 如同前身一樣,使用了AES-128-CBC演算法加密。 散佈區域 據ESET資料中心統計,烏克蘭只受到攻擊佔總數的12.2%。具體統計資料如下: 俄羅斯:65%烏克蘭:12.2%保加利亞:10.2%土耳其:6.4%日本:3.8%其他:2.4% 這與被植入惡意Java腳本的受害網站分佈情況大致吻合。那麼為何烏克蘭相比其他國家受害情況更嚴重呢? 值得一提的是,所有這些大公司都是同時遭受攻擊的。很可能駭客已滲透進公司網路,同時發起Watering Hole(水坑)攻擊以掩人耳目。再沒有什麼比“Flash更新”令其受害更具說服力。ESET目前仍在著手調查,我們將第一時間發佈相關資訊。 樣本 c&C伺服器...
