¶ñÒâÈí¼þÈëÇÖ»úÖÆÉî¶ÈÆÊÎö
Ê®´óÖ®ÎÛÈí¼þ£¨Ten Major Malicious Softwares£©ÆÕ±é½ÓÄÉÏȽøµÄ·´Õì²ì¼¼ÊõÍ»ÆÆÏµÍ³·ÀÏߣ¬2023ÄêÍøÂçÄþ¾²³ÂËßÏÔʾ£¬½öÀÕË÷²¡¶¾ÀàÈí¼þ¾ÍÔìÓñ³ÉÇòÁè¼Ý300ÒÚÃÀÔª¾¼ÃËðʧ¡£ÕâÀà¶ñÒⷨʽÖ÷Ҫͨ¹ýÈý´ó;¾¶ÉøÍ¸£ºÎ±×°Õý¹æÈí¼þµÄÊý×ÖÇ©ÃûÆÛÆ¡¢ÀûÓÃϵͳ©¶´µÄÁãÈÕ¹¥»÷£¬ÒÔ¼°É罻ýÌåÁ÷´«µÄÓÕµ¼ÏÂÔØ¡£ÒÔEmotet²¡¶¾ÎªÀý£¬Æä½ÓÄɵÄÄ£¿é»¯Éè¼Æ¿ÉÒÔ¶¯Ì¬¼ÓÔØ¹¥»÷×é¼þ£¬µ¼ÖÂ89%µÄÊÜѬȾÉ豸ÔÚ72СʱÄÚ·ºÆðÊý¾Ýй¶¡£
ϵͳÖж¾µÄµäÐÍ֢״ʶ±ð
µ±ÅÌËã»úѬȾʮ´ó¶ñÒâÈí¼þºó£¬Óû§³£»áÔâÓö¶àÏîÒì³£ÌåÏÖ¡£ÖÐÑë´¦Öóͷ£Æ÷ʹÓÃÂÊÒì³£ìÉýÖÁ90%ÒÔÉÏÊÇ×îÏÔÖøÕ÷Õ×£¬ÓÈÆäÊÇÔÚδִÐÐÅÓ´óÔËËãÈÎÎñʱ¡£²¿ÃÅÀÕË÷Èí¼þ»¹»áÐÞ¸ÄÎļþÀ©Õ¹Ãû£¬½«.jpg¸ÄΪ.encrypted¡£Æ¾¾ÝÈüÃÅÌú¿ËʵÑéÊҵļà²âÊý¾Ý£¬78%µÄÖж¾É豸¶¼ÊзºÆð×¢²á±í£¨Registry£©Òªº¦Ïî±»¸Ä¶¯µÄÇé¿ö£¬ÕâÕýÊǶñÒâÈí¼þʵÏֳ־û¯×¤ÁôµÄ¼¼ÊõÊֶΡ£
Ó¦¼±´¦Öóͷ£µÄÒªº¦²Ù×÷²½Öè
·¢ÏÖÒÉËÆÑ¬È¾Ê®´óÖ®ÎÛÈí¼þʱ£¬Ê×Òª´ëÊ©ÊÇÁ¢¼´¶Ï¿ªÍøÂçÁ¬½Ó·ÀÖ¹Êý¾ÝÍâ´«¡£Ê¹ÓôøÓÐдÑÚ»¤¹¦Ð§µÄPEÆô¶¯Å̽øÈëÄþ¾²Ä£Ê½£¬ÔËÐÐProcess Explorer¹¤¾ß¼ì²â¿ÉÒɽø³Ì¡£×ÊÉîÄþ¾²¹¤³Ìʦ½¨Ò飬´ËʱӦÓÅÏÈʹÓÃVolume Shadow Copy¼¼Êõ±¸·ÝÒªº¦Êý¾Ý£¬ÖÆÖ¹Îóɾµ¼Ö²»ÐÐÄæËðʧ¡£ÃÀ¹úÅÌËã»úÓ¦¼±ÏìӦС×éµÄ´¦Öùæ³ÌÌØ±ðÇ¿µ÷£¬ÔÚδȷÈϲ¡¶¾Çå³ýǰÇÐÎð½ÓÈëÆäËû´æ´¢É豸¡£
רҵ¼¶Çå³ý¹¤¾ßʵսÑÝʾ
Õë¶ÔÍç¹ÌµÄÊ®´ó¶ñÒâÈí¼þ£¬´«Í³É±¶¾Èí¼þ¿ÉÄÜÄÑÒÔ³¹µ×Çå³ý¡£ÕâÀïÍÆ¼öʹÓýáºÏÐÐΪ·ÖÎöµÄMalwarebytes Anti-Malware½øÐÐÉî¶ÈɨÃ裬ÅäºÏHijackThis½øÐÐÆô¶¯ÏîÐÞ¸´¡£Ä³½ðÈÚ»ú¹¹Äþ¾²ÍŶӵÄʵ¼Ê°¸ÀýÏÔʾ£¬Ê¹ÓÃTDSSKillerרɱ¹¤¾ßÀÖ³ÉÒÆ³ýÁËÄÑÒÔ¼ì²âµÄRootkit²¡¶¾¡£ÔÚϵͳÐÞ¸´½×¶Î£¬Ö´ÐÐsfc /scannowÃüÁîУÑéϵͳÎļþµÄÍêÕûÐÔ£¬¿ÉÐÞ¸´85%ÒÔÉϵı»¸Ä¶¯ÏµÍ³×é¼þ¡£
ϵͳ¼Ó¹ÌµÄ·À»¤Õ½ÂÔ¹¹½¨
³¹µ×Çå³ýÊ®´óÖ®ÎÛÈí¼þºó£¬¹¹½¨¶à²ã·ÀÓùÌåϵÖÁ¹ØÖØÒª¡£¿ªÆôÓ²¼þ¼¶·À»¤¹¦Ð§ÈçIntel CET£¨¿ØÖÆÁ÷Ç¿ÖÆ¼¼Êõ£©£¬¿ÉÓÐЧ×èÖ¹78%µÄÄÚ´æ¹¥»÷¡£Ó¦Óð×Ãûµ¥ÖƶÈÏÞÖÆ²»Ã÷·¨Ê½Ö´ÐУ¬ÅäºÏ·À»ðǽÉèÖóöÕ¾¹æÔò×è¶Ï¿ÉÒÉÁ¬½Ó¡£Î¢Èí¹Ù·½Êý¾ÝÏÔʾ£¬ÆôÓÃCredential Guard¹¦Ð§ºó£¬Æ¾Ö¤ÇÔÈ¡À๥»÷µÄÀÖ³ÉÂÊϽµ92%¡£¶¨ÆÚ¸üÐÂUEFI¹Ì¼þ£¨Í³Ò»¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú£©Ò²ÊÇ·À·¶BIOS¼¶²¡¶¾µÄÒªº¦´ëÊ©¡£
Ãæ¶ÔÈÕÒæÅÓ´óµÄÊ®´ó¶ñÒâÈí¼þÍþв£¬Óû§ÐèÒª½¨ÉèÍêÕûµÄÈÏÖªÌåϵºÍÓ¦¶Ô»úÖÆ¡£´Ó¾«×¼Ê¶±ðÖж¾Ö¢×´µ½Ê¹ÓÃרҵ¹¤¾ß³¹µ×Çå³ý£¬Ã¿¸ö»·½Ú¶¼¹ØÏµµ½Êý¾ÝÄþ¾²µÄ×îÖÕ½á¹û¡£½¨Òéÿ¼¾¶ÈÖ´ÐÐÈ«ÅÌɨÃ裬ʵʱ¸üв¡¶¾ÌØÕ÷¿â£¬½«ÍøÂçÄþ¾²·À»¤´Ó±»¶¯ÏìӦת±äΪÖ÷¶¯·ÀÓù¡£¼Çס£¬ÕæÕýµÄÄþ¾²²»½öÔÚÓÚÇå³ýÏÖÓÐÍþв£¬¸üÔÚÓÚ¹¹½¨Á¬Ðø½ø»¯µÄ·À»¤Ìåϵ¡£ Ô˶¯£º¡¾Í°ÀÃ30·ÖÖÓÃô½Ý´¦Öóͷ£30·ÖÖÓÄÚ»ëË®Çå³ý¡¿ ÔÚÊý×Ö»¯Ê±´úÈÕÒæÑϾþµÄÍøÂçÄþ¾²Çé¿öÏ£¬Ê®´ó¶ñÒâÈí¼þÒѳÉΪÍþвСÎÒ˽¼ÒÒþ˽ºÍÆóÒµÊý¾ÝÄþ¾²µÄÖ÷ÒªÒþ»¼¡£±¾ÎĽ«Éî¶È½âÎöÕâЩ¸ßΣ²¡¶¾Èí¼þµÄÊÂÇéÔÀí£¬Í¨¹ýȨÍþÊý¾ÝչʾÆäÔì³ÉµÄÖ±½Ó¾¼ÃËðʧÓë¼¼ÊõΣº¦£¬²¢ÏµÍ³»¯ÑÝʾ´Ó»ù´¡·ÀÓùµ½×¨Òµ²éɱµÄÍêÕû½â¾ö·½°¸Á÷³Ì£¬×ÊÖúÓû§¹¹½¨¼áʵµÄÄþ¾²·À»¤Ìåϵ¡£¶ñÒâÈí¼þÈëÇÖ»úÖÆÉî¶ÈÆÊÎö
Ê®´óÖ®ÎÛÈí¼þ£¨Ten Major Malicious Softwares£©ÆÕ±é½ÓÄÉÏȽøµÄ·´Õì²ì¼¼ÊõÍ»ÆÆÏµÍ³·ÀÏߣ¬2023ÄêÍøÂçÄþ¾²³ÂËßÏÔʾ£¬½öÀÕË÷²¡¶¾ÀàÈí¼þ¾ÍÔìÓñ³ÉÇòÁè¼Ý300ÒÚÃÀÔª¾¼ÃËðʧ¡£ÕâÀà¶ñÒⷨʽÖ÷Ҫͨ¹ýÈý´ó;¾¶ÉøÍ¸£ºÎ±×°Õý¹æÈí¼þµÄÊý×ÖÇ©ÃûÆÛÆ¡¢ÀûÓÃϵͳ©¶´µÄÁãÈÕ¹¥»÷£¬ÒÔ¼°É罻ýÌåÁ÷´«µÄÓÕµ¼ÏÂÔØ¡£ÒÔEmotet²¡¶¾ÎªÀý£¬Æä½ÓÄɵÄÄ£¿é»¯Éè¼Æ¿ÉÒÔ¶¯Ì¬¼ÓÔØ¹¥»÷×é¼þ£¬µ¼ÖÂ89%µÄÊÜѬȾÉ豸ÔÚ72СʱÄÚ·ºÆðÊý¾Ýй¶¡£
ϵͳÖж¾µÄµäÐÍ֢״ʶ±ð
µ±ÅÌËã»úѬȾʮ´ó¶ñÒâÈí¼þºó£¬Óû§³£»áÔâÓö¶àÏîÒì³£ÌåÏÖ¡£ÖÐÑë´¦Öóͷ£Æ÷ʹÓÃÂÊÒì³£ìÉýÖÁ90%ÒÔÉÏÊÇ×îÏÔÖøÕ÷Õ×£¬ÓÈÆäÊÇÔÚδִÐÐÅÓ´óÔËËãÈÎÎñʱ¡£²¿ÃÅÀÕË÷Èí¼þ»¹»áÐÞ¸ÄÎļþÀ©Õ¹Ãû£¬½«.jpg¸ÄΪ.encrypted¡£Æ¾¾ÝÈüÃÅÌú¿ËʵÑéÊҵļà²âÊý¾Ý£¬78%µÄÖж¾É豸¶¼ÊзºÆð×¢²á±í£¨Registry£©Òªº¦Ïî±»¸Ä¶¯µÄÇé¿ö£¬ÕâÕýÊǶñÒâÈí¼þʵÏֳ־û¯×¤ÁôµÄ¼¼ÊõÊֶΡ£
Ó¦¼±´¦Öóͷ£µÄÒªº¦²Ù×÷²½Öè
·¢ÏÖÒÉËÆÑ¬È¾Ê®´óÖ®ÎÛÈí¼þʱ£¬Ê×Òª´ëÊ©ÊÇÁ¢¼´¶Ï¿ªÍøÂçÁ¬½Ó·ÀÖ¹Êý¾ÝÍâ´«¡£Ê¹ÓôøÓÐдÑÚ»¤¹¦Ð§µÄPEÆô¶¯Å̽øÈëÄþ¾²Ä£Ê½£¬ÔËÐÐProcess Explorer¹¤¾ß¼ì²â¿ÉÒɽø³Ì¡£×ÊÉîÄþ¾²¹¤³Ìʦ½¨Ò飬´ËʱӦÓÅÏÈʹÓÃVolume Shadow Copy¼¼Êõ±¸·ÝÒªº¦Êý¾Ý£¬ÖÆÖ¹Îóɾµ¼Ö²»ÐÐÄæËðʧ¡£ÃÀ¹úÅÌËã»úÓ¦¼±ÏìӦС×éµÄ´¦Öùæ³ÌÌØ±ðÇ¿µ÷£¬ÔÚδȷÈϲ¡¶¾Çå³ýǰÇÐÎð½ÓÈëÆäËû´æ´¢É豸¡£
רҵ¼¶Çå³ý¹¤¾ßʵսÑÝʾ
Õë¶ÔÍç¹ÌµÄÊ®´ó¶ñÒâÈí¼þ£¬´«Í³É±¶¾Èí¼þ¿ÉÄÜÄÑÒÔ³¹µ×Çå³ý¡£ÕâÀïÍÆ¼öʹÓýáºÏÐÐΪ·ÖÎöµÄMalwarebytes Anti-Malware½øÐÐÉî¶ÈɨÃ裬ÅäºÏHijackThis½øÐÐÆô¶¯ÏîÐÞ¸´¡£Ä³½ðÈÚ»ú¹¹Äþ¾²ÍŶӵÄʵ¼Ê°¸ÀýÏÔʾ£¬Ê¹ÓÃTDSSKillerרɱ¹¤¾ßÀÖ³ÉÒÆ³ýÁËÄÑÒÔ¼ì²âµÄRootkit²¡¶¾¡£ÔÚϵͳÐÞ¸´½×¶Î£¬Ö´ÐÐsfc /scannowÃüÁîУÑéϵͳÎļþµÄÍêÕûÐÔ£¬¿ÉÐÞ¸´85%ÒÔÉϵı»¸Ä¶¯ÏµÍ³×é¼þ¡£
ϵͳ¼Ó¹ÌµÄ·À»¤Õ½ÂÔ¹¹½¨
³¹µ×Çå³ýÊ®´óÖ®ÎÛÈí¼þºó£¬¹¹½¨¶à²ã·ÀÓùÌåϵÖÁ¹ØÖØÒª¡£¿ªÆôÓ²¼þ¼¶·À»¤¹¦Ð§ÈçIntel CET£¨¿ØÖÆÁ÷Ç¿ÖÆ¼¼Êõ£©£¬¿ÉÓÐЧ×èÖ¹78%µÄÄÚ´æ¹¥»÷¡£Ó¦Óð×Ãûµ¥ÖƶÈÏÞÖÆ²»Ã÷·¨Ê½Ö´ÐУ¬ÅäºÏ·À»ðǽÉèÖóöÕ¾¹æÔò×è¶Ï¿ÉÒÉÁ¬½Ó¡£Î¢Èí¹Ù·½Êý¾ÝÏÔʾ£¬ÆôÓÃCredential Guard¹¦Ð§ºó£¬Æ¾Ö¤ÇÔÈ¡À๥»÷µÄÀÖ³ÉÂÊϽµ92%¡£¶¨ÆÚ¸üÐÂUEFI¹Ì¼þ£¨Í³Ò»¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú£©Ò²ÊÇ·À·¶BIOS¼¶²¡¶¾µÄÒªº¦´ëÊ©¡£
Ãæ¶ÔÈÕÒæÅÓ´óµÄÊ®´ó¶ñÒâÈí¼þÍþв£¬Óû§ÐèÒª½¨ÉèÍêÕûµÄÈÏÖªÌåϵºÍÓ¦¶Ô»úÖÆ¡£´Ó¾«×¼Ê¶±ðÖж¾Ö¢×´µ½Ê¹ÓÃרҵ¹¤¾ß³¹µ×Çå³ý£¬Ã¿¸ö»·½Ú¶¼¹ØÏµµ½Êý¾ÝÄþ¾²µÄ×îÖÕ½á¹û¡£½¨Òéÿ¼¾¶ÈÖ´ÐÐÈ«ÅÌɨÃ裬ʵʱ¸üв¡¶¾ÌØÕ÷¿â£¬½«ÍøÂçÄþ¾²·À»¤´Ó±»¶¯ÏìӦת±äΪÖ÷¶¯·ÀÓù¡£¼Çס£¬ÕæÕýµÄÄþ¾²²»½öÔÚÓÚÇå³ýÏÖÓÐÍþв£¬¸üÔÚÓÚ¹¹½¨Á¬Ðø½ø»¯µÄ·À»¤Ìåϵ¡£