ื•ื™ืจื•ืก ืงื•ืจื•ื ื” ื“ื™ื’ื™ื˜ืœื™ - ืฉื™ืœื•ื‘ ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ื•ื’ื ื™ื‘ืช ืžื™ื“ืข

ืื™ื•ืžื™ื ืฉื•ื ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ื ื•ืฉืื™ ืงื•ืจื•ื ื” ืžืžืฉื™ื›ื™ื ืœื”ื•ืคื™ืข ื‘ืื™ื ื˜ืจื ื˜. ื•ื”ื™ื•ื ืื ื—ื ื• ืจื•ืฆื™ื ืœืฉืชืฃ ืžื™ื“ืข ืขืœ ืžืงืจื” ืžืขื ื™ื™ืŸ ืื—ื“ ืฉืžืžื—ื™ืฉ ื‘ื‘ื™ืจื•ืจ ืืช ื”ืจืฆื•ืŸ ืฉืœ ื”ืชื•ืงืคื™ื ืœืžืงืกื ืืช ื”ืจื•ื•ื—ื™ื ืฉืœื”ื. ื”ืื™ื•ื ืžืงื˜ื’ื•ืจื™ื™ืช "2 ื‘-1" ืงื•ืจื ืœืขืฆืžื• CoronaVirus. ื•ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ื ืžืฆื ืชื—ืช ื—ืชืš.

ื•ื™ืจื•ืก ืงื•ืจื•ื ื” ื“ื™ื’ื™ื˜ืœื™ - ืฉื™ืœื•ื‘ ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ื•ื’ื ื™ื‘ืช ืžื™ื“ืข

ื ื™ืฆื•ืœ ื ื•ืฉื ื”ืงื•ืจื•ื ื” ื”ื—ืœ ืœืคื ื™ ื™ื•ืชืจ ืžื—ื•ื“ืฉ. ื”ืชื•ืงืคื™ื ื ื™ืฆืœื• ืืช ืขื ื™ื™ืŸ ื”ืฆื™ื‘ื•ืจ ื‘ืžื™ื“ืข ืขืœ ื”ืชืคืฉื˜ื•ืช ื”ืžื’ื™ืคื” ื•ื”ืืžืฆืขื™ื ืฉื ื ืงื˜ื•. ื‘ืื™ื ื˜ืจื ื˜ ื”ื•ืคื™ืขื• ืžืกืคืจ ืขืฆื•ื ืฉืœ ืžืœืฉื™ื ื™ื ืฉื•ื ื™ื, ืืคืœื™ืงืฆื™ื•ืช ืžื™ื•ื—ื“ื•ืช ื•ืืชืจื™ื ืžื–ื•ื™ืคื™ื ืฉืคื•ื’ืขื™ื ื‘ืžืฉืชืžืฉื™ื, ื’ื•ื ื‘ื™ื ื ืชื•ื ื™ื ื•ืœืขื™ืชื™ื ืžืฆืคื™ื ื™ื ืืช ืชื•ื›ืŸ ื”ืžื›ืฉื™ืจ ื•ื“ื•ืจืฉื™ื ื›ื•ืคืจ. ื–ื” ื‘ื“ื™ื•ืง ืžื” ืฉืขื•ืฉื” ืืคืœื™ืงืฆื™ื™ืช Coronavirus Tracker ืœื ื™ื™ื“, ื—ื•ืกืžืช ืืช ื”ื’ื™ืฉื” ืœืžื›ืฉื™ืจ ื•ื“ื•ืจืฉืช ื›ื•ืคืจ.

ื ื•ืฉื ื ืคืจื“ ืœื”ืคืฆืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื”ื™ื” ื”ื‘ืœื‘ื•ืœ ืขื ืืžืฆืขื™ ืชืžื™ื›ื” ืคื™ื ื ืกื™ื™ื. ื‘ืžื“ื™ื ื•ืช ืจื‘ื•ืช, ื”ืžืžืฉืœื” ื”ื‘ื˜ื™ื—ื” ืกื™ื•ืข ื•ืชืžื™ื›ื” ืœืื–ืจื—ื™ื ืžืŸ ื”ืฉื•ืจื” ื•ืœื ืฆื™ื’ื™ ืขืกืงื™ื ื‘ืžื”ืœืš ื”ืžื’ื™ืคื”. ื•ื›ืžืขื˜ ื‘ืฉื•ื ืžืงื•ื ืœื ืžืงื‘ืœื™ื ืืช ื”ืกื™ื•ืข ื”ื–ื” ืคืฉื•ื˜ ื•ืฉืงื•ืฃ. ื™ืชืจื” ืžื›ืš, ืจื‘ื™ื ืžืงื•ื•ื™ื ืฉื™ืขื–ืจื• ืœื”ื ื›ืœื›ืœื™ืช, ืืš ืื™ื ื ื™ื•ื“ืขื™ื ืื ื”ื ื ื›ืœืœื™ื ื‘ืจืฉื™ืžืช ืžื™ ืฉื™ืงื‘ืœื• ืกื•ื‘ืกื™ื“ื™ื•ืช ืžืžืฉืœืชื™ื•ืช ืื• ืœื. ื•ืžื™ ืฉื›ื‘ืจ ืงื™ื‘ืœ ืžืฉื”ื• ืžื”ืžื“ื™ื ื” ืœื ืกื‘ื™ืจ ืฉื™ืกืจื‘ ืœืขื–ืจื” ื ื•ืกืคืช.

ื–ื” ื‘ื“ื™ื•ืง ืžื” ืฉืชื•ืงืคื™ื ืžื ืฆืœื™ื. ื”ื ืฉื•ืœื—ื™ื ืžื›ืชื‘ื™ื ื‘ืฉื ื‘ื ืงื™ื, ืจื’ื•ืœื˜ื•ืจื™ื ืคื™ื ื ืกื™ื™ื ื•ืจืฉื•ื™ื•ืช ื‘ื™ื˜ื•ื— ืœืื•ืžื™, ื•ืžืฆื™ืขื™ื ืขื–ืจื”. ืืชื” ืจืง ืฆืจื™ืš ืœื”ื™ื›ื ืก ืœืงื™ืฉื•ืจ...

ืœื ืงืฉื” ืœื ื—ืฉ ืฉืื—ืจื™ ืœื—ื™ืฆื” ืขืœ ื›ืชื•ื‘ืช ืžืคื•ืงืคืงืช, ืื“ื ืžื’ื™ืข ืœืืชืจ ืคื™ืฉื™ื ื’ ื‘ื• ื”ื•ื ืžืชื‘ืงืฉ ืœื”ื–ื™ืŸ ืืช ื”ืžื™ื“ืข ื”ืคื™ื ื ืกื™ ืฉืœื•. ืœืจื•ื‘, ื‘ืžืงื‘ื™ืœ ืœืคืชื™ื—ืช ืืชืจ ืื™ื ื˜ืจื ื˜, ืชื•ืงืคื™ื ืžื ืกื™ื ืœื”ื“ื‘ื™ืง ืžื—ืฉื‘ ื‘ืชื•ื›ื ื™ืช ื˜ืจื•ื™ืื ื™ืช ืฉืžื˜ืจืชื” ืœื’ื ื•ื‘ ื ืชื•ื ื™ื ืื™ืฉื™ื™ื ื•ื‘ืคืจื˜ ืžื™ื“ืข ืคื™ื ื ืกื™. ืœืคืขืžื™ื ืงื•ื‘ืฅ ืžืฆื•ืจืฃ ืœืžื™ื™ืœ ื›ื•ืœืœ ืงื•ื‘ืฅ ืžื•ื’ืŸ ื‘ืกื™ืกืžื” ื”ืžื›ื™ืœ "ืžื™ื“ืข ื—ืฉื•ื‘ ืขืœ ืื™ืš ืืชื” ื™ื›ื•ืœ ืœืงื‘ืœ ืชืžื™ื›ื” ืžืžืฉืœืชื™ืช" ื‘ืฆื•ืจื” ืฉืœ ืชื•ื›ื ื•ืช ืจื™ื’ื•ืœ ืื• ื›ื•ืคืจ.

ื‘ื ื•ืกืฃ, ืœืื—ืจื•ื ื” ื”ื—ืœื• ืœื”ืชืคืฉื˜ ืชื•ื›ื ื™ื•ืช ืžืงื˜ื’ื•ืจื™ื™ืช Infostealer ื’ื ื‘ืจืฉืชื•ืช ื”ื—ื‘ืจืชื™ื•ืช. ืœื“ื•ื’ืžื”, ืื ื‘ืจืฆื•ื ืš ืœื”ื•ืจื™ื“ ื›ืœื™ ืขื–ืจ ืœื’ื™ื˜ื™ืžื™ ืฉืœ Windows, ื ื ื™ื— wisecleaner[.]best, ื™ื™ืชื›ืŸ ืฉ-Infostealer ื™ื’ื™ืข ื™ื—ื“ ืื™ืชื•. ืขืœ ื™ื“ื™ ืœื—ื™ืฆื” ืขืœ ื”ืงื™ืฉื•ืจ, ื”ืžืฉืชืžืฉ ืžืงื‘ืœ ื”ื•ืจื“ื” ืฉืžื•ืจื™ื“ ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ื™ื—ื“ ืขื ื›ืœื™ ื”ืฉื™ืจื•ืช, ื•ืžืงื•ืจ ื”ื”ื•ืจื“ื” ื ื‘ื—ืจ ื‘ื”ืชืื ืœืชืฆื•ืจืช ื”ืžื—ืฉื‘ ืฉืœ ื”ืงื•ืจื‘ืŸ.

ื•ื™ืจื•ืก ืงื•ืจื•ื ื” 2022

ืœืžื” ืขื‘ืจื ื• ืืช ื›ืœ ื”ื˜ื™ื•ืœ ื”ื–ื”? ื”ืขื•ื‘ื“ื” ื”ื™ื ืฉื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ื”ื—ื“ืฉื”, ืฉื™ื•ืฆืจื™ื” ืœื ื—ืฉื‘ื• ื™ื•ืชืจ ืžื“ื™ ืขืœ ื”ืฉื, ืคืฉื•ื˜ ืกืคื’ื” ืืช ื›ืœ ื”ื˜ื•ื‘ ื‘ื™ื•ืชืจ ื•ืžืฉืžื—ืช ืืช ื”ืงื•ืจื‘ืŸ ื‘ืฉื ื™ ืกื•ื’ื™ ื”ืชืงืคื•ืช ื‘ื‘ืช ืื—ืช. ืžืฆื“ ืื—ื“, ืชื•ื›ื ื™ืช ื”ื”ืฆืคื ื” (CoronaVirus) ื ื˜ืขื ืช, ื•ืžืฆื“ ืฉื ื™, KPOT infostealer.

ืชื•ื›ื ืช ืจื ืกื•ืžื•ืจ ืฉืœ CoronaVirus

ืชื•ื›ื ืช ื”ื›ื•ืคืจ ืขืฆืžื” ื”ื™ื ืงื•ื‘ืฅ ืงื˜ืŸ ื‘ื’ื•ื“ืœ 44KB. ื”ืื™ื•ื ืคืฉื•ื˜ ืืš ื™ืขื™ืœ. ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ืžืขืชื™ืง ืืช ืขืฆืžื• ืชื—ืช ืฉื ืืงืจืื™ ืœ %AppData%LocalTempvprdh.exe, ื•ื’ื ืžื’ื“ื™ืจ ืืช ื”ืžืคืชื— ื‘ืจื™ืฉื•ื WindowsCurrentVersionRun. ืœืื—ืจ ืžื™ืงื•ื ื”ืขื•ืชืง, ื”ืžืงื•ืจ ื ืžื—ืง.

ื›ืžื• ืจื•ื‘ ืชื•ื›ื ื•ืช ื”ื›ื•ืคืจ, CoronaVirus ืžื ืกื” ืœืžื—ื•ืง ื’ื™ื‘ื•ื™ื™ื ืžืงื•ืžื™ื™ื ื•ืœื”ืฉื‘ื™ืช ืืช ื”ืฆืœืœืช ืงื‘ืฆื™ื ืขืœ ื™ื“ื™ ื”ืคืขืœืช ืคืงื•ื“ื•ืช ื”ืžืขืจื›ืช ื”ื‘ืื•ืช:
C:Windowssystem32VSSADMIN.EXE Delete Shadows /All /Quiet
C:Windowssystem32wbadmin.exe delete systemstatebackup -keepVersions:0 -quiet
C:Windowssystem32wbadmin.exe delete backup -keepVersions:0 -quiet

ืœืื—ืจ ืžื›ืŸ, ื”ืชื•ื›ื ื” ืžืชื—ื™ืœื” ืœื”ืฆืคื™ืŸ ืงื‘ืฆื™ื. ื”ืฉื ืฉืœ ื›ืœ ืงื•ื‘ืฅ ืžื•ืฆืคืŸ ื™ื›ื™ืœ [email protected]__ ื‘ื”ืชื—ืœื”, ื•ื›ืœ ื”ืฉืืจ ื ืฉืืจ ืื•ืชื• ื”ื“ื‘ืจ.
ื‘ื ื•ืกืฃ, ืชื•ื›ื ืช ื”ื›ื•ืคืจ ืžืฉื ื” ืืช ืฉื ื›ื•ื ืŸ C ืœ-CoronaVirus.

ื•ื™ืจื•ืก ืงื•ืจื•ื ื” ื“ื™ื’ื™ื˜ืœื™ - ืฉื™ืœื•ื‘ ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ื•ื’ื ื™ื‘ืช ืžื™ื“ืข

ื‘ื›ืœ ืกืคืจื™ื™ื” ืฉื”ื•ื•ื™ืจื•ืก ื”ื–ื” ื”ืฆืœื™ื— ืœื”ื“ื‘ื™ืง ืžื•ืคื™ืข ืงื•ื‘ืฅ CoronaVirus.txt ื”ืžื›ื™ืœ ื”ื•ืจืื•ืช ืชืฉืœื•ื. ื”ื›ื•ืคืจ ื”ื•ื ืจืง 0,008 ื‘ื™ื˜ืงื•ื™ืŸ ืื• ื›-$60. ืื ื™ ื—ื™ื™ื‘ ืœื•ืžืจ ืฉื–ื” ื ืชื•ืŸ ืฆื ื•ืข ืžืื•ื“. ื•ื›ืืŸ ื”ืขื ื™ื™ืŸ ื”ื•ื ืื• ืฉื”ื›ื•ืชื‘ ืœื ืฉื ืœืขืฆืžื• ืœืžื˜ืจื” ืœื”ืชืขืฉืจ ืžืื•ื“... ืื• ืœื”ื™ืคืš, ื”ื•ื ื”ื—ืœื™ื˜ ืฉืžื“ื•ื‘ืจ ื‘ืกื›ื•ื ืžืฆื•ื™ืŸ ืฉื›ืœ ืžืฉืชืžืฉ ืฉื™ื•ืฉื‘ ื‘ื‘ื™ืช ื‘ื‘ื™ื“ื•ื“ ืขืฆืžื™ ื™ื›ื•ืœ ืœืฉืœื. ืžืกื›ื™ื, ืื ืืชื” ืœื ื™ื›ื•ืœ ืœืฆืืช ื”ื—ื•ืฆื”, ืื– 60 $ ื›ื“ื™ ืœื”ื—ื–ื™ืจ ืืช ื”ืžื—ืฉื‘ ืฉืœืš ืœืขื‘ื•ื“ื” ื–ื” ืœื ื›ืœ ื›ืš ื”ืจื‘ื”.

ื•ื™ืจื•ืก ืงื•ืจื•ื ื” ื“ื™ื’ื™ื˜ืœื™ - ืฉื™ืœื•ื‘ ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ื•ื’ื ื™ื‘ืช ืžื™ื“ืข

ื‘ื ื•ืกืฃ, ืชื•ื›ื ืช ื”-Ransomware ื”ื—ื“ืฉื” ื›ื•ืชื‘ืช ืงื•ื‘ืฅ ื”ืคืขืœื” ืงื˜ืŸ ืฉืœ DOS ื‘ืชื™ืงื™ื™ืช ื”ืงื‘ืฆื™ื ื”ื–ืžื ื™ื™ื ื•ืจื•ืฉืžืช ืื•ืชื• ื‘ืจื™ืฉื•ื ืชื—ืช ืžืคืชื— BootExecute ื›ืš ืฉื”ื•ืจืื•ืช ืชืฉืœื•ื ื™ื•ืฆื’ื• ื‘ืคืขื ื”ื‘ืื” ืฉื”ืžื—ืฉื‘ ื™ื•ืคืขืœ ืžื—ื“ืฉ. ื‘ื”ืชืื ืœื”ื’ื“ืจื•ืช ื”ืžืขืจื›ืช, ื™ื™ืชื›ืŸ ืฉื”ื•ื“ืขื” ื–ื• ืœื ืชื•ืคื™ืข. ืขื ื–ืืช, ืœืื—ืจ ื”ืฉืœืžืช ื”ื”ืฆืคื ื” ืฉืœ ื›ืœ ื”ืงื‘ืฆื™ื, ื”ืžื—ืฉื‘ ื™ื•ืคืขืœ ืžื—ื“ืฉ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™.

ื•ื™ืจื•ืก ืงื•ืจื•ื ื” ื“ื™ื’ื™ื˜ืœื™ - ืฉื™ืœื•ื‘ ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ื•ื’ื ื™ื‘ืช ืžื™ื“ืข

ื’ื ื‘ ืžื™ื“ืข ืฉืœ KPOT

ืชื•ื›ื ืช ื›ื•ืคืจ ื–ื• ืžื’ื™ืขื” ื’ื ืขื ืชื•ื›ื ืช ืจื™ื’ื•ืœ KPOT. ื’ื ื‘ ืžื™ื“ืข ื–ื” ื™ื›ื•ืœ ืœื’ื ื•ื‘ ืขื•ื’ื™ื•ืช ื•ืกื™ืกืžืื•ืช ืฉืžื•ืจื•ืช ืžืžื’ื•ื•ืŸ ื“ืคื“ืคื ื™ื, ื›ืžื• ื’ื ืžืžืฉื—ืงื™ื ื”ืžื•ืชืงื ื™ื ื‘ืžื—ืฉื‘ (ื›ื•ืœืœ Steam), Jabber ื•-Skype Instant Messengers. ืชื—ื•ื ื”ืขื ื™ื™ืŸ ืฉืœื• ื›ื•ืœืœ ื’ื ืคืจื˜ื™ ื’ื™ืฉื” ืœ-FTP ื•-VPN. ืœืื—ืจ ืฉืขืฉื” ืืช ืขื‘ื•ื“ืชื• ื•ื’ื ื‘ ื›ืœ ืžื” ืฉื”ื•ื ื™ื›ื•ืœ, ื”ืžืจื’ืœ ืžื•ื—ืง ืืช ืขืฆืžื• ืขื ื”ืคืงื•ื“ื” ื”ื‘ืื”:

cmd.exe /c ping 127.0.0.1 && del C:tempkpot.exe

ื–ื” ื›ื‘ืจ ืœื ืจืง ืชื•ื›ื ืช ื›ื•ืคืจ

ื”ืžืชืงืคื” ื”ื–ื•, ืฉื•ื‘ ืงืฉื•ืจื” ืœื ื•ืฉื ืžื’ื™ืคืช ื”ืงื•ืจื•ื ื”, ืžื•ื›ื™ื—ื” ืฉื•ื‘ ืฉืชื•ื›ื ืช ื›ื•ืคืจ ืžื•ื“ืจื ื™ืช ืžื‘ืงืฉืช ืœืขืฉื•ืช ื™ื•ืชืจ ืžืืฉืจ ืจืง ืœื”ืฆืคื™ืŸ ืืช ื”ืงื‘ืฆื™ื ืฉืœืš. ื‘ืžืงืจื” ื–ื”, ื”ื ืคื’ืข ืžืกืชื›ืŸ ื‘ื’ื ื™ื‘ืช ืกื™ืกืžืื•ืช ืœืืชืจื™ื ื•ืคื•ืจื˜ืœื™ื ืฉื•ื ื™ื. ืงื‘ื•ืฆื•ืช ืคื•ืฉืขื™ ืกื™ื™ื‘ืจ ืžืื•ืจื’ื ื•ืช ืžืื•ื“ ื›ืžื• Maze ื•-DoppelPaymer ื”ืคื›ื• ืžื™ื•ืžื ื•ืช ื‘ืฉื™ืžื•ืฉ ื‘ื ืชื•ื ื™ื ืื™ืฉื™ื™ื ื’ื ื•ื‘ื™ื ื›ื“ื™ ืœืกื—ื•ื˜ ืžืฉืชืžืฉื™ื ืื ื”ื ืœื ืจื•ืฆื™ื ืœืฉืœื ืขื‘ื•ืจ ืฉื—ื–ื•ืจ ืงื‘ืฆื™ื. ื•ืื›ืŸ, ืคืชืื•ื ื”ื ืœื ื›ืœ ื›ืš ื—ืฉื•ื‘ื™ื, ืื• ืฉืœืžืฉืชืžืฉ ื™ืฉ ืžืขืจื›ืช ื’ื™ื‘ื•ื™ ืฉืื™ื ื” ืจื’ื™ืฉื” ืœื”ืชืงืคื•ืช Ransomware.

ืœืžืจื•ืช ื”ืคืฉื˜ื•ืช ืฉืœื•, ื”-CoronaVirus ื”ื—ื“ืฉ ืžื“ื’ื™ื ื‘ื‘ื™ืจื•ืจ ืฉื’ื ืคื•ืฉืขื™ ืกื™ื™ื‘ืจ ืžื‘ืงืฉื™ื ืœื”ื’ื“ื™ืœ ืืช ื”ื›ื ืกืชื ื•ืžื—ืคืฉื™ื ืืžืฆืขื™ื ื ื•ืกืคื™ื ืœืžื•ื ื˜ื™ื–ืฆื™ื”. ื”ืืกื˜ืจื˜ื’ื™ื” ืขืฆืžื” ืื™ื ื” ื—ื“ืฉื” - ืžื–ื” ืžืกืคืจ ืฉื ื™ื, ืื ืœื™ืกื˜ื™ื ืฉืœ Acronis ืฆื•ืคื™ื ื‘ื”ืชืงืคื•ืช ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ืฉื’ื ืฉื•ืชืœื•ืช ืกื•ืกื™ื ื˜ืจื•ื™ืื ื™ื™ื ืคื™ื ื ืกื™ื™ื ืขืœ ื”ืžื—ืฉื‘ ืฉืœ ื”ืงื•ืจื‘ืŸ. ื™ืชืจื” ืžื›ืš, ื‘ืชื ืื™ื ืžื•ื“ืจื ื™ื™ื, ืžืชืงืคืช ืชื•ื›ื ืช ื›ื•ืคืจ ื™ื›ื•ืœื” ืœืฉืžืฉ ื‘ื“ืจืš ื›ืœืœ ื›ื—ื‘ืœื” ืขืœ ืžื ืช ืœื”ืกื™ื˜ ืืช ืชืฉื•ืžืช ื”ืœื‘ ืžื”ืžื˜ืจื” ื”ืขื™ืงืจื™ืช ืฉืœ ื”ืชื•ืงืคื™ื โ€“ ื“ืœื™ืคืช ื ืชื•ื ื™ื.

ื›ืš ืื• ืื—ืจืช, ื ื™ืชืŸ ืœื”ืฉื™ื’ ื”ื’ื ื” ืžืคื ื™ ืื™ื•ืžื™ื ื›ืืœื” ืจืง ื‘ืืžืฆืขื•ืช ื’ื™ืฉื” ืžืฉื•ืœื‘ืช ืœื”ื’ื ืช ืกื™ื™ื‘ืจ. ื•ืžืขืจื›ื•ืช ืื‘ื˜ื—ื” ืžื•ื“ืจื ื™ื•ืช ื—ื•ืกืžื•ืช ื‘ืงืœื•ืช ืื™ื•ืžื™ื ื›ืืœื” (ื•ืฉื ื™ ื”ืžืจื›ื™ื‘ื™ื ืฉืœื”ื) ืขื•ื“ ืœืคื ื™ ืฉื”ืŸ ืžืชื—ื™ืœื•ืช ืœื”ืฉืชืžืฉ ื‘ืืœื’ื•ืจื™ืชืžื™ื ื”ื™ื•ืจื™ืกื˜ื™ื™ื ืชื•ืš ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืœืžื™ื“ืช ืžื›ื•ื ื”. ืื ืžืฉื•ืœื‘ื™ื ืขื ืžืขืจื›ืช ื’ื™ื‘ื•ื™/ืฉื—ื–ื•ืจ ืžืืกื•ืŸ, ื”ืงื‘ืฆื™ื ื”ืคื’ื•ืžื™ื ื”ืจืืฉื•ื ื™ื ื™ืฉื•ื—ื–ืจื• ืžื™ื“.

ื•ื™ืจื•ืก ืงื•ืจื•ื ื” ื“ื™ื’ื™ื˜ืœื™ - ืฉื™ืœื•ื‘ ืฉืœ ืชื•ื›ื ื•ืช ื›ื•ืคืจ ื•ื’ื ื™ื‘ืช ืžื™ื“ืข

ืœืžืขื•ื ื™ื™ื ื™ื, ืกื›ื•ืžื™ ื’ื™ื‘ื•ื‘ ืฉืœ ืงื‘ืฆื™ IoC:

CoronaVirus Ransomware: 3299f07bc0711b3587fe8a1c6bf3ee6bcbc14cb775f64b28a61d72ebcb8968d3
Kpot infostealer: a08db3b44c713a96fe07e0bfc440ca9cf2e3d152a5d13a70d6102c15004c4240

ืจืง ืžืฉืชืžืฉื™ื ืจืฉื•ืžื™ื ื™ื›ื•ืœื™ื ืœื”ืฉืชืชืฃ ื‘ืกืงืจ. ืœื”ืชื—ื‘ืจื‘ื‘ืงืฉื”.

ื”ืื ืื™ ืคืขื ื—ื•ื•ื™ืช ื”ืฆืคื ื” ืกื™ืžื•ืœื˜ื ื™ืช ื•ื’ื ื™ื‘ืช ื ืชื•ื ื™ื?

  • 19,0%ื›ืŸ4

  • 42,9%ืžืกืคืจ 9

  • 28,6%ื ืฆื˜ืจืš ืœื”ื™ื•ืช ื™ื•ืชืจ ืขืจื ื™ื™ื6

  • 9,5%ืืคื™ืœื• ืœื ื—ืฉื‘ืชื™ ืขืœ ื–ื”2

21 ืžืฉืชืžืฉื™ื ื”ืฆื‘ื™ืขื•. 5 ืžืฉืชืžืฉื™ื ื ืžื ืขื•.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”