{"id":1923,"date":"2022-05-18T14:33:58","date_gmt":"2022-05-18T06:33:58","guid":{"rendered":"https:\/\/blog.billows.com.tw\/?p=1923"},"modified":"2023-02-13T11:02:37","modified_gmt":"2023-02-13T03:02:37","slug":"lockbit2-0%e9%8e%96%e5%ae%9a%e5%8f%b0%e7%81%a3%e4%ba%86-5%e6%9c%88%e4%b8%8a%e3%80%81%e4%b8%ad%e6%97%ac%e5%b7%b2%e8%a6%8b%e5%9b%9b%e5%ae%b6%e5%8f%b0%e7%81%a3%e4%bc%81%e6%a5%ad%ef%bc%8c%e9%81%adlockbi","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=1923","title":{"rendered":"LockBit2.0\u9396\u5b9a\u53f0\u7063\u4e86?! 5\u6708\u4e0a\u3001\u4e2d\u65ec\u5df2\u898b\u56db\u5bb6\u53f0\u7063\u4f01\u696d\uff0c\u906dLockBit2.0\u52d2\u7d22\u8edf\u9ad4\u7684\u653b\u64ca"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"529\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/Core_Opto.jpg\" alt=\"\" class=\"wp-image-1934\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/Core_Opto.jpg 800w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/Core_Opto-300x198.jpg 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/Core_Opto-768x508.jpg 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><figcaption class=\"wp-element-caption\">LockBit 2.0\u52d2\u7d22\u8edf\u9ad4\u8072\u7a31\u653b\u64ca\u4e86\u53f0\u7063\u67d0\u80cc\u5149\u6a21\u7d44\u5927\u5ee0\u548c\u5176\u5b50\u516c\u53f8<\/figcaption><\/figure>\n\n\n\n<p>\u64da\u89c0\u5bdf\uff0c\u52d2\u7d22\u8edf\u9ad4LockBit 2.0\u5df2\u57285\u6708\u4e0a\u3001\u4e2d\u65ec\uff0c\u653b\u64ca\u4e86\u56db\u9593\u4e0d\u540c\u7684\u53f0\u7063\u4f01\u696d\uff0c\u5927\u8086\u5728\u5176\u63ed\u79d8\u7db2\u7ad9\u4e0a\u516c\u544a\u53d7\u5bb3\u540d\u55ae\u3002\u7576\u4e2d\u5f15\u4eba\u95dc\u6ce8\u7684\u662f\u4e00\u9593\u4e0a\u5e02\u7684\u80cc\u5149\u6a21\u7d44\u5927\u5ee0\u8207\u5176\u5b50\u516c\u53f8\u7591\u540c\u6642\u906dLockBit 2.0\u7684\u6bd2\u624b\uff0cLockBit\u63da\u8a00\u5df2\u7aca\u5f97\u6bcd\u516c\u53f8\u548c\u5b50\u516c\u53f8\u7684\u6a5f\u5bc6\u8cc7\u6599\uff0c\u5305\u62ecapps\u7684\u539f\u59cb\u78bc\u3001\u8ca1\u52d9\u5831\u544a\u3001\u54e1\u5de5\u500b\u8cc7\u7b49\u8d85\u904e 3 \u5343\u4efd\u6a94\u6848\u3002\u64da\u4e86\u89e3\u6bcd\u516c\u53f8\u548c\u5b50\u516c\u53f8\u5206\u5225\u4f4d\u65bc\u4e0d\u540c\u7684\u7e23\u5e02\uff0c\u8a72\u6bcd\u516c\u53f8\u7684\u4e3b\u8981\u751f\u7522\u5ee0\u623f\u904d\u4f48\u53f0\u7063\u53ca\u5927\u9678\u591a\u500b\u5730\u5340\u3002\u622a\u81f3\u76ee\u524d\uff0c\u5728\u516c\u958b\u8cc7\u8a0a\u89c0\u6e2c\u7ad9\u4e0a\u6c92\u6709\u770b\u5230\u8a72\u6bcd\u516c\u53f8\u767c\u4f48\u91cd\u8a0a\u7684\u76f8\u95dc\u8a0a\u606f\uff0c\u53e6\u5916\uff0cLockBit2.0\u8072\u7a31\u6703\u57285\u670818\u65e5\u767c\u5e03\u5f9e\u8a72\u6bcd\u516c\u53f8\u53ca\u5b50\u516c\u53f8\u76dc\u4f86\u7684\u8cc7\u6599\uff0c\u4f46\u76ee\u524d\u5c1a\u672a\u770b\u5230\u4efb\u4f55\u516c\u958b\u6d41\u51fa\u7684\u6a94\u6848\u3002<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"943\" height=\"698\" data-id=\"1931\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/TW_02-1.jpg\" alt=\"\" class=\"wp-image-1931\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/TW_02-1.jpg 943w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/TW_02-1-300x222.jpg 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/TW_02-1-768x568.jpg 768w\" sizes=\"auto, (max-width: 943px) 100vw, 943px\" \/><\/figure>\n<\/figure>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"505\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-13.png\" alt=\"\" class=\"wp-image-1928\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-13.png 865w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-13-300x175.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-13-768x448.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><\/figure>\n\n\n\n<p>\u53e6\u5916\uff0c\u4e00\u5bb6\u4f4d\u65bc\u65b0\u5317\u5e02\u7684\u96fb\u7dda\u516c\u53f8\u548c\u4e00\u5bb6\u4f4d\u65bc\u53f0\u4e2d\u7684\u5c0d\u8b1b\u6a5f\u88fd\u9020\u5ee0\u5546\u4e5f\u6210\u70baLockBit 2.0\u7684\u53d7\u5bb3\u8005\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"508\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-14.png\" alt=\"\" class=\"wp-image-1929\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-14.png 865w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-14-300x176.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2022\/05\/image-14-768x451.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><figcaption class=\"wp-element-caption\">LockBit \u7684\u6f14\u8b8a\uff0cLockBit\u662f\u76ee\u524d\u5176\u4e2d\u6700\u6210\u529f\u7684\u52d2\u7d22\u8edf\u9ad4\u5373\u670d\u52d9\uff08Ransomware-as-a-Service\uff1bRaaS\uff09\u4e4b\u4e00\uff0cPhoto Credit: Kaspersky<\/figcaption><\/figure>\n\n\n\n<p>LockBit\u57282021\u5e746\u6708\u63a8\u51fa<a href=\"https:\/\/blog.billows.com.tw\/?p=1173\">\u5347\u7d1a\u7248<\/a> LockBit 2.0 \u4ee5\u4f86\uff0c\u627f\u8afe\u901a\u904e\u540d\u70baStealBit\u7684\u65b0\u5de5\u5177\u63d0\u4f9b\u5e02\u5834\u4e0a\u6700\u5feb\u7684\u6578\u64da\u4e0a\u50b3\u901f\u5ea6\uff0c\u8a72\u5de5\u5177\u9084\u652f\u63f4\u5be6\u6642\u58d3\u7e2e\u548c\u62d6\u653e\u529f\u80fd\uff0c\u5c0d\u5b89\u5168\u5de5\u5177\u4fdd\u6301\u96b1\u85cf\u3002\u6839\u64da LockBit \u7684\u627f\u8afe\uff0c\u5b83\u53ef\u4ee5\u5728\u4e0d\u5230 20 \u5206\u9418\u7684\u6642\u9593\u5167\u5f9e\u53d7\u611f\u67d3\u7684\u7cfb\u7d71\u4e0b\u8f09 100 GB \u7684\u6578\u64da\uff0c\u653b\u64ca\u7684\u4f01\u696d\u6578\u91cf\u6bd4\u4ee5\u5f80\u66f4\u591a\u30028\u6708\u521d\uff0cBleepingComputer<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks\/\">\u66fe\u5831\u5c0e<\/a>\uff0cLockBit2.0\u7a4d\u6975\u62db\u52df\u76ee\u6a19\u4f01\u696d\u7684\u5167\u9b3c\uff0c\u5e6b\u52a9\u4ed6\u5011\u5165\u4fb5\u548c\u52a0\u5bc6\u4f01\u696d\u7684\u7db2\u8def\uff0c\u4e26\u6703\u4ee5\u767e\u842c\u7f8e\u5143\u4f5c\u70ba\u5831\u916c\u3002LockBit2.0\u80fd\u5229\u7528 Active Directory (AD) \u7684\u7fa4\u7d44\u539f\u5247\uff0c\u81ea\u52d5\u5c07 Windows \u7db2\u57df\u5167\u6240\u6709\u88dd\u7f6e\u52a0\u5bc6\uff0c\u4f7f\u653b\u64ca\u66f4\u52a0\u6709\u6548\uff0c\u4e4b\u5f8cLockBit 2.0\u9084\u5728\u5176\u5de5\u5177\u5305\u4e2d\u589e\u52a0<a>\u4e86<\/a>\u4e00\u500b\u91dd\u5c0d VMware ESXi\u865b\u64ec\u5316\u7cfb\u7d71\u4e2d\u7684Linux\u52a0\u5bc6\u5668\u3002<\/p>\n\n\n\n<p>\u7f8e\u570bFBI(\u806f\u90a6\u8abf\u67e5\u5c40)\u57282022\u5e742\u6708\u91dd\u5c0dLockBit\u767c\u5e03\u4e86CU-000162-MW\u7684<a href=\"https:\/\/www.ic3.gov\/Media\/News\/2022\/220204.pdf\">Flash Alert<\/a>\u8b66\u5831\uff0c\u63d0\u4f9b\u4e86\u8207 LockBit \u52d2\u7d22\u8edf\u9ad4\u653b\u64ca\u76f8\u95dc\u7684\u6280\u8853\u7d30\u7bc0\u548c\u5165\u4fb5\u6307\u6a19\u3002FBI \u5efa\u8b70\u7db2\u7d61\u5b89\u5168\u4eba\u54e1\u8981\u6c42\u4f7f\u7528\u5f37\u5bc6\u78bc\u3001\u591a\u56e0\u7d20\u8eab\u4efd\u9a57\u8b49\u548c\u66f4\u65b0\u8edf\u4ef6\u7b49\uff0c\u4ee5\u964d\u4f4e LockBit 2.0 \u52d2\u7d22\u8edf\u4ef6\u7684\u5371\u5bb3\u98a8\u96aa\u3002<\/p>\n\n\n\n<p>\u5728\u904e\u53bbLockbit2.0\u66fe\u653b\u64ca\u904e\u7684\u53f0\u7063\u4f01\u696d:<\/p>\n\n\n\n<p>2021\u5e7410\u6708\u67d0\u88fd\u9020\u696d\u6210\u8863\u526f\u6599\u5546\u00e0<a href=\"https:\/\/blog.billows.com.tw\/?p=1411\">https:\/\/blog.billows.com.tw\/?p=1411<\/a><\/p>\n\n\n\n<p>2021\u5e7411\u6708\u4e0a\u5e02\u71df\u5efa\u516c\u53f8<a href=\"https:\/\/www.ithome.com.tw\/news\/147592\">\u65e5\u52dd\u751f<\/a>\u53ca\u8a72\u96c6\u5718\u65d7\u4e0b\u767e\u8ca8<a href=\"https:\/\/www.ithome.com.tw\/news\/147627\">\u4eac\u7ad9<\/a>\u4e5f\u906dLockBit2.0\u653b\u64ca<\/p>\n\n\n\n<p>2022 \u5e74 4 \u6708\u67d0\u4e00\u98f2\u6599\u539f\u7269\u6599\u5546\u00e0<a href=\"https:\/\/blog.billows.com.tw\/?p=1833\">https:\/\/blog.billows.com.tw\/?p=1833<\/a><\/p>\n\n\n\n<p>\u6709\u95dcLockBit2.0\u7684\u90e8\u5206\u5165\u4fb5\u6307\u6a19(Indicator of compromise -IOCs):<\/p>\n\n\n\n<p>URL:<\/p>\n\n\n\n<p>http:\/\/45.32.108.54:443\/c0000015.log<\/p>\n\n\n\n<p>http:\/\/45.32.108.54:443\/glib-2.0.dll<\/p>\n\n\n\n<p>IPv4: 149.28.137.7<\/p>\n\n\n\n<p>SHA 1:<\/p>\n\n\n\n<p>e35a702db47cb11337f523933acd3bce2f60346d<\/p>\n\n\n\n<p>729eb505c36c08860c4408db7be85d707bdcbf1b<\/p>\n\n\n\n<p>25fbfa37d5a01a97c4ad3f0ee0396f953ca51223<\/p>\n\n\n\n<p>1458421f0a4fe3acc72a1246b80336dc4138dd4b<\/p>\n\n\n\n<p>0c842d6e627152637f33ba86861d74f358a85e1f<\/p>\n\n\n\n<p>091b490500b5f827cc8cde41c9a7f68174d11302<\/p>\n\n\n\n<p>\u00a0&#8220;\u8f49\u8cbc\u3001\u5206\u4eab\u6216\u5f15\u7528\u6587\u7ae0\u5167\u5bb9\uff0c\u8acb\u8a3b\u660e\u51fa\u8655\u70ba\u7ae3\u76df\u79d1\u6280\u00a0<a href=\"https:\/\/www.billows.com.tw\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.billows.com.tw<\/a>\u00a0, \u4ee5\u514d\u89f8\u6cd5&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u64da\u89c0\u5bdf\uff0c\u52d2\u7d22\u8edf\u9ad4LockBit 2.0\u5df2\u57285\u6708\u4e0a\u3001\u4e2d\u65ec\uff0c\u653b\u64ca\u4e86\u56db\u9593\u4e0d\u540c\u7684\u53f0\u7063\u4f01\u696d\uff0c\u5927\u8086\u5728\u5176\u63ed\u79d8\u7db2\u7ad9\u4e0a\u516c\u544a\u53d7\u5bb3\u540d <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=1923\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[184,116],"class_list":["post-1923","post","type-post","status-publish","format-standard","hentry","category-6","tag-lockbit2-0","tag-lockbitransomware"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1923"}],"version-history":[{"count":3,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1923\/revisions"}],"predecessor-version":[{"id":2441,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1923\/revisions\/2441"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}