BevictorΰµÂ

֤ȯ¼ò³Æ£ºBevictorΰµÂ ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

Hermetic Wiper±¬·¢£¡BevictorΰµÂÓÉ¡°±ß¡±µ½¡°¶Ë¡±ÐÞ½¨Á¢Ì廯Çå¾²·ÀµØ

¾«×¼·ÀÓùHermetic Wiper£¡BevictorΰµÂÏÂÒ»´ú·À»ðǽ¡¢EDR¡¢²¡¶¾¹ýÂËÍø¹ØÒÔ¼°½©Ä¾Èä¼ì²âϵͳµÈ²úÆ·ÓÉ¡°±ß¡±µ½¡°¶Ë¡±ÐÞ½¨Á¢Ì廯Çå¾²·ÀµØ£¡

Hermetic Wiper±¬·¢£¡BevictorΰµÂÓÉ¡°±ß¡±µ½¡°¶Ë¡±ÐÞ½¨Á¢Ì廯Çå¾²·ÀµØ

Ðû²¼Ê±¼ä£º2022-03-01
ä¯ÀÀ´ÎÊý£º4587
·ÖÏí£º

ÏÖÔÚ £¬ÈËÀàÐÅÏ¢ÊÖÒÕµÄÏòËÞÊÀ³¤ £¬ ¡°Ç§ÀïÑÛ¡¢Ë³·ç¶ú¡±µÄÉñ»°ÔçÒѳÉΪÏÖʵ £¬ÐÅÏ¢Õ½¸üÊdzÉΪÏÖ´úÕ½ÕùµÄ½¹µãÖ®Ò»¡£¿ËÈÕ £¬Ò»ÖÖÖØ´óÐÂÐͶñÒâÈí¼þHermetic Wiper£¨ÓÖÃûKillDisk.NCV£©µÄ¹¥»÷ÔÙÒ»´ÎÔÚÁ½¹úÕ½ÕùÖÐÊܵ½ÈËÃǵĹØ×¢¡£¸Ã¶ñÒâÈí¼þʹÓÃHermetica Digital LtdÖ¤Êé¾ÙÐÐÊðÃû £¬²¢Å²ÓôÅÅÌ·ÖÇøÕýµ±Çý¶¯³ÌÐò £¬ÈÆ¿ªÉ±¶¾Èí¼þ¼ì²â £¬ÆÆËðWindowsµçÄÔµÄMBR·ÖÇø £¬Ó°ÏìϵͳÕý³£Æô¶¯ £¬Î£º¦ÖØ´ó¡£

ÈôÊÇËµÍøÂç¹¥»÷ÔÚ¹ú¼Ò¼äÊÇÒ»³¡Ã»ÓÐÏõÑ̵ÄÕ½Õù £¬ÄÇô¹ØÓÚÆóÒµ¶øÑÔ £¬ÍøÂç¹¥»÷¾Í¸üÊÇÐÎͬÉúÓëËÀµÄ¿¹Õù¡£ÍøÂç¹¥»÷ÖпÉÄܱ£´æÒþÃØÐÔ¹¥»÷ £¬ÈçÇÔÈ¡Ç鱨¡¢ÆÆËðÖ÷ÒªÊý¾Ý¡¢Ì±»¾Í¨Ñ¶ÏµÍ³µÈһϵÁÐÎÊÌâ¡£

BevictorΰµÂ´Ó½çÏß³ö·¢ £¬Öð²½ÖþÀζàά¶ÈÍøÂçÇå¾²·ÀµØ £¬¹¹½¨½çÏßµ½Öն˵ÄÁ¢Ì廯·ÀÓùϵͳ £¬²¢ÌṩÖÜÈ«µÄÇå¾²± £»¤ £¬ÓÐÓÃ×èÖ¹¸Ã¶ñÒâÈí¼þÉìÕÅ¡£ÂÄÀúÖ¤ £¬BevictorΰµÂÏÂÒ»´ú·À»ðǽ¡¢EDR¡¢²¡¶¾¹ýÂËÍø¹ØÒÔ¼°½©Ä¾Èä¼ì²âϵͳµÈϵÁвúÆ·¾ù¿É׼ȷ¼ì²â²¢²éɱ¸Ã¶ñÒâÈí¼þ¡£

²¡¶¾ÐÅÏ¢¸Å¿öÓëÑùÌìÖ°Îö
Ï»¬Éó²éÑù±¾ÍêÕûÆÊÎö¨Œ¨Œ¨Œ

³ÌÐòÔËÐкóÊ×ÏÈÌáÉýSeBackupPrivilegeȨÏÞ £»

Ö®ºó»ñÈ¡Ö÷»ú´¦Öóͷ£Æ÷µÄλÊý £¬´ÓPE×ÊÔ´¶ÎÖÐÊͷŶÔÓ¦µÄÇý¶¯Îļþ £»

ÒÔ·þÎñµÄ·½·¨¼ÓÔØÇý¶¯ £¬²¢¸ü¸Ä»îԾ״̬µÄϵͳvss·þÎñÆô¶¯ÀàÐÍSERVICE_DISABLED´Ó¶ø½ûÓÃvss·þÎñ £»

ÔÚc:/windows/system32/driverĿ¼ÏÂÊÍ·ÅËĸö×ÖĸÃüÃûµÄÇý¶¯³ÌÐòxrdr.sys²¢¼ÓÔØÇý¶¯ £»

½¨Éè¶à¸öÏ̲߳¢Ê¹Óó¤Ê±¼äµÄsleepÀ´ÈƹýɳÏäµÄ¼à¿ØÊ±¼ä £»

xrdr.sysÇý¶¯³ÌÐòͬÑù¾ßÓÐÊý×ÖÊðÃûµ«ÒѾ­ÓâÆÚ¡£ÆäÊý×ÖÊðÃûÁ¥ÊôÓڳɶ¼Ä³¿Æ¼¼ÓÐÏÞ¹«Ë¾ £¬´ÓÇý¶¯µÄ±àÒëʱ¼äºÍÊðÃûʱ¼ä¡¢PDBµÈÐÅÏ¢¿ÉÒÔÍÆ¶ÏÇý¶¯ÎļþºÜ¿ÉÄÜÊǰ×Îļþ £¬ÊôÓÚÇý¶¯µÄ°×ʹÓ᣸ÃÇý¶¯³ÌÐòÊÇ EaseUS Partition Master Èí¼þÖеÄÕýµ±Çý¶¯³ÌÐò £»

HermeticWiper,exeÀú³ÌÕ¼ÓÃÁ˽ϸߵÄCPUʹÓÃÂÊ £¬²¢ÏòÇý¶¯·¢ËÍIOCTL¿ØÖÆÂë £¬Õ¼ÓúܸߵÄI/OʹÓÃÂÊ £»

µ±ÊÖ¶¯¾ÙÐÐÖØÆôºó £¬ÓÉÓÚHermeticWiper,exe¸ü¸ÄÁËϵͳµ×²ãϵͳVBR £¬ÏµÍ³ÒѾ­ÎÞ·¨¾ÙÐÐÕý³£¿ª»ú¡£

½çÏß²à Ë«ÖØ·ÀÓùÎÞÒÅ©
Ò»ÖØ·ÀÓù

×÷ΪÕûÌå·À¶¾µÄµÚÒ»µÀ·ÀµØ £¬BevictorΰµÂ¹ýÂËÍø¹ØÕë¶Ô¶àÖÖЭÒéÁ÷Á¿¾ÙÐв¡¶¾¼ì²â¹ýÂË £¬ÓÐÓ÷ÀÓùͨ¹ýÎļþ¡¢Óʼþ¡¢ÍøÒ³µÈ·½·¨À¦°óÈö²¥µÄ²¡¶¾ÓÚÄÚÍøÖ®Íâ £¬ÊµÏÖ×Ô¶¯ÐÔ¡¢Ò»Á¬ÐÔ¡¢ºÏ¹æÐԵIJ¡¶¾·ÀÓù £¬¿ìËÙ¼ì²â²¢´¦Öóͷ£ÖÖÖÖ¶ñÒâÈí¼þ»ò´úÂë¡£

Õë¶ÔHermeticWiper¶ñÒâÈí¼þ £¬BevictorΰµÂ¹ýÂËÍø¹Ø¼ì²â´¦Öóͷ£·ÖΪÈý²½ £¬¼´¿ÉÌṩһÁ¬ÐÔ²»ÖÐÖ¹µÄ²¡¶¾¼ì²â´¦Öóͷ£·þÎñ £¬²¢¸¨ÒÔʵʱÌáÐѸ澯¡¢²¡¶¾±¬·¢±¨¾¯¡¢ÏêϸµÄÈÕÖ¾¡¢¿ÉÊÓ»¯±¨±í¡£

Ò»¡¢Éý¼¶µ½×îв¡¶¾ÌØÕ÷¿â

¶þ¡¢ÆôÓò¡¶¾É¨Ãè·þÎñ

Èý¡¢Ñ¡Ôñ²¡¶¾´¦Öóͷ£·½·¨

ÒѹºÖÃBevictorΰµÂ¹ýÂËÍø¹ØÏµÍ³£¨TopFilter£©µÄ¿Í»§ £¬¿Éͨ¹ýÒÔÏ·¾¶Éý¼¶×îв¡¶¾¿â¡£

²¡¶¾¿â°æ±¾ºÅ£ºkav-v2022.03.01.tir £»

ÏÂÔØµØÖ·£ºftp://ftp.topsec.com.cn/·À²¡¶¾Íø¹Ø(Top-Filter)/²¡¶¾¿âÍÑ»úÉý¼¶°ü/¼ì²â²¡¶¾¿â £»

¶þÖØ·ÀÓù

BevictorΰµÂ½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³£¨TopTVD£© £¬¼¯¹¥»÷¼ì²â¡¢DDoS¼ì²â¡¢½©Ä¾Èä¼ì²â¡¢¶ñÒâ³ÌÐò¼ì²â¡¢APT¼ì²â¡¢WEBÇå¾²¼ì²â¡¢ÐéÄâɳÏä¡¢ÔªÊý¾ÝÌáÈ¡¡¢Á÷Á¿ÆÊÎö¾Å´ó¹¦Ð§ÎªÒ»Ìå £»Ê×´´Ó¦ÓÃTAI-1ÖÇ»ÛÒýÇæ+ÐéÄâɳÏäÊÖÒÕ £¬ÓµÓÐǶÈëʽÍþвÇ鱨¿â £»ÊµÏÖ¶àÖÖÍþвÖÜÈ«¼ì²â £¬Í»ÆÆÁ˹ŰåÌØÕ÷¿âÆ¥ÅäÊÖÒÕÔ¼Êø £¬ÊÇ·¢Ã÷δ֪ÍþÐ²ÌØÊâÊÇAPT¹¥»÷µÄÓÐÁ¦¹¤¾ß¡£

ÏÖÔÚ £¬BevictorΰµÂ½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³ÒÑ¿ÉÒÔÕë¶Ô´Ë¶ñÒâÈí¼þ¹¥»÷¾ÙÐÐÇå¾²¼ì²â¡£ÒѹºÖÃBevictorΰµÂ½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³£¨TopTVD£©µÄ¿Í»§ £¬¿ÉÒÔÉý¼¶ÍþвÇ鱨¿â¾ÙÐÐÓÐÓüà²â·À»¤¡£

ÍþвÇ鱨¿â°æ±¾ºÅ£ºti-v2022.03.01.001.tor £»

ÏÂÔØµØÖ·£ºftp://ftp.topsec.com.cn/BevictorΰµÂÏÂÒ»´úÈëÇÖ·ÀÓùϵͳ(NGIDP)/ÍþвÇ鱨¿â/ ti-v2022.03.01.001.tor¡£

Öն˲à È«·½Î»± £»¤·À¸Ä¶¯

ÔÚÖն˲à £¬BevictorΰµÂEDRͨ¹ýÔ¤·À¡¢·ÀÓù¡¢¼ì²â¡¢ÏìÓ¦µÄÒ»Ì廯Ç徲ϵͳ¸¶ÓëÖÕ¶ËÍþв·ÀÓùÄÜÁ¦ £¬Í¨¹ýÒ»Á¬µØ·ÀÓùºÍ¼ì²âÆÊÎö £¬¸ü¾«×¼µØÊ¶±ðÖÖÖÖÀÕË÷²¡¶¾¶ÔÖն˵ÄÈëÇÖ £¬²úÆ·ÍŽá¶àά¶È²¡¶¾·ÀÓù¡¢ÏµÍ³¼Ó¹Ì¡¢Î¢¸ôÀë¼°×Ô¶¯ÏìÓ¦µÈÊÖÒÕ £¬È«·½Î»·ÀÓù²¡¶¾¡£

Õë¶ÔHermeticWiper¶ñÒâÈí¼þ £¬µ±¸Ã¶ñÒâÈí¼þδ±»´¥·¢ £¬BevictorΰµÂEDRͨ¹ý²¡¶¾É¨Ãè¼´¿É¶ÔÆä¾ÙÐо«×¼Ê¶±ðÓë´¦Öóͷ£ £»µ±¸Ã¶ñÒâÈí¼þ±»´¥·¢ £¬Ôò»á¶ÔϵͳĿ¼¾ÙÐиĶ¯ÆÆËð´ÅÅÌ £¬BevictorΰµÂEDR¿Í»§¶Ëϵͳ¼Ó¹ÌÊÖÒտɶÔϵͳҪº¦Î»ÖþÙÐÐÖØµã¼à¿Ø £¬±ÜÃâ±»¶ñÒâ¸Ä¶¯ £¬É¨³ý»òÆÆËðϵͳÊý¾Ý¡£Í¬Ê± £¬Èô¸Ã¶ñÒâÈí¼þͨ¹ýUÅÌ¡¢Óʼþ¡¢ÍøÒ³¡¢Í¨Ñ¶¹¤¾ßµÈ·½·¨Èö²¥ £¬BevictorΰµÂEDRÔò¿ÉÒÔͨ¹ýUÅ̱ £»¤¡¢Óʼþ± £»¤¡¢¶ñÒâÍøÕ¾×èµ²¡¢ÎļþʵÑé¼à¿ØµÈ¶àά¶È²¡¶¾·ÀÓù £¬ÖÜÈ«¶Å¾ø¶ñÒâÈí¼þÂ䵨ÖÕ¶Ë¡£

BevictorΰµÂEDR»ñÈ¡·½·¨£º

BevictorΰµÂEDRÆóÒµ°æÊÔÓ㺿Éͨ¹ýBevictorΰµÂ¸÷µØ·Ö¹«Ë¾»ñÈ¡£¨ÅÌÎÊÍøÖ·£ºhttp://www.topsec.com.cn/contact/£©

BevictorΰµÂEDRµ¥»ú°æÏÂÔØµØÖ·£ºhttp://edr.topsec.com.cn

Õë¶ÔÇå¾²ÊÂÎñƵ·¢ £¬BevictorΰµÂ½¨Òé¿Éͨ¹ýÒÔϼ¸¸öÒªÁì¾ÙÐÐÌá·À£º

²»Òª·­¿ªÈªÔ´²»Ã÷µÄÍøÒ³¡¢µç×ÓÓʼþÁ´½Ó»ò¸½¼þ £¬ÕâЩºÜ¿ÉÄÜÒþ²Ø×Å´ó×ڵIJ¡¶¾¡¢Ä¾Âí £¬Ò»µ©·­¿ª £¬»á×Ô¶¯½øÈëµçÄÔ²¢Òþ²ØÔÚµçÄÔÖÐ £¬Ôì³ÉÎļþɥʧËð»µÉõÖÁµ¼ÖÂϵͳ̱»¾ £»

°´ÆÚ±¸·ÝµçÄÔÖеÄÖ÷ÒªÎļþ×ÊÁÏ £¬ÒÔ±ÜÃâÔÚÒâÍâÇéÐÎÏÂÔì³ÉµÄÎļþÐÅϢɥʧÎÊÌâ £»

²Ù×÷ϵͳÃÜÂë½ÓÄɸßÇ¿¶È×éºÏ £¬Í¬Ê±Î´±ØÆÚµÄÌæ»»ÃÜÂë £¬ÈôÊÇÃÜÂëÒ»³ÉÎȹ̵ϰ £¬¼«Ò×ÒýÆðϵͳµÄÇå¾²ÐÔÎÊÌâ £»

ʵʱÐÞ¸´ÏµÍ³Îó²î £¬Îó²î¾ÍÏñÊÇÅÌËã»úųÈõµÄºóÃÅ £¬²¡¶¾ºÍ¶ñÒâÈí¼þ¿ÉÒÔͨ¹ýÕâ¸öųÈõµÄºóÃŹ¥Æä²»±¸¡£

¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼