TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Maersk IT systems infected with ransomware

106 点作者 TonnyGaric将近 8 年前

12 条评论

simonvc将近 8 年前
I worked a Maersk for a couple of years. This happened once before, we came in and all Maersk&#x27;s machines were randomly shutting down.<p>I heard later a rumour that the reason the AV didn&#x27;t pick it up was it was a 0-day (stuxnet derived before that was known) and it was literally targeting the SCADA systems on boats.. but that&#x27;s also the plot of Hackers, so take that with a pinch of salt.<p>Anyway being the build&#x2F;devops&#x2F;tooling person on a project i burned 40 dvd&#x27;s with eclipse and ubuntu and handed to them to the devs and they booted into Ubuntu and kept developing.<p>All was going fine until i got a telling off from the Corporate IT security team complaining that our unauthorised Ubuntu machines weren&#x27;t running AV and so could be introducing viruses into the network.<p>Total facepalm.
评论 #14646151 未加载
评论 #14645842 未加载
评论 #14646168 未加载
smartbit将近 8 年前
Essence of Maersk attack in one tweet <a href="https:&#x2F;&#x2F;twitter.com&#x2F;craiu&#x2F;status&#x2F;879690795946827776" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;craiu&#x2F;status&#x2F;879690795946827776</a><p><i>New Petrwrap&#x2F;Petya ransomware has a fake Microsoft digital signature appended. Copied from Sysinternals Utils.</i><p>I was sitting next to someone who wanted didn&#x27;t close his laptop immediately when notified, 1 minute later it was too late. Most of my colleagues went home, even if their laptop was not infected (also over de VPN) they are no allowed to start the machine. Some departments ask people to stay home tomorrow too. Those with MacBooks continue working. And <i>externals</i>.<p>In Rotterdam APM Terminals has shutdown.
评论 #14646144 未加载
评论 #14646321 未加载
评论 #14645770 未加载
r721将近 8 年前
It looks like there is a massive Petya ransomware attack:<p>&gt;Russia, Ukraine, Spain, France - confirmed reports about #Petya ransomware outbreak. Good morning, America.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;codelancer&#x2F;status&#x2F;879688596852101120" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;codelancer&#x2F;status&#x2F;879688596852101120</a><p>&gt;Petrwrap&#x2F;Petya ransomware variant with contact wowsmith123456@posteo.net spreading worldwide, large number of countries affected.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;craiu&#x2F;status&#x2F;879689411419668480" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;craiu&#x2F;status&#x2F;879689411419668480</a><p>Sample: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;benkow_&#x2F;status&#x2F;879692704724250628" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;benkow_&#x2F;status&#x2F;879692704724250628</a><p>Articles:<p><a href="http:&#x2F;&#x2F;www.independent.co.uk&#x2F;news&#x2F;world&#x2F;europe&#x2F;ukraine-cyber-attack-hackers-national-bank-state-power-company-airport-rozenko-pavlo-cabinet-a7810471.html" rel="nofollow">http:&#x2F;&#x2F;www.independent.co.uk&#x2F;news&#x2F;world&#x2F;europe&#x2F;ukraine-cyber...</a><p><a href="https:&#x2F;&#x2F;motherboard.vice.com&#x2F;en_us&#x2F;article&#x2F;qv4gx5&#x2F;a-ransomware-outbreak-is-infecting-computers-across-the-world-right-now" rel="nofollow">https:&#x2F;&#x2F;motherboard.vice.com&#x2F;en_us&#x2F;article&#x2F;qv4gx5&#x2F;a-ransomwa...</a>
评论 #14645997 未加载
onion2k将近 8 年前
A shipping company being attacked by malware worm designed to steal money is <i>literally</i> the plot of the movie Hackers.
评论 #14646350 未加载
secfirstmd将近 8 年前
Hey, FWIW we had to do some response for ransomware cases recently. There was a lack of decent stuff out there for how IT teams should deal with it. So we contributed to putting together this quick checklist:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;0xswap&#x2F;guides&#x2F;blob&#x2F;master&#x2F;ransomware-triage.txt" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;0xswap&#x2F;guides&#x2F;blob&#x2F;master&#x2F;ransomware-tria...</a><p>Would be great if more people wanted to add to it.
fest将近 8 年前
About a year ago:<p>One morning a colleague notices that a particular Windows share used by every EE in the multi-national company now contains encrypted files and generic request for ransom.<p>Highlight of the e-mail thread that followed: &quot;&lt;Name of another coworker whose account was used to encrypt files&gt;, virus <i></i>again<i></i>?&quot;
pasta将近 8 年前
There are reports of other large companies that currently are being infected.<p>It almost looks like the virus has been slumbering in systems and today woke up.
vuln将近 8 年前
I laughed way too hard at this.<p>&#x27;Petya sees you when you&#x27;re sleeping<p>Petya knows when you&#x27;re awake<p>Don&#x27;t click the link in that email or IR gets no break&#x27;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;FourOctets&#x2F;status&#x2F;879700290395439105" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;FourOctets&#x2F;status&#x2F;879700290395439105</a>
nthcolumn将近 8 年前
Not just Maersk. Petya going global. Writes to boot sector.
评论 #14646226 未加载
NeutronBoy将近 8 年前
WaPo have just published a story about the attacks <a href="https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;world&#x2F;europe&#x2F;ukraines-government-key-infrastructure-hit-in-massive-cyberattack&#x2F;2017&#x2F;06&#x2F;27&#x2F;7d22c7dc-5b40-11e7-9fc6-c7ef4bc58d13_story.html" rel="nofollow">https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;world&#x2F;europe&#x2F;ukraines-governm...</a>
Hoshea将近 8 年前
Anything special about the way this one is spreading or just the usual suspects?
评论 #14645757 未加载
评论 #14645630 未加载
proyb2将近 8 年前
DBSchenker and many logistic companies are still running Windows XP on some legacy PC. I have encountered one PC had ransomware too.
评论 #14645624 未加载
评论 #14645914 未加载