免費防毒軟體的三大威脅

這幾年全球重大資安事件頻傳,世界容易遭受駭客病毒攻擊國家,香港、台灣一直也名列前茅,資安意識雖逐年抬頭,但心存僥倖的仍不少,這也是為什麼每次香港、台灣也都會無法幸免於難的主因,在與大家討論到底要使用免費防毒軟體還是付費防毒軟體前,想先問各位兩個簡單的問題,

您(公司)是否願意用很低的金額或無償交換您(公司)的隱私或財產,如個資及重要文件檔案等…,卻只能獲得基本的病毒防護?!

您(公司)會使用一個免費的鎖在您家的大門上,讓提供免費鎖的公司有鑰匙進入您的房子,還是您願意花小錢購買了全功能的鎖而只有您有鑰匙可以進入家門呢?!

我想答案已很清楚了,接下來跟大家分析使用免費防毒軟體及付費防毒軟體的差別,

1. 隱私/財產全都露

天下沒有白吃的午餐,這個道理人人都懂,絕大多數的防毒軟體都是由專業的資安公司所推出,它具有一定的開發以及維護成本,例如研發人員需要撰寫防毒軟體的程式,並且隨時收集最新的病毒資訊,還要發佈更新檔,以提升防毒軟體的防護能力。然而如果消費者選擇的是免費的防毒軟體,那麼這些成本是要如何回收呢?大家可以好好的思考一下….

之前時有所聞,免費的防毒軟體更改使用者條款,放寬使用者個人資料的使用限制,讓廠商可能可以將使用者的瀏覽器歷史記錄、搜尋記錄、GPS定位記錄等無法辨識個人身份的資料,出售給廣告商,用來作為廣告投放的參考依據。請問您在下載或使用這些軟體之前,是否都有仔細的閱讀這些相關的條約內容,還是想快點把軟體程式安裝完,就只是按「Yes」或「同意」;又如果軟體沒有繁體中文的說明,您是否也有耐下心來逐一閱讀呢。如果以上情況您都有的話,那麼”恭喜”您,您己經將您的隱私曝光在陽光下了。

結論:花小錢_即可確保你的隱私安全

2. 當災難發生時,只能坐以待斃

若您不幸遭受資安威脅侵害時,使用免費防毒軟體,則求救無門,只能花錢了事,以2017年讓人聞之色變的勒索病毒為例,通常會向受害者勒索價值 50 至 500 美金不等的贖金,並要求以比特幣付款,如果以美金 50 元來計算的話,大約等於港幣 400 元,已經比一般防毒軟體一年授權的費用還要高了,再加上您不幸被勒索的金額是美金 500 元的話,就等於需要支付港幣 4,000 元;好一點的是您付了錢,勒索者會提供解密金鑰,讓您拿回檔案,算是花錢消災。慘一點的,付了錢,檔案還是付之一炬。請問您是要省一時的小錢保護您的重要檔案資料,還是要花您無法預測且一定得支付的大錢呢? 建議您好好思考這個問題….

反觀,使用付費防毒軟體時,完整的防護功能或機制,除了協助您即時抵禦資安之威脅外,您還也可以跟在地團隊透過客服電話或請他們派專人至公司享受專業的資安服務,讓您或公司的損失可以降至最低。

結論:花小錢_即可享”網路安全”大效益,還能保護重要資料及享有在地且專業的資安團隊服務

3. 軟體或系統的漏洞的潛在資安威脅

天下沒有完美的事物,軟體會有Bug,就跟一般人會說錯話、寫錯字一樣,在所難免。不論是硬體或硬體的因素,系統只要出一次包,就可能影響成千上萬使用者。但其中執行的程式一旦有功能性的失誤,甚至有安全性漏洞,想要修正就沒那麼簡單,來來回回之間,往往耗費許多時間和人力進行。對許多IT人員來說,持續關注系統資安弱點資訊、定期執行漏洞修補,已經成為例行公事之一。從2001到2003年之間,開始有許多惡意程式利用Windows、IE、Outlook Express、Outlook的安全性弱點發動攻擊,肆虐全球個人電腦與伺服器,像是Code Red、Nimda、Blaster、Sasser等蠕蟲。

除了微軟,在個人電腦使用率相當高的數位內容格式Adobe PDF和Flash在2009年之後,也因為漏洞而頻頻遭到攻擊,到了2012年、2013年,Java成為新的苦主,再舉2017年「WanaCrypt0r 2.0」的勒索軟體攻擊感染,近乎所有 Windows 系統及其伺服器版本均受威脅,而這都在在證明知名及很多人在使用的軟體,是駭害的最愛,因為每次出手皆有斬獲,這真的不是危言聳聽。

以上所述,也都不是只具簡單及基本防護功能的免費防毒軟體所能解決的,因此對抗無法預期的軟體或系統漏洞所產生的已知或未知的資安威脅,選擇專業且知名的資安品牌或解決方案來做防護或抵禦是很重要的。

結論:花小錢_買專業知名的資安產品或解決方案,方能高枕無憂

關於Version 2 Limited
Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。 

ESET boosts value proposition for MSPs via new direct plug-in with ConnectWise

ESET today announced the launch of ESET Direct Endpoint Management with ConnectWise, a company that transforms how technology solution providers build, manage, and grow their businesses. The new Remote Management and Monitoring (RMM) plug-in for ConnectWise Automate speeds up and improves installation processes of ESET endpoints for the company’s Managed Service Providers (MSPs).

ESET Direct Endpoint Management establishes a direct connection between ESET endpoints and the ConnectWise Automate console. Built with the ConnectWise equipped partner in mind, the plug-in leverages the existing ConnectWise Agent to simplify deployment and management without sacrificing on performance or functionality.

While ESET currently offers a plug-in that connects ESET Remote Administrator (ERA) and ConnectWise Automate, this new version does not require MSPs to install ERA at all, meaning there are no additional servers or intermediate console to manage.  MSPs can get up and running faster, and stay running with fewer issues caused by complex integration. 

“We’ve had a strong relationship with ESET for many years, and from working with them, we know that we are partnering with a proven and reliable technology company,” said Travis Vigneau, director of channel sales and alliances for ConnectWise. “This new direct plug-in demonstrates ESET’s commitment to constantly improving what they offer to the entire ecosystem.”

“We understand how important our MSPs are and we want to help them overcome any challenges they may face,” said Jeronimo Varela, Director of Global Sales at ESET. “That’s why we’ve focused on developing the very best tools, with world-class protection solutions, to not only ensure our MSPs can deliver top-quality service efficiently, but also so that they can become trusted advisors to their customers.”


To find out more about ESET’s MSP program, please click here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About ConnectWise
ConnectWise transforms how technology solution providers successfully build, manage and grow their businesses. Our award-winning set of software solutions provides a fully integrated, seamless experience to companies in more than 50 countries, giving them the ability to increase their productivity, efficiency and profitability. When combined with our relentless commitment to innovation, powerful network of ideas and experts, unparalleled passion for our users, and more than 35 years of experience, ConnectWise software solutions deliver the support companies want at each step of their business journey. For more information, visit http://www.ConnectWise.com.

GREYCORTEX RELEASES MENDEL 3.0

March brings the most recent version of GREYCORTEX MENDEL; Version 3.0. As part of this release, MENDEL 3.0 brings several new features SOC administrators will love, as well as continued expansion for SCADA networks and upgraded hardware support.

Specifically, MENDEL now supports the latest in DELL Rx40 hardware. Those in SCADA network environments will enjoy updates to the MENDEL IDS system. Version 3.0 also includes visibility for the NFS (Network File System) and IEC 60870 5 101/104 protocols. SOC users will note that dashboards have been adjusted to better accommodate multiple sensors, and that the overall capacity for sensors connected to one collector has been increased to 30. Finally, MENDEL’s capabilities have been expanded to include the ability to add your own blacklist file, as well as export files to IBM Qradar SIEM via the LEEF format.
New Features

  • GREYCORTEX has added support for the latest Dell servers (Rx40) so users will now be able to use the latest hardware.
  • SCADA support continues, with updates to the MENDEL IDS engine to include visibility IEC 60870 5 101/104 protocols – bringing new security for professionals in the energy infrastructure sector.
  • SOC administrators will appreciate several new features in version 3.0, including new dashboard settings suitable for multiple sensors for better SOC visualization, as well as the ability to add up to 30 sensors on one collector, and finally; LEEF expert format for events exported to IBM Qradar SIEM, and the ability to upload users’ own blacklists in .csv file.

Improvements
Several MENDEL features were improved. These included easier license extension, host identification, decryption performance, status monitoring, and data export.
Bug Fixes

In general, our development team focused on improving the user experience and reporting.

Please note that updating to version 3.0 requires appliance restart and may take up to one hour.

Contact your local GREYCORTEX partner to find out how you can put MENDEL v3.0 to work for you.

FriedEx: BitPaymer ransomware the work of Dridex authors

Dridex has been a nightmare for computer users, companies and financial institutions for several years now, so much so that for many, it has become the first thing that comes to mind when talking about banking trojans.

Recent ESET research shows that the authors of the infamous Dridex banking trojan are also behind another high-profile malware family – a sophisticated ransomware detected by ESET products as Win32/Filecoder.FriedEx and Win64/ Filecoder.FriedEx, and also known as BitPaymer.

Dridex

The Dridex banking trojan first appeared in 2014 as a relatively simple bot inspired by older projects, but the authors quickly turned this bot into one of the most sophisticated banking trojans on the market. The development seems to be steady, with new versions of the bot including minor fixes and updates being released on a weekly basis, with occasional breaks. From time to time, the authors introduce a major update that adds some crucial functionality or larger changes. The last major update from version 3 to version 4, released at the beginning of 2017, gained attention for adopting the Atom Bombing injection technique, and later in the year also introducing a new MS Word zero-day exploit, which helped spread the trojan to millions of victims.

As of this writing, the most recent version of Dridex is 4.80 and includes support for webinjects into Chrome version 63. Dridex 4.80 was released on December 14th 2017.

Note: Last year we released a tool that helps identify malicious hooks in popular web browsers. The tool is designed to help incident responders discover potential banking trojan infections, including Dridex.

FriedEx

Initially dubbed BitPaymer, based on text in its ransom demand web site, this ransomware was discovered in early July 2017 by Michael Gillespie. In August, it returned to the spotlight and made headlines by infecting NHS hospitals in Scotland.

FriedEx focuses on higher profile targets and companies rather than regular end users and is usually delivered via an RDP brute force attack. The ransomware encrypts each file with a randomly generated RC4 key, which is then encrypted using the hardcoded 1024-bit RSA public key and saved in the corresponding .readme_txt file.

In December 2017, we took a closer look at one of the FriedEx samples and almost instantly noticed the resemblance of the code to Dridex. Intrigued by the initial findings, we dug deep into the FriedEx samples, and found out that FriedEx uses the same techniques as Dridex to hide as much information about its behavior as possible.

It resolves all system API calls on the fly by searching for them by hash, stores all strings in encrypted form, looks up registry keys and values by hash, etc. The resulting binary is very low profile in terms of static features and it’s very hard to tell what the malware is doing without a deeper analysis.

This prompted yet further analysis, which revealed a number of additional attributes that confirmed our initial suspicions – the two malware families were created by the same developers.

Code Similarities

Figure 1. Comparison of GetUserID function present in both Dridex and FriedEx samples

In Figure 1, we can see a part of a function used for generating UserID that can be found across all Dridex binaries (both loaders and bot modules). As we can see, the very same Dridex-specific function is also used in the FriedEx binaries. The function produces the same results – it generates a string from several attributes of the victim’s machine that serves as a unique identifier of the given victim, either in the botnet in the case of Dridex, or of the ransomware with FriedEx. Indeed, the screenshots would make for a good “Spot the difference” game!

This kind of similarity to Dridex is present throughout the FriedEx binaries and only very few functions that mostly correspond to the specific ransomware functionality are not found in the Dridex sample (i.e. the file encryption loop and creation of ransom message files).

 Figure 2. Comparison of function order in Dridex and FriedEx samples. 
Functions that are missing in the other sample are highlighted in the corresponding color

Another shared feature is the order of the functions in the binaries, which occurs when the same codebase or static library is used in multiple projects. As we can see in Figure 2, while the FriedEx sample seems to be missing some of the functions present in the Dridex sample and vice versa (which is caused by the compiler omitting unreferenced/unused functions), the order remains the same.

Note: Auto-generated function name pairs, based on code addresses (sub_CA5191 and sub_2A56A2, etc), obviously do not match, but the code they refer to does.

It’s also worth mentioning that both Dridex and FriedEx use the same malware packer. However, since the packer is very popular nowadays (probably due to its effectiveness in avoiding detection and hampering analysis) and used by other well-known families like QBot, Emotet or Ursnif, we don’t really consider that alone strong evidence.

PDB paths

When building a Windows executable, the linker may include a PDB (Program Database) path pointing to a file that contains debug symbols that help the developer with debugging and identifying crashes. The actual PDB file is almost never present in malware, because it’s a separate file that doesn’t get into distribution. However, sometimes even just the path, if included, can provide valuable information, because PDB files are located in the same directory as the compiled executable by default and usually also have the same base name followed by the .pdb extension.

As one might guess, PDB paths are not included in malware binaries very often, as the attackers don’t want to give away any information. Fortunately, some samples of both families do include PDB paths.

Figure 3. List of all PDB paths found in the Dridex and FriedEx projects

As you can see in Figure 3, the binaries of both projects are being built in the same, distinctively named directory. Based on a search across all of our malware sample metadata, we have concluded that the path S:Work_bin is unique to the Dridex and FriedEx projects.

Timestamps

We found several cases of Dridex and FriedEx with the same date of compilation. This could, of course, be coincidence, but after a closer look, we quickly ruled out the “just a coincidence” theory.

Not only do the compilations with the same date have time differences of several minutes at most (which implies Dridex guys probably compile both projects concurrently), but the randomly generated constants are also identical in these samples. These constants change with each compilation as a form of polymorphism, to make the analysis harder and to help avoid detection.

This might be completely randomized in each compilation or based on some variable like the current date.

Figure 4. GetAPIByHash function in Dridex samples with compilation time difference of 3 days. The highlighted constant is different

In Figure 4, we have the comparison of two Dridex loader samples with a three-day difference between compilation timestamps. While the loaders are almost identical with the only difference being their hardcoded data, such as encryption keys and C&C IPs, the constants are different, and so are all the hashes that are based on them. On the other hand, in Figure 5, we can see the comparison of the FriedEx and Dridex loader from the same day (in fact, with timestamps just two minutes apart). Here, the constants are the same, meaning both were probably built during the same compilation session.

Figure 5. GetAPIByHash function in Dridex and FriedEx binaries compiled the same day. 
The highlighted constant is the same in both samples

Compiler information

The compiler information only further supports all the evidence we found so far – the binaries of both Dridex and FriedEx are compiled in Visual Studio 2015. This is confirmed by both the linker version found in the PE Header and Rich Header data.

Figure 6. Rich header data found in Dridex and FriedEx samples

Apart from the obvious similarities with Dridex, we came across a previously unreported 64-bit variant of the ransomware. As the usual 32-bit version of the ransomware can target both x86 and x64 systems, we consider this variant to be a bit of a curiosity.

Conclusion

With all this evidence, we confidently claim that FriedEx is indeed the work of the Dridex developers. This discovery gives us a better picture of the group’s activities – we can see that the group continues to be active and not only consistently updates their banking trojan to maintain its webinject support for the latest versions of Chrome and to introduce new features like Atom Bombing, but that it also follows the latest malware “trends”, creating their own ransomware.

We can only guess what the future will bring, but we can be sure that the Dridex gang isn’t going anywhere anytime soon and that they will keep innovating their old project and possibly extend their portfolio with a new piece here and there.

For a long time, it was believed that the Dridex gang was a one-trick pony that kept their focus on their banking trojan. We have now found that this is not the case and that they can easily adapt to the newest trends and create a different kind of malware that can compete with the most advanced in its category.

IoCs

Win32/Dridex.BE C70BD77A5415B5DCF66B7095B22A0DEE2DDA95A0

Win64/FriedEx.A CF1038C9AED9239B6A54EFF17EB61CAB2EE12141

Win32/FriedEx.A 8AE1C1869C42DAA035032341804AEFC3E7F3CAF1

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

免費防毒軟體的三大威脅

這幾年全球重大資安事件頻傳,世界容易遭受駭客病毒攻擊國家,台灣一直也名列前茅,資安意識雖逐年抬頭,但心存僥倖的仍不少,這也是為什麼每次台灣也都會無法幸免於難的主因,在與大家討論到底要使用免費防毒軟體還是付費防毒軟體前,想先問各位兩個簡單的問題,

您(公司)是否願意用很低的金額或無償交換您(公司)的隱私或財產,如個資及重要文件檔案等…,卻只能獲得基本的病毒防護?!

您(公司)會使用一個免費的鎖在您家的大門上,讓提供免費鎖的公司有鑰匙進入您的房子,還是您願意花小錢購買了全功能的鎖而只有您有鑰匙可以進入家門呢?!

我想答案已很清楚了,接下來跟大家分析使用免費防毒軟體及付費防毒軟體的差別,

1. 隱私/財產全都露

天下沒有白吃的午餐,這個道理人人都懂,絕大多數的防毒軟體都是由專業的資安公司所推出,它具有一定的開發以及維護成本,例如研發人員需要撰寫防毒軟體的程式,並且隨時收集最新的病毒資訊,還要發佈更新檔,以提升防毒軟體的防護能力。然而如果消費者選擇的是免費的防毒軟體,那麼這些成本是要如何回收呢?大家可以好好的思考一下….

之前時有所聞,免費的防毒軟體更改使用者條款,放寬使用者個人資料的使用限制,讓廠商可能可以將使用者的瀏覽器歷史記錄、搜尋記錄、GPS定位記錄等無法辨識個人身份的資料,出售給廣告商,用來作為廣告投放的參考依據。請問您在下載或使用這些軟體之前,是否都有仔細的閱讀這些相關的條約內容,還是想快點把軟體程式安裝完,就只是按「Yes」或「同意」;又如果軟體沒有繁體中文的說明,您是否也有耐下心來逐一閱讀呢。如果以上情況您都有的話,那麼”恭喜”您,您己經將您的隱私曝光在陽光下了。

結論:花小錢_即可確保你的隱私安全

2. 當災難發生時,只能坐以待斃

若您不幸遭受資安威脅侵害時,使用免費防毒軟體,則求救無門,只能花錢了事,以2017年讓人聞之色變的勒索病毒為例,通常會向受害者勒索價值 50 至 500 美金不等的贖金,並要求以比特幣付款,如果以美金 50 元來計算的話,大約等於新台幣 1,500 元,已經比一般防毒軟體一年授權的費用還要高了,再加上您不幸被勒索的金額是美金 500 元的話,就等於需要支付新台幣 15,000 元;好一點的是您付了錢,勒索者會提供解密金鑰,讓您拿回檔案,算是花錢消災。慘一點的,付了錢,檔案還是付之一炬。請問您是要省一時的小錢保護您的重要檔案資料,還是要花您無法預測且一定得支付的大錢呢? 建議您好好思考這個問題….

反觀,使用付費防毒軟體時,完整的防護功能或機制,除了協助您即時抵禦資安之威脅外,您還也可以跟在地團隊透過客服電話或請他們派專人至公司享受專業的資安服務,讓您或公司的損失可以降至最低。

結論:花小錢_即可享”網路安全”大效益,還能保護重要資料及享有在地且專業的資安團隊服務

3. 軟體或系統的漏洞的潛在資安威脅

天下沒有完美的事物,軟體會有Bug,就跟一般人會說錯話、寫錯字一樣,在所難免。不論是硬體或硬體的因素,系統只要出一次包,就可能影響成千上萬使用者。但其中執行的程式一旦有功能性的失誤,甚至有安全性漏洞,想要修正就沒那麼簡單,來來回回之間,往往耗費許多時間和人力進行。對許多IT人員來說,持續關注系統資安弱點資訊、定期執行漏洞修補,已經成為例行公事之一。從2001到2003年之間,開始有許多惡意程式利用Windows、IE、Outlook Express、Outlook的安全性弱點發動攻擊,肆虐全球個人電腦與伺服器,像是Code Red、Nimda、Blaster、Sasser等蠕蟲。

除了微軟,在個人電腦使用率相當高的數位內容格式Adobe PDF和Flash在2009年之後,也因為漏洞而頻頻遭到攻擊,到了2012年、2013年,Java成為新的苦主,再舉2017年「WanaCrypt0r 2.0」的勒索軟體攻擊感染,近乎所有 Windows 系統及其伺服器版本均受威脅,而這都在在證明知名及很多人在使用的軟體,是駭害的最愛,因為每次出手皆有斬獲,這真的不是危言聳聽。

以上所述,也都不是只具簡單及基本防護功能的免費防毒軟體所能解決的,因此對抗無法預期的軟體或系統漏洞所產生的已知或未知的資安威脅,選擇專業且知名的資安品牌或解決方案來做防護或抵禦是很重要的。

結論:花小錢_買專業知名的資安產品或解決方案,方能高枕無憂

全球資安大廠ESET一直致力開發主動偵測、多層級的安全技術,並結合自動化的機器學習和人類知識,基於30 年的研究經驗,為各種規模的企業和端點平台,提供主動和智慧的防護產品或解決方案。連年榮獲Virus Bulletin 100獎項肯定, 優異的成績持續保持業界領先地位。全球擁有超過1億的用戶,代理機構遍及全球超過180個國家,支援多種語系,亞太區並由專業的團隊,提供在地化的服務協助、是個人及企業值得信賴的防毒軟體品牌。

 

有關2018新版功能或企業資安解決方案,請洽ESET資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://www.eset.tw/

歡迎加入資安電子報,即時掌握資訊與最新活動:https://www.eset.tw/e-news/subscribe/

開春獻大禮~~即日起,凡新購【ESET家庭辦公室資安包】,上網登錄即送日本Brother事務機!!!

回顧2017三大資安攻擊型態–勒索病毒(WannaCryptor等)、目標式攻擊及DDoS攻擊,各產業無一倖免。而WannaCry是第一個利用Windows系統中SMB漏洞進行攻擊的勒索軟體,直到現在都還有很多駭客利用SMB漏洞發動資安攻擊,且攻擊對象以一般中小企業為主,全球資安大廠ESET推出【家庭辦公室資安包】,適合5-20台電腦以內的小型企業及工作室,此方案結合檔案伺服器與行動裝置防護,以最優秀的主動防禦技術,不影響公司系統架構,提供最優質的資安防護,讓您花小成本,資安防護大效益,一舉打擊駭客防堵勒索。 ESET開春重炮出擊,即日起凡新購【家庭辦公室資安包】20台3年,上網登錄即送日本Brother事務機,讓您“一舉兩得”且省更多,同時擁有安全的網路環境還增添優質辦公配備。數量有限,動作要快!!!欲知活動詳情可電洽資安團隊(02)7722-6899,或上ESET官網查詢:https://www.eset.tw/event/business/

GREYCORTEX OPENS JAPANESE OFFICE, ANNOUNCES FIRST PARTNER AND CUSTOMERS

GREYCORTEX is happy to announce that we have successfully entered the Japanese market with our first office outside of Europe, and first Japanese partner and customers.
The new GREYCORTEX office, located in Kobe, Japan, will focus on sales and service across the APAC region. It will be led by Milan Fujita, who brings nearly 20 years of experience in the software sector and the Japanese and APAC markets. The office will also coordinate the regional collaboration between GREYCORTEX and its regional ESET technology alliance partners. The office may be contacted at: Kobe Fashion Mart 10F, 6-9 Koyo-cho Naka, Higashinada-ku Kobe, Hyogo, Japan 658-0032.
GREYCORTEX is also happy to announce our first partner in Japan: iSEC. Information Security Inc. Based in Kobe City, iSEC is led by CEO Yoshihisa Suzuki. iSEC offers the MENDEL Network Traffic Analysis throughout the country. The relationship is already bearing fruit, with two customers implementing GREYCORTEX MENDEL; Hyogo Prefectural Government (https://web.pref.hyogo.lg.jp/fl/index.html) and University of Hyogo (http://www.u-hyogo.ac.jp/english/index.html)
We look forward to many years of success from these relationships.

GREYCORTEX MONITORS NATO CCDCOE CYBER DEFENSE EXERCISE

GREYCORTEX is happy to announce that we, represented by Petr Chmelar, Chief Research Officer, successfully participated as a member of the Situational Awareness (Yellow) Team in the recent “Crossed Swords 2018” cyber defense training exercise, held in Latvia and organized by the NATO Cooperative Cyber Defense Centre of Excellence (CCDCOE) in cooperation with CERT.LV.
The sister event to the larger NATO CCDCOE “Locked Shields” cyber defense exercise (the largest and most complex live-fire cyber defense exercise in the world), “Crossed Swords” is focused on practicing skills required to carry out responsive tactical cyber operations. “The exercise aims to practice skills required to fill the role of the Red Team at cyber defence exercises and to offer the most cutting-edge and challenging training experience for national cyber defenders. It is evident that in order to defend ourselves better in cyberspace, we need to know how attacks are carried out,” explained Aare Reintam, Project Manager of Technical Exercises at the NATO CCDCOE. The “Crossed Swords 2018” event included a group of more than 80 cybersecurity professionals from 15 countries.
In this year’s exercise, the Red Team was tasked with conducting a full spectrum cyber operation in a fictional scenario, while the Blue Team actively defended their assets. The Yellow Team monitored Red Team activity from different sources of information, such as network tap and host-based log files, and provided a highly valuable near real-time feedback. As part of the exercise, GREYCORTEX contributed features to “Frankenstack,” a novel stack of tools built by NATO CCDCOE, Tallinn University of Technology, CERT.LV, and industry partners.
GREYCORTEX’s experience didn’t end with the end of the training exercise. Inspired by “Crossed Swords,” GREYCORTEX renamed its Malware Lab research team to the “Red Team,” but as Petr Chmelar noted, “We will always be Yellow Team-focused.”