近日,北京一客户服务器数据被加密,鸿萌工程师查看服务器发现,服务器内所有有效数据被添加.deadfiles后缀,入侵者留下如下信息:
YOUR PERSONAL ID:
(省略)
/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\
All your important files have been encrypted!
Your files are safe! Only modified. (RSA+AES)
ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE
WILL PERMANENTLY CORRUPT IT.
DO NOT MODIFY ENCRYPTED FILES.
DO NOT RENAME ENCRYPTED FILES.
No software available on internet can help you. We are the only ones able to
solve your problem.
We gathered highly confidential/personal data. These data are currently stored on
a private server. This server will be immediately destroyed after your payment.
If you decide to not pay, we will release your data to public or re-seller.
So you can expect your data to be publicly available in the near future..
We only seek money and our goal is not to damage your reputation or prevent
your business from running.
You will can send us 2-3 non-important files and we will decrypt it for free
to prove we are able to give your files back.
Contact us for price and get decryption software.
{}
* Note that this server is available via Tor browser only
Follow the instructions to open the link:
1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.
2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.
3. Now you have Tor browser. In the Tor Browser open "{}".
4. Start a chat and follow the further instructions.
If you can?t use the above link, use the email:
dec_restore@protonmail.com
decrestore@cock.li
Make contact as soon as possible. Your private key (decryption key)is only stored temporarily.
IF YOU DON'T CONTACT US WITHIN 72 HOURS, PRICE WILL BE HIGHER.
这种后缀的勒索病毒,鸿萌工程师是首次发现,分析了一下加密文件的底层代码,加密程度较高。恢复难度较大。
勒索病毒的肆虐,一方面说明境外的入侵者疯狂破坏国内的大、中、小型企事业单位的核心服务器,另一方面,也反映出很多单位对于网络安全的重视程度不足,导致黑客轻松得手。为此,鸿萌再一次提醒客户朋友,一定要做好数据备份工作,确保核心数据安全。
假如中招了,也不要慌张,尽快拔掉中毒的服务器网线,联系鸿萌的数据安全工程师获得帮助。
领取专属 10元无门槛券
私享最新 技术干货