Love彡丶小笨笨 发表于 2023-12-24 22:11

中了.[myers@airmail.cc].mkp勒索病毒

本帖最后由 Love彡丶小笨笨 于 2023-12-24 22:14 编辑

中了..mkp勒索病毒,用群晖挂载着虚拟机下东西,虚拟机是开了公网远程,密码和密码提示是一样的,但是端口改了不是默认的,虚拟机把群晖里的文件映射到了进去了,前几天还远程连接虚拟机显示密码错误还纳闷咋回事呢,没往这想,过了几天用pe重置了密码进去才发现中勒索病毒了,群晖有个共享文件夹加密,结果今天打开发现了群晖加密的文件也全都被加密了,但是小姐姐也是群晖加密的但是没被感染,这么多年所有重要的照片视频文件啥的全都毁于一旦。看了下文件修改记录2g多t的文件加密前后加密花了4天时间,黑客改密码估计就是为了延缓发现的时间,让文件能彻底加密,要是当时就关机损失没这么严重了。之前太信任群晖了,想着群晖的风险最大不过硬盘坏了吗,组raid就能解决,没考虑到有这个风险,现在感觉对咱这种小白来说网盘更安全,群晖能被攻破的地方太多了,重要文件得异地备份。
有几个问题
1.黑客是怎么发现我的域名并且能试出来端口的,这个过程是人为的还是自动的
2.群晖加密共享文件夹明明加密了怎么被篡改的
3.这还有办法解吗,360显示暂无法解密

这是被加密的文件
链接:https://pan.baidu.com/s/174hfrEK6zlr4-2WoNA1y2g
提取码:2jx0

黑客留言

+README-WARNING+.txt
::: Greetings :::

Little FAQ:

.1.
Q: Whats Happen?
A: Your files have been encrypted. The file structure was not damaged, we did everything possible so that this could not happen.

.2.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay us.

.3.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will cooperate with us. Its not in our interests.
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg,xls,doc, etc... not databases!) and low sizes(max 1 mb), we will decrypt them and send back to you. That is our guarantee.

.4.
Q: How to contact with you?
A: You can write us to our mailbox: myers@airmail.cc
Or you can contact us via JABBER chat: helprecovery@gnu.gr

.5.
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use. With this program you will be able to decrypt all your encrypted files.

.6.
Q: If I don抰 want to pay bad people like you?
A: If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause only we have the private key. In practice - time is much more valuable than money.



:::BEWARE:::
DON'T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions - please make a backup for all encrypted files!
Any changes in encrypted files may entail damage of the private key and, as result, the loss all data.

lws0318 发表于 2023-12-25 10:07

这个要恢复有点难了

as2486568 发表于 2023-12-25 11:17

病毒吧问问他们的吧主

辞年小妖 发表于 2023-12-25 12:12

个人推测,因为虚拟机开了公网,公网时时刻刻有人在扫描在线设备(软件自动扫描IP 端口号)。弱密码,虚拟机被入侵,因为共享文件夹账号密码,群晖被入侵了,加密。群晖有开自动备份,可以尝试恢复。
可以尝试硬盘数据恢复,不过很贵。付勒索金额,50%几率打动黑客。
特别重要资料请冷备份,网盘资料需要加密备份。
页: [1]
查看完整版本: 中了.[myers@airmail.cc].mkp勒索病毒