吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 1965|回复: 3
收起左侧

中了.[myers@airmail.cc].mkp勒索病毒

[复制链接]
Love彡丶小笨笨 发表于 2023-12-24 22:11
使用论坛附件上传样本压缩包时必须使用压缩密码保护,压缩密码:52pojie,否则会导致论坛被杀毒软件等误报,论坛有权随时删除相关附件和帖子!
病毒分析分区附件样本、网址谨慎下载点击,可能对计算机产生破坏,仅供安全人员在法律允许范围内研究,禁止非法用途!
禁止求非法渗透测试、非法网络攻击、获取隐私等违法内容,即使对方是非法内容,也应向警方求助!
50吾爱币
本帖最后由 Love彡丶小笨笨 于 2023-12-24 22:14 编辑

中了.[myers@airmail.cc].mkp勒索病毒,用群晖挂载着虚拟机下东西,虚拟机是开了公网远程,密码和密码提示是一样的,但是端口改了不是默认的,虚拟机把群晖里的文件映射到了进去了,前几天还远程连接虚拟机显示密码错误还纳闷咋回事呢,没往这想,过了几天用pe重置了密码进去才发现中勒索病毒了,群晖有个共享文件夹加密,结果今天打开发现了群晖加密的文件也全都被加密了,但是小姐姐也是群晖加密的但是没被感染,这么多年所有重要的照片视频文件啥的全都毁于一旦。看了下文件修改记录2g多t的文件加密前后加密花了4天时间,黑客改密码估计就是为了延缓发现的时间,让文件能彻底加密,要是当时就关机损失没这么严重了。之前太信任群晖了,想着群晖的风险最大不过硬盘坏了吗,组raid就能解决,没考虑到有这个风险,现在感觉对咱这种小白来说网盘更安全,群晖能被攻破的地方太多了,重要文件得异地备份。
有几个问题
1.黑客是怎么发现我的域名并且能试出来端口的,这个过程是人为的还是自动的
2.群晖加密共享文件夹明明加密了怎么被篡改的
3.这还有办法解吗,360显示暂无法解密

这是被加密的文件
链接:https://pan.baidu.com/s/174hfrEK6zlr4-2WoNA1y2g
提取码:2jx0

黑客留言

+README-WARNING+.txt
::: Greetings :::

Little FAQ:

.1.
Q: Whats Happen?
A: Your files have been encrypted. The file structure was not damaged, we did everything possible so that this could not happen.

.2.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay us.

.3.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will cooperate with us. Its not in our interests.
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg,xls,doc, etc... not databases!) and low sizes(max 1 mb), we will decrypt them and send back to you. That is our guarantee.

.4.
Q: How to contact with you?
A: You can write us to our mailbox: myers@airmail.cc
Or you can contact us via JABBER chat: helprecovery@gnu.gr

.5.
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use. With this program you will be able to decrypt all your encrypted files.

.6.
Q: If I don抰 want to pay bad people like you?
A: If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause only we have the private key. In practice - time is much more valuable than money.



:::BEWARE:::
DON'T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions - please make a backup for all encrypted files!
Any changes in encrypted files may entail damage of the private key and, as result, the loss all data.

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

lws0318 发表于 2023-12-25 10:07
这个要恢复有点难了
as2486568 发表于 2023-12-25 11:17
辞年小妖 发表于 2023-12-25 12:12
个人推测,因为虚拟机开了公网,公网时时刻刻有人在扫描在线设备(软件自动扫描IP 端口号)。弱密码,虚拟机被入侵,因为共享文件夹账号密码,群晖被入侵了,加密。群晖有开自动备份,可以尝试恢复。
可以尝试硬盘数据恢复,不过很贵。付勒索金额,50%几率打动黑客。
特别重要资料请冷备份,网盘资料需要加密备份。
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-11-24 09:23

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表