¶¶È¦Îª¶Ä¶øÉú

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍøÄþ¾²×¨Ìâ > Äþ¾²×ÊѶ

Å·ÖÞÄÜÔ´¾ÞÍ·ÔâÀÕË÷£¬ÓÃ1000ÍòÅ·Ôª»»10TBÊý¾Ý£¿

×÷ÕߣºSandra1432 2020-04-15

½üÈÕ£¬¹¥»÷ÕßÀûÓÃRagnar LockerÀÕË÷Èí¼þÏ®»÷ÁËÆÏÌÑÑÀ¿ç¹úÄÜÔ´¹«Ë¾EDP£¨Energias de Portugal£©£¬¶øÇÒË÷Òª1580µÄ±ÈÌØ±ÒÊê½ð£¨ÕÛºÏÔ¼1090ÍòÃÀÔª/990ÍòÅ·Ôª£©¡£¶Ô´Ë£¬EDPÉÐδ×÷³ö»Ø¸´¡£

EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄÜÉú²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÓòÓµÓÐÒµÎñ£¬ÓµÓÐÁè¼Ý11500ÃûÔ±¹¤£¬²¢ÎªÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£

1.jpg

¹¥»÷ÕßÑïÑÔ¡°ËºÆ±¡±10TBµÄÇÔÃÜÊý¾Ý

ÔÚÕâ´Î¹¥»÷¹ý³ÌÖУ¬Ragnar LockerÀÕË÷Èí¼þµÄÄ»ºóºÚÊÖÉù³ÆÒѾ­»ñÈ¡Á˹«Ë¾10TBµÄÃô¸ÐÊý¾ÝÎļþ£¬Èç¹ûEDP²»Ö§¸¶Êê½ð£¬ÄÇôËûÃǽ«ÔÚ¹ûȻй¶ÕâЩÊý¾Ý¡£

¾ÝRagnarµÄйÃÜÍøÕ¾Ëµµ½£º

ÎÒÃÇÒѾ­ÏÂÔØÁËEDP×éÖ¯·þÎñÆ÷10TBµÄ˽ÃÜÐÅÏ¢¡£×÷Ϊ֤¾Ý£¬ÎÒÃÇÌṩÁËһЩÄã·½ÆóÒµÍøÂçÖÐÏÂÔØµÄÎļþ½ØÆÁ£¡ÏÖÔÚÕâ¸öÌû×ÓÖ»ÊÇÁÙʱ£¬µ«ÊÇÈç¹ûÄãÃDz»Ö§¸¶Êê½ð£¬ÕâÒ²»á³ÉΪÓÀ¾ÃÐÔµÄÒ³Ãæ£¡ÎÒÃǽ«ÔÚ¸÷´óÖªÃû±¨É硢ýÌå¡¢²©¿Í¹ûÈ»ÕâЩÎļþ×ÊÁÏ£¬¶øÇÒ¼û¸æÄãÃǵĿͻ§¡¢ºÏ×÷»ï°éºÍ¾ºÕù¶ÔÊÖ£¬ËùÒÔÕâЩÎļþÊÇ»úÃÜ»¹ÊǹûÈ»Íêȫȡ¾öÓÚÄãÃÇ£¡

2.jpg

Ragnar ÍøÕ¾µÄÍþв֪ͨ

ÆäÖУ¬¹¥»÷Õßй¶Á˲¿ÃÅÎļþÀ´¾¯¸æEDP£¬°üÂÞÒ»¸öedpradmin2.kdbµÄÎļþ£¬ÕâÊÇKeePassÃÜÂë¹ÜÀíÊý¾Ý¿â¡£µ±µã¿ªÕâ¸öй¶ÎļþµÄÁ´½Ó£¬»áÖ±½Óµ¼³öEDPÔ±¹¤µÄµÇ¼Ãû¡¢ÃÜÂë¡¢ÕÊ»§¡¢URLSÒÔ¼°×¢ÊÍ¡£

3.png

MalwareHunterÍŶӷ¢ÏÖÁËÕâ´ÎÀÕË÷Èí¼þµÄ¹¥»÷Ñù±¾£¬²¢ÕÒµ½Êê½ð¼Ç¼ºÍTor¸¶¿îÒ³Ãæ£¬¹¥»÷ÕßÔÚÆäÖÐÏêϸÃèÊöÁ˽âÃܹý³ÌºÍÀÕË÷½ð¶î¡£

ƾ¾ÝEDP¼ÓÃÜϵͳÉϵÄÊê½ð¼Ç¼£¬¹¥»÷ÕßÄܹ»ÇÔÈ¡ÓйØÕ˵¥¡¢ºÏͬ¡¢½»Òס¢¿Í»§ºÍºÏ×÷»ï°éµÄ»úÃÜÐÅÏ¢¡£

Êê½ð˵Ã÷˵£º¡°²¢È·±££¬Èç¹ûÄú²»¸¶¿î£¬ËùÓÐÎļþºÍÎĵµ½«±»Ðû²¼¸øËùÓÐÈ˼ì²ì£¬¶øÇÒÎÒÃǽ«Í¨¹ýÖ±½ÓÁ´½Ó֪ͨËùÓпͻ§ºÍºÏ×÷»ï°éÓйØÕâ´Îй©µÄÐÅÏ¢¡£¡±

4.jpg

ͼƬÀ´×ÔÍÆÌØ

ËùÒÔÈç¹ûÄãÃDz»ÏëÃûÉùÊÜËð£¬×îºÃ¾¡¿ì°´ÒªÇóÖ§¸¶Êê½ð¡£

¹¥»÷ÕßÔÚ¼´Ê±´°¿ÚÖм¥Ð¦EDP

Ragnar LockerÀÕË÷Èí¼þ±³ºóµÄÀûÓÃÕß»¹ÔÚͨ¹ý¡°¿Í·þ´°¿Ú¡±ºÍEDP½øÐÐʵʱÁÄÌ죬ҪÇóËûÃǼì²é¹«Ë¾ÍøÕ¾¹ØÓÚÕâ¸öйÃÜÍþвµÄ֪ͨ£¬²¢Ñ¯Îʹ«Ë¾ÊÇ·ñÔ¸Òâ¿´µ½Æóҵ˽ÈËÐÅÏ¢·ºÆðÔÚ¿ìѶ¡¢¼¼Êõ²©¿ÍºÍ¹ÉÊÐÍøÕ¾ÉÏ¡£

ËûÃÇ»¹Ôö²¹µÀ¡°Ê±²»´ýÈË¡±£¬»¹¾¯¸æEDP²»ÒªÊµÑéʹÓóýRagnar LockerÒÔÍâµÄ½âÃÜÆ÷À´ÆÆ½âÎļþ£¬·ñÔò½«ÓÐÊý¾ÝÆÆ»µºÍ¶ªÊ§µÄ·çÏÕ¡£

¹¥»÷Õß»¹¼¥·íEDPÈç¹ûÔÚϵͳ¼ÓÃÜÁ½ÌìºóÁªÏµËûÃÇ£¬Äܹ»ÏíÊÜÓŻݼ۸ñ¡£µ«ÊÇ£¬ËûÃÇÒ²ÒªµÈ×Å£¬ÀÕË÷Èí¼þµÄ¼´Ê±ÁÄÌìÒ²²»»áÈ«ÌìºòÔÚÏß¡£

½ØÖ¹·¢ÎÄ£¬EDP¹«Ë¾¶Ô´ËÉÐδÖÃÆÀ¡£

Ragnar Locker¼ÓÃܹý³Ì

Ragnar LockerÀÕË÷Èí¼þÔÚ2019Äê12Ôµ×Ê״α»·¢ÏÖ£¬×¨ÃÅÕë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ³£ÓÃÈí¼þ£¬À´ÈëÇÖÍøÂçÇÔÈ¡Êý¾ÝÎļþ¡£

MSPÄþ¾²¹«Ë¾Huntress LabsµÄÊ×ϯִÐйÙKyle HanslovanÔÚ2ÔÂ˵µ½£¬ËûµÄ¹«Ë¾·¢ÏÖRagnar Lockerͨ¹ýMSPÈí¼þConnectWise½øÐÐÁ˲¿Êð¡£

5.png

¾­¹ýÕì²ìºÍ²¿Êðǰ½×¶Î£¬¹¥»÷Õß¹¹½¨Õë¶ÔÐÔÇ¿µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþΪ¼ÓÃÜÎļþÌí¼ÓÁËÌØ¶¨µÄÀ©Õ¹Ãû£¬¾ßÓÐǶÈëʽRSA-2048ÃÜÔ¿£¬²¢¼ÓÈë×Ô½ç˵ÀÕË÷Ʊ¾Ý¡£

Ragnar Locker¾ßÓжà´ÎµÄÊê½ð¼Ç¼£¬Êê½ð¼Ç¼°üÂÞÊܺ¦ÕߵĹ«Ë¾Ãû³Æ¡¢TorÕ¾µãµÄÁ´½ÓÒÔ¼°°üÂÞÊܺ¦ÕßÒÑÐû²¼Êý¾ÝµÄÊý¾Ýй©վµã£¬Êê½ð·¶Î§´Ó20ÍòÃÀÔªµ½Ô¼Äª60ÍòÃÀÔª²»µÈ¡£

SentinelLabs¶ÔÕâÖÖÀÕË÷²¡¶¾½øÐзÖÎö£¬ÂôÁ¦ÈËVitali KremezÌá¼°£¬Ragnar LockerÊ×´ÎÆô¶¯Ê±½«¼ì²éÅäÖõÄWindowsÓïÑÔÊ×Ñ¡ÏÈç¹û½«ËüÃÇÉèÖÃΪǰËÕÁª¹ú¼ÒÖ®Ò»£¬Ôò»áÖÕÖ¹¸Ã¹ý³Ì¶øÇÒ²î³Ø¼ÆËã»ú½øÐмÓÃÜ¡£Èç¹ûÊܺ¦Õßͨ¹ýÁ˴˼ì²é£¬ÔòÀÕË÷Èí¼þ½«Í£Ö¹ÉÏÒ»½ÚÖÐËùÊöµÄÖÖÖÖWindows·þÎñ¡£

ÏÖÔÚÒѾ­×¼±¸ºÃ¶Ô¼ÆËã»ú½øÐмÓÃÜ£¬Ragnar Locker½«¿ªÊ¼¶Ô¼ÆËã»úÉϵÄÎļþ½øÐмÓÃÜ¡£

¼ÓÃÜÎļþʱ£¬Ëü½«Ìø¹ýÒÔÏÂÎļþ¼Ð¡¢ÎļþÃûºÍÀ©Õ¹ÃûÖеÄÎļþ£º

kernel32.dll

Windows

Windows.old

Tor browser

Internet Explorer

Google

Opera

Opera Software

Mozilla

Mozilla Firefox

$Recycle.Bin

ProgramData

All Users

autorun.inf

boot.ini

bootfont.bin

bootsect.bak

bootmgr

bootmgr.efi

bootmgfw.efi

desktop.ini

iconcache.db

ntldr

ntuser.dat

ntuser.dat.log

ntuser.ini

thumbs.db

.sys

.dll

.lnk

.msi

.drv

.exe

¶ÔÓÚÿ¸ö¼ÓÃÜÎļþ£¬ÎļþÃûºó¶¼ÊÐÌí¼ÓÒ»¸öÔ¤ÅäÖõÄÀ©Õ¹Ãû£¬Èç.ragnar_22015ABC ¡£ÈçÏÂËùʾ£¬¡° RAGNAR¡±Îļþ±êÖ¾Ò²½«Ìí¼Óµ½Ã¿¸ö¼ÓÃÜÎļþµÄĩβ¡£

6.jpg

¼ÓÃÜÎļþ±êÖ¾

×îºó£¬½«´´½¨Ò»¸öÃûΪ.RGNR_ [extension] .txtµÄÊê½ðƱ¾Ý£¬ÆäÖаüÂÞÓйØÊܺ¦ÕßÎļþ·¢ÉúÁËʲôÇé¿ö¡¢Êê½ð½ð¶î¡¢±ÈÌØ±ÒÖ§¸¶µØÖ·¡¢Óë¹¥»÷Õß½øÐÐͨÐŵÄTOXÁÄÌìIDµÈÐÅÏ¢£¬Èç¹ûTOXÔòÓñ¸·ÝµÄµç×ÓÓʼþµØÖ·¡£

7.png

Ragnar LockerÀÕË÷Ʊ¾Ý

ĿǰÕë¶ÔRagnar LockerÀÕË÷Èí¼þ¼ÓÃÜÎļþÉÐÎÞ·¨½âÃÜ£¬ºóÐø±¾ÎĽ«Á¬Ðø¸ú½ø¡£


£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©

ÉÏһƪ ÏÂһƪ

7*24Сʱ·þÎñÈÈÏß

400-624-3900


ÍøÕ¾µØÍ¼