GA»Æ½ð¼×

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍø°²È«×¨Ìâ > °²È«×ÊѶ

Å·ÖÞÄÜÔ´¾ÞÍ·ÔâÀÕË÷£¬ÓÃ1000ÍòÅ·Ôª»»10TBÊý¾Ý £¿

×÷ÕߣºSandra1432 2020-04-15

½üÈÕ£¬¹¥»÷ÕßÀûÓÃRagnar LockerÀÕË÷Èí¼þÏ®»÷ÁËÆÏÌÑÑÀ¿ç¹úÄÜÔ´¹«Ë¾EDP£¨Energias de Portugal£©£¬²¢ÇÒË÷Òª1580µÄ±ÈÌØ±ÒÊê½ð£¨ÕÛºÏÔ¼1090ÍòÃÀÔª/990ÍòÅ·Ôª£©¡£¶Ô´Ë£¬EDPÉÐδ×÷³ö»Ø¸´¡£

EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄܳö²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¶È/µØÓòÕ¼ÓÐÒµÎñ£¬Õ¼Óг¬¹ý11500ÃûÔ±¹¤£¬²¢Îª³¬¹ý1100Íò¿Í»§ÌṩÄÜÔ´¡£

1.jpg

¹¥»÷ÕßÑïÑÔ¡°ËºÆ±¡±10TBµÄÇÔÃÜÊý¾Ý

ÔÚÕâ´Î¹¥»÷¹ý³ÌÖУ¬Ragnar LockerÀÕË÷Èí¼þµÄÄ»ºóºÚÊÖÐû³ÆÒѾ­»ñÈ¡Á˹«Ë¾10TBµÄÃô¸ÐÊý¾ÝÎļþ£¬ÈôÊÇEDP²»Ö§¸¶Êê½ð£¬ÄÇôËûÃǽ«ÔÚ¹«¿ªÐ¹Â¶ÕâЩÊý¾Ý¡£

¾ÝRagnarµÄйÃÜÍøÕ¾Ëµµ½£º

ÎÒÃÇÒѾ­ÏÂÔØÁËEDP×éÖ¯·þÎñÆ÷10TBµÄ˽ÃÜÐÅÏ¢¡£×÷Ϊ֤¾Ý£¬ÎÒÃÇÌṩÁËһЩÄã·½ÆóÒµÍøÂçÖÐÏÂÔØµÄÎļþ½ØÆÁ£¡´Ë¿ÌÕâ¸öÌû×ÓÖ»ÊÇһʱ£¬µ«ÊÇÈôÊÇÄãÃDz»Ö§¸¶Êê½ð£¬ÕâÒ²»á³ÉΪÓÀÔ¶ÐÔµÄÒ³Ãæ£¡ÎÒÃǽ«ÔÚ¸÷´ó³ÛÃû±¨É硢ýÌå¡¢²©¿Í¹«¿ªÕâЩÎļþ×ÊÁÏ£¬²¢ÇÒ·î¸æÄãÃǵĿͻ§¡¢ºÏ×÷ͬ°éºÍ¾ºÕùµÐÊÖ£¬ËùÒÔÕâЩÎļþÊÇ»úÃÜ»¹Êǹ«¿ªÆëȫȡ¾öÓÚÄãÃÇ£¡

2.jpg

Ragnar ÍøÕ¾µÄÍþв֪ͨ

ÆäÖУ¬¹¥»÷Õßй¶Á˲¿ÃÅÎļþÀ´ÖÒ¸æEDP£¬Ô̺¬Ò»¸öedpradmin2.kdbµÄÎļþ£¬ÕâÊÇKeePassÃÜÂëÖÎÀíÊý¾Ý¿â¡£µ±µã¿ªÕâ¸öй¶ÎļþµÄÁ´½Ó£¬»áÖ±½Óµ¼³öEDPÔ±¹¤µÄµÇ¼Ãû¡¢ÃÜÂë¡¢ÕÊ»§¡¢URLSÒÔ¼°×¢½â¡£

3.png

MalwareHunterÍŶӷ¢ÏÖÁËÕâ´ÎÀÕË÷Èí¼þµÄ¹¥»÷Ñù±¾£¬²¢ÕÒµ½Êê½ð¼Í¼ºÍTor¸¶¿îÒ³Ãæ£¬¹¥»÷ÕßÔÚÆäÖоßÌåÃèÊöÏàʼûܹý³ÌºÍÀÕË÷½ð¶î¡£

ƾ¾ÝEDP¼ÓÃÜϵͳÉϵÄÊê½ð¼Í¼£¬¹¥»÷Õß¿ÉÄÜÇÔÈ¡ÓйØÕ˵¥¡¢ºÏͬ¡¢ÂòÂô¡¢¿Í»§ºÍºÏ×÷ͬ°éµÄ»úÃÜÐÅÏ¢¡£

Êê½ð×¢Ã÷˵£º¡°²¢È·±££¬ÈôÊÇÄú²»¸¶¿î£¬ËùÓÐÎļþºÍÎĵµ½«±»°ä²¼¸øËùÓÐÈ˲鿴£¬²¢ÇÒÎÒÃǽ«Í¨¹ýÖ±½ÓÁ´½Ó֪ͨËùÓпͻ§ºÍºÏ×÷ͬ°éÓйØÕâ´Îй©µÄÐÅÏ¢¡£¡±

4.jpg

ͼƬÀ´×ÔÍÆÌØ

ËùÒÔÈôÊÇÄãÃDz»ÏëÃûÉùÊÜËð£¬×îºÃ¾¡¿ì°´ÒªÇóÖ§¸¶Êê½ð¡£

¹¥»÷ÕßÔÚ¼´Ê±´°¿ÚÖг°·íEDP

Ragnar LockerÀÕË÷Èí¼þ±³ºóµÄ°Ñ³ÖÕß»¹ÔÚͨ¹ý¡°¿Í·þ´°¿Ú¡±ºÍEDP½øÐÐʵʱ̸Ì죬ҪÇóËûÃDz鳭¹«Ë¾ÍøÕ¾¹ØÓÚÕâ¸öйÃÜÍþвµÄ֪ͨ£¬²¢Ñ¯Îʹ«Ë¾ÊÇ·ñÔ¸Òâ¿´µ½ÆóÒµ¸öÈËÐÅÏ¢³Ê´Ë¿Ì¿ìѶ¡¢¼¼Êõ²©¿ÍºÍ¹ÉÊÐÍøÕ¾ÉÏ¡£

ËûÃÇ»¹²¹³ä·¡°Ê±²»´ýÈË¡±£¬»¹ÖÒ¸æEDP²»Òª³¢ÊÔʹÓóýRagnar LockerÒÔ±íµÄ½âÃÜÆ÷À´ÆÆ½âÎļþ£¬²»È»½«º±¼û¾Ý·ÛËéºÍÃÔʧµÄ·çÏÕ¡£

¹¥»÷Õß»¹µ÷Ù©EDPÈôÊÇÔÚϵͳ¼ÓÃÜÁ½ÌìºóÁªÏµËûÃÇ£¬¿ÉÄÜÏíÊÜÓŻݼÛÖµ¡£µ«ÊÇ£¬ËûÃÇÒ²ÒªµÈ×Å£¬ÀÕË÷Èí¼þµÄ¼´Ê±Ì¸ÌìÒ²²»»áÈ«ÌìºòÔÚÏß¡£

½ØÖ¹·¢ÎÄ£¬EDP¹«Ë¾¶Ô´ËÉÐδÖÃÆÀ¡£

Ragnar Locker¼ÓÃܹý³Ì

Ragnar LockerÀÕË÷Èí¼þÔÚ2019Äê12Ôµ׳õ´Î±»·¢ÏÖ£¬×¨ÃÅÕë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ³£ÓÃÈí¼þ£¬À´ÈëÇÖÍøÂçÇÔÈ¡Êý¾ÝÎļþ¡£

MSP°²È«¹«Ë¾Huntress LabsµÄÊ×ϯִÐйÙKyle HanslovanÔÚ2ÔÂ˵µ½£¬ËûµÄ¹«Ë¾·¢ÏÖRagnar Lockerͨ¹ýMSPÈí¼þConnectWise½øÐÐÁ˲¿Êð¡£

5.png

¾­¹ý¿úËźͲ¿Êðǰ½×¶Î£¬¹¥»÷Õß¹¹½¨Õë¶ÔÐÔÇ¿µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþΪ¼ÓÃÜÎļþÔö³¤ÁËÌØ¶¨µÄÀ©´óÃû£¬ÓµÓÐǶÈëʽRSA-2048ÃÜÔ¿£¬²¢²ÎÓë×Ô½ç˵ÀÕË÷µ¥¾Ý¡£

Ragnar LockerÓµÓÐÂŴεÄÊê½ð¼Í¼£¬Êê½ð¼Í¼Ô̺¬Êܺ¦ÕߵĹ«Ë¾Ãû³Æ¡¢TorÕ¾µãµÄÁ´½ÓÒÔ¼°Ô̺¬Êܺ¦ÕßÒѰ䲼Êý¾ÝµÄÊý¾Ýй©վµã£¬Êê½ðÁìÓò´Ó20ÍòÃÀÔªµ½Ô¼Äª60ÍòÃÀÔª²»µÈ¡£

SentinelLabs¶ÔÕâÖÖÀÕË÷²¡¶¾½øÐзÖÎö£¬ÕƹÜÈËVitali KremezÌá¼°£¬Ragnar Locker³õ´ÎÆô¶¯Ê±½«²é³­ÅäÖõÄWindows˵»°Ê×Ñ¡ÏÈôÊǽ«ËüÃÇÉèÖÃΪǰËÕÁª¹ú¶ÈÖ®Ò»£¬Ôò»áÖÕÖ¹¸Ã¹ý³Ì²¢ÇÒ²»ºÏÍÆËã»ú½øÐмÓÃÜ¡£ÈôÊÇÊܺ¦Õßͨ¹ýÁ˴˲鳭£¬ÔòÀÕË÷Èí¼þ½«ÖÕ³¡ÉÏÒ»½ÚÖÐËùÊöµÄ¸÷ÀàWindows·þÎñ¡£

´Ë¿ÌÒѾ­³ï±¸ºÃ¶ÔÍÆËã»ú½øÐмÓÃÜ£¬Ragnar Locker½«ÆðÍ·¶ÔÍÆËã»úÉϵÄÎļþ½øÐмÓÃÜ¡£

¼ÓÃÜÎļþʱ£¬Ëü½«Ìø¹ýÒÔÏÂÎļþ¼Ó×¢ÎļþÃûºÍÀ©´óÃûÖеÄÎļþ£º

kernel32.dll

Windows

Windows.old

Tor browser

Internet Explorer

Google

Opera

Opera Software

Mozilla

Mozilla Firefox

$Recycle.Bin

ProgramData

All Users

autorun.inf

boot.ini

bootfont.bin

bootsect.bak

bootmgr

bootmgr.efi

bootmgfw.efi

desktop.ini

iconcache.db

ntldr

ntuser.dat

ntuser.dat.log

ntuser.ini

thumbs.db

.sys

.dll

.lnk

.msi

.drv

.exe

¶ÔÓÚÿ¸ö¼ÓÃÜÎļþ£¬ÎļþÃûºó³ÇÊÐÔö³¤Ò»¸öÔ¤ÅäÖõÄÀ©´óÃû£¬Èç.ragnar_22015ABC ¡£ÈçÏÂËùʾ£¬¡° RAGNAR¡±ÎļþÏóÕ÷Ò²½«Ôö³¤µ½Ã¿¸ö¼ÓÃÜÎļþµÄĩβ¡£

6.jpg

¼ÓÃÜÎļþÏóÕ÷

×îºó£¬½«´´½¨Ò»¸öÃûΪ.RGNR_ [extension] .txtµÄÊê½ðµ¥¾Ý£¬ÆäÖÐÔ̺¬ÓйØÊܺ¦ÕßÎļþ²úÉúÁËʲôÇé¿ö¡¢Êê½ð½ð¶î¡¢±ÈÌØ±ÒÖ§¸¶µØÖ·¡¢Óë¹¥»÷Õß½øÐÐͨѶµÄTOX̸ÌìIDµÈÐÅÏ¢£¬ÈôÊÇTOXÔòÓñ¸·ÝµÄµç×ÓÓʼþµØÖ·¡£

7.png

Ragnar LockerÀÕË÷µ¥¾Ý

ĿǰÕë¶ÔRagnar LockerÀÕË÷Èí¼þ¼ÓÃÜÎļþÉÐÎÞ·¨½âÃÜ£¬ºóÐø±¾ÎĽ«³ÖÐø¸ú½ø¡£


£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©

ÉÏһƪ ÏÂһƪ

7*24Ó×ʱ·þÎñÈÈÏß

400-624-3900


¡¾ÍøÕ¾µØÍ¼¡¿