½üÈÕ£¬¹¥»÷ÕßÀûÓÃRagnar LockerÀÕË÷Èí¼þÏ®»÷ÁËÆÏÌÑÑÀ¿ç¹úÄÜÔ´¹«Ë¾EDP£¨Energias de Portugal£©£¬¶øÇÒË÷Òª1580µÄ±ÈÌرÒÊê½ð£¨ÕÛºÏÔ¼1090ÍòÃÀÔª/990ÍòÅ·Ôª£©¡£¶Ô´Ë£¬EDPÉÐδ×÷³ö»Ø¸´¡£
EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄÜÉú²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÓòÓµÓÐÒµÎñ£¬ÓµÓÐÁè¼Ý11500ÃûÔ±¹¤£¬²¢ÎªÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£
¹¥»÷ÕßÑïÑÔ¡°ËºÆ±¡±10TBµÄÇÔÃÜÊý¾Ý
ÔÚÕâ´Î¹¥»÷¹ý³ÌÖУ¬Ragnar LockerÀÕË÷Èí¼þµÄÄ»ºóºÚÊÖÉù³ÆÒѾ»ñÈ¡Á˹«Ë¾10TBµÄÃô¸ÐÊý¾ÝÎļþ£¬Èç¹ûEDP²»Ö§¸¶Êê½ð£¬ÄÇôËûÃǽ«ÔÚ¹ûȻй¶ÕâЩÊý¾Ý¡£
¾ÝRagnarµÄйÃÜÍøվ˵µ½£º
ÎÒÃÇÒѾÏÂÔØÁËEDP×éÖ¯·þÎñÆ÷10TBµÄ˽ÃÜÐÅÏ¢¡£×÷Ϊ֤¾Ý£¬ÎÒÃÇÌṩÁËһЩÄã·½ÆóÒµÍøÂçÖÐÏÂÔصÄÎļþ½ØÆÁ£¡ÏÖÔÚÕâ¸öÌû×ÓÖ»ÊÇÁÙʱ£¬µ«ÊÇÈç¹ûÄãÃDz»Ö§¸¶Êê½ð£¬ÕâÒ²»á³ÉΪÓÀ¾ÃÐÔµÄÒ³Ã棡ÎÒÃǽ«ÔÚ¸÷´óÖªÃû±¨É硢ýÌå¡¢²©¿Í¹ûÈ»ÕâЩÎļþ×ÊÁÏ£¬¶øÇÒ¼û¸æÄãÃǵĿͻ§¡¢ºÏ×÷»ï°éºÍ¾ºÕù¶ÔÊÖ£¬ËùÒÔÕâЩÎļþÊÇ»úÃÜ»¹ÊǹûÈ»ÍêÈ«È¡¾öÓÚÄãÃÇ£¡
Ragnar ÍøÕ¾µÄÍþв֪ͨ
ÆäÖУ¬¹¥»÷Õßй¶Á˲¿ÃÅÎļþÀ´¾¯¸æEDP£¬°üÂÞÒ»¸öedpradmin2.kdbµÄÎļþ£¬ÕâÊÇKeePassÃÜÂë¹ÜÀíÊý¾Ý¿â¡£µ±µã¿ªÕâ¸öй¶ÎļþµÄÁ´½Ó£¬»áÖ±½Óµ¼³öEDPÔ±¹¤µÄµÇ¼Ãû¡¢ÃÜÂë¡¢ÕÊ»§¡¢URLSÒÔ¼°×¢ÊÍ¡£
MalwareHunterÍŶӷ¢ÏÖÁËÕâ´ÎÀÕË÷Èí¼þµÄ¹¥»÷Ñù±¾£¬²¢ÕÒµ½Êê½ð¼Ç¼ºÍTor¸¶¿îÒ³Ã棬¹¥»÷ÕßÔÚÆäÖÐÏêϸÃèÊöÁ˽âÃܹý³ÌºÍÀÕË÷½ð¶î¡£
ƾ¾ÝEDP¼ÓÃÜϵͳÉϵÄÊê½ð¼Ç¼£¬¹¥»÷ÕßÄܹ»ÇÔÈ¡ÓйØÕ˵¥¡¢ºÏͬ¡¢½»Òס¢¿Í»§ºÍºÏ×÷»ï°éµÄ»úÃÜÐÅÏ¢¡£
Êê½ð˵Ã÷˵£º¡°²¢È·±££¬Èç¹ûÄú²»¸¶¿î£¬ËùÓÐÎļþºÍÎĵµ½«±»Ðû²¼¸øËùÓÐÈ˼ì²ì£¬¶øÇÒÎÒÃǽ«Í¨¹ýÖ±½ÓÁ´½Ó֪ͨËùÓпͻ§ºÍºÏ×÷»ï°éÓйØÕâ´Îй©µÄÐÅÏ¢¡£¡±
ͼƬÀ´×ÔÍÆÌØ
ËùÒÔÈç¹ûÄãÃDz»ÏëÃûÉùÊÜËð£¬×îºÃ¾¡¿ì°´ÒªÇóÖ§¸¶Êê½ð¡£
¹¥»÷ÕßÔÚ¼´Ê±´°¿ÚÖм¥Ð¦EDP
Ragnar LockerÀÕË÷Èí¼þ±³ºóµÄÀûÓÃÕß»¹ÔÚͨ¹ý¡°¿Í·þ´°¿Ú¡±ºÍEDP½øÐÐʵʱÁÄÌ죬ҪÇóËûÃǼì²é¹«Ë¾ÍøÕ¾¹ØÓÚÕâ¸öйÃÜÍþвµÄ֪ͨ£¬²¢Ñ¯Îʹ«Ë¾ÊÇ·ñÔ¸Òâ¿´µ½Æóҵ˽ÈËÐÅÏ¢·ºÆðÔÚ¿ìѶ¡¢¼¼Êõ²©¿ÍºÍ¹ÉÊÐÍøÕ¾ÉÏ¡£
ËûÃÇ»¹Ôö²¹µÀ¡°Ê±²»´ýÈË¡±£¬»¹¾¯¸æEDP²»ÒªÊµÑéʹÓóýRagnar LockerÒÔÍâµÄ½âÃÜÆ÷À´ÆƽâÎļþ£¬·ñÔò½«ÓÐÊý¾ÝÆÆ»µºÍ¶ªÊ§µÄ·çÏÕ¡£
¹¥»÷Õß»¹¼¥·íEDPÈç¹ûÔÚϵͳ¼ÓÃÜÁ½ÌìºóÁªÏµËûÃÇ£¬Äܹ»ÏíÊÜÓŻݼ۸ñ¡£µ«ÊÇ£¬ËûÃÇÒ²ÒªµÈ×Å£¬ÀÕË÷Èí¼þµÄ¼´Ê±ÁÄÌìÒ²²»»áÈ«ÌìºòÔÚÏß¡£
½ØÖ¹·¢ÎÄ£¬EDP¹«Ë¾¶Ô´ËÉÐδÖÃÆÀ¡£
Ragnar Locker¼ÓÃܹý³Ì
Ragnar LockerÀÕË÷Èí¼þÔÚ2019Äê12Ôµ×Ê״α»·¢ÏÖ£¬×¨ÃÅÕë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ³£ÓÃÈí¼þ£¬À´ÈëÇÖÍøÂçÇÔÈ¡Êý¾ÝÎļþ¡£
MSPÄþ¾²¹«Ë¾Huntress LabsµÄÊ×ϯִÐйÙKyle HanslovanÔÚ2ÔÂ˵µ½£¬ËûµÄ¹«Ë¾·¢ÏÖRagnar Lockerͨ¹ýMSPÈí¼þConnectWise½øÐÐÁ˲¿Êð¡£
¾¹ýÕì²ìºÍ²¿ÊðÇ°½×¶Î£¬¹¥»÷Õß¹¹½¨Õë¶ÔÐÔÇ¿µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþΪ¼ÓÃÜÎļþÌí¼ÓÁËÌض¨µÄÀ©Õ¹Ãû£¬¾ßÓÐǶÈëʽRSA-2048ÃÜÔ¿£¬²¢¼ÓÈë×Ô½ç˵ÀÕË÷Ʊ¾Ý¡£
Ragnar Locker¾ßÓжà´ÎµÄÊê½ð¼Ç¼£¬Êê½ð¼Ç¼°üÂÞÊܺ¦ÕߵĹ«Ë¾Ãû³Æ¡¢TorÕ¾µãµÄÁ´½ÓÒÔ¼°°üÂÞÊܺ¦ÕßÒÑÐû²¼Êý¾ÝµÄÊý¾Ýй©վµã£¬Êê½ð·¶Î§´Ó20ÍòÃÀÔªµ½Ô¼Äª60ÍòÃÀÔª²»µÈ¡£
SentinelLabs¶ÔÕâÖÖÀÕË÷²¡¶¾½øÐзÖÎö£¬ÂôÁ¦ÈËVitali KremezÌá¼°£¬Ragnar LockerÊ×´ÎÆô¶¯Ê±½«¼ì²éÅäÖõÄWindowsÓïÑÔÊ×Ñ¡ÏÈç¹û½«ËüÃÇÉèÖÃΪǰËÕÁª¹ú¼ÒÖ®Ò»£¬Ôò»áÖÕÖ¹¸Ã¹ý³Ì¶øÇÒ²î³Ø¼ÆËã»ú½øÐмÓÃÜ¡£Èç¹ûÊܺ¦Õßͨ¹ýÁ˴˼ì²é£¬ÔòÀÕË÷Èí¼þ½«Í£Ö¹ÉÏÒ»½ÚÖÐËùÊöµÄÖÖÖÖWindows·þÎñ¡£
ÏÖÔÚÒѾ׼±¸ºÃ¶Ô¼ÆËã»ú½øÐмÓÃÜ£¬Ragnar Locker½«¿ªÊ¼¶Ô¼ÆËã»úÉϵÄÎļþ½øÐмÓÃÜ¡£
¼ÓÃÜÎļþʱ£¬Ëü½«Ìø¹ýÒÔÏÂÎļþ¼Ð¡¢ÎļþÃûºÍÀ©Õ¹ÃûÖеÄÎļþ£º
kernel32.dll
Windows
Windows.old
Tor browser
Internet Explorer
Opera
Opera Software
Mozilla
Mozilla Firefox
$Recycle.Bin
ProgramData
All Users
autorun.inf
boot.ini
bootfont.bin
bootsect.bak
bootmgr
bootmgr.efi
bootmgfw.efi
desktop.ini
iconcache.db
ntldr
ntuser.dat
ntuser.dat.log
ntuser.ini
thumbs.db
.sys
.dll
.lnk
.msi
.drv
.exe
¶ÔÓÚÿ¸ö¼ÓÃÜÎļþ£¬ÎļþÃûºó¶¼ÊÐÌí¼ÓÒ»¸öÔ¤ÅäÖõÄÀ©Õ¹Ãû£¬Èç.ragnar_22015ABC ¡£ÈçÏÂËùʾ£¬¡° RAGNAR¡±Îļþ±êÖ¾Ò²½«Ìí¼Óµ½Ã¿¸ö¼ÓÃÜÎļþµÄĩβ¡£
¼ÓÃÜÎļþ±êÖ¾
×îºó£¬½«´´½¨Ò»¸öÃûΪ.RGNR_ [extension] .txtµÄÊê½ðƱ¾Ý£¬ÆäÖаüÂÞÓйØÊܺ¦ÕßÎļþ·¢ÉúÁËʲôÇé¿ö¡¢Êê½ð½ð¶î¡¢±ÈÌرÒÖ§¸¶µØÖ·¡¢Óë¹¥»÷Õß½øÐÐͨÐŵÄTOXÁÄÌìIDµÈÐÅÏ¢£¬Èç¹ûTOXÔòÓñ¸·ÝµÄµç×ÓÓʼþµØÖ·¡£
Ragnar LockerÀÕË÷Ʊ¾Ý
Ä¿Ç°Õë¶ÔRagnar LockerÀÕË÷Èí¼þ¼ÓÃÜÎļþÉÐÎÞ·¨½âÃÜ£¬ºóÐø±¾ÎĽ«Á¬Ðø¸ú½ø¡£
£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©
Copyright ? ¶«Éƽ̨ °æȨËùÓÐ ¾©ICP±¸05032414ºÅ ¾©¹«Íø°²±¸11010802024551ºÅ