¿ËÈÕ£¬¹¥»÷ÕßʹÓÃRagnar LockerÀÕË÷Èí¼þÏ®»÷ÁËÆÏÌÑÑÀ¿ç¹úÄÜÔ´¹«Ë¾EDP£¨Energias de Portugal£©£¬²¢ÇÒË÷Òª1580µÄ±ÈÌرÒÊê½ð£¨ÕÛºÏÔ¼1090ÍòÃÀÔª/990ÍòÅ·Ôª£©¡£¶Ô´Ë£¬EDPÉÐδ×÷³ö»Ø¸´¡£
EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨×ÔÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÌìϵÚËÄ´ó·çÄÜÉú²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÇøÓµÓÐÓªÒµ£¬ÓµÓÐÁè¼Ý11500ÃûÔ±¹¤£¬²¢ÎªÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£
¹¥»÷ÕßÑïÑÔ¡°ËºÆ±¡±10TBµÄÇÔÃÜÊý¾Ý
ÔÚÕâ´Î¹¥»÷Àú³ÌÖУ¬Ragnar LockerÀÕË÷Èí¼þµÄÄ»ºóºÚÊÖÉù³ÆÒѾ»ñÈ¡Á˹«Ë¾10TBµÄÃô¸ÐÊý¾ÝÎļþ£¬ÈôÊÇEDP²»Ö§¸¶Êê½ð£¬ÄÇôËûÃǽ«ÔÚ¹ûÕæй¶ÕâЩÊý¾Ý¡£
¾ÝRagnarµÄйÃÜÍøվ˵µ½£º
ÎÒÃÇÒѾÏÂÔØÁËEDP×éÖ¯·þÎñÆ÷10TBµÄ˽ÃÜÐÅÏ¢¡£×÷Ϊ֤¾Ý£¬ÎÒÃÇÌṩÁËһЩÄã·½ÆóÒµÍøÂçÖÐÏÂÔصÄÎļþ½ØÆÁ£¡ÏÖÔÚÕâ¸öÌû×ÓÖ»ÊÇÔÝʱ£¬¿ÉÊÇÈôÊÇÄãÃDz»Ö§¸¶Êê½ð£¬ÕâÒ²»á³ÉΪÓÀÊÀÐÔµÄÒ³Ã棡ÎÒÃǽ«ÔÚ¸÷´ó×ÅÃû±¨É硢ýÌå¡¢²©¿Í¹ûÕæÕâЩÎļþ×ÊÁÏ£¬²¢ÇÒ¼û¸æÄãÃǵĿͻ§¡¢ÏàÖúͬ°éºÍ¾ºÕùµÐÊÖ£¬ÒÔÊÇÕâЩÎļþÊÇÉñÃØÕվɹûÕæÍêÈ«È¡¾öÓÚÄãÃÇ£¡
Ragnar ÍøÕ¾µÄÍþв֪ͨ
ÆäÖУ¬¹¥»÷Õßй¶Á˲¿·ÖÎļþÀ´ÖÒÑÔEDP£¬°üÀ¨Ò»¸öedpradmin2.kdbµÄÎļþ£¬ÕâÊÇKeePassÃÜÂëÖÎÀíÊý¾Ý¿â¡£µ±µã¿ªÕâ¸öй¶ÎļþµÄÁ´½Ó£¬»áÖ±½Óµ¼³öEDPÔ±¹¤µÄµÇ¼Ãû¡¢ÃÜÂë¡¢ÕÊ»§¡¢URLSÒÔ¼°×¢ÊÍ¡£
MalwareHunterÍŶӷ¢Ã÷ÁËÕâ´ÎÀÕË÷Èí¼þµÄ¹¥»÷Ñù±¾£¬²¢ÕÒµ½Êê½ð¼Í¼ºÍTor¸¶¿îÒ³Ã棬¹¥»÷ÕßÔÚÆäÖÐÏêϸÐÎòÏàʶÃÜÀú³ÌºÍÀÕË÷½ð¶î¡£
ƾ֤EDP¼ÓÃÜϵͳÉϵÄÊê½ð¼Í¼£¬¹¥»÷ÕßÄܹ»ÇÔÈ¡ÓйØÕ˵¥¡¢ÌõÔ¼¡¢ÉúÒâ¡¢¿Í»§ºÍÏàÖúͬ°éµÄÉñÃØÐÅÏ¢¡£
Êê½ð˵Ã÷˵£º¡°²¢È·±££¬ÈôÊÇÄú²»¸¶¿î£¬ËùÓÐÎļþºÍÎĵµ½«±»Ðû²¼¸øËùÓÐÈËÉó²é£¬²¢ÇÒÎÒÃǽ«Í¨¹ýÖ±½ÓÁ´½Ó֪ͨËùÓпͻ§ºÍÏàÖúͬ°éÓйØÕâ´Î×ß©µÄÐÅÏ¢¡£¡±
ͼƬÀ´×ÔÍÆÌØ
ÒÔÊÇÈôÊÇÄãÃDz»ÏëÃûÉùÊÜËð£¬×îºÃ¾¡¿ì°´ÒªÇóÖ§¸¶Êê½ð¡£
¹¥»÷ÕßÔÚ¼´Ê±´°¿ÚÖм¥Ð¦EDP
Ragnar LockerÀÕË÷Èí¼þ±³ºóµÄʹÓÃÕß»¹ÔÚͨ¹ý¡°¿Í·þ´°¿Ú¡±ºÍEDP¾ÙÐÐʵʱ̸Ì죬ҪÇóËûÃǼì²é¹«Ë¾ÍøÕ¾¹ØÓÚÕâ¸öйÃÜÍþвµÄ֪ͨ£¬²¢Ñ¯Îʹ«Ë¾ÊÇ·ñÔ¸Òâ¿´µ½Æóҵ˽ÈËÐÅÏ¢·ºÆðÔÚ¿ìѶ¡¢ÊÖÒÕ²©¿ÍºÍ¹ÉÊÐÍøÕ¾ÉÏ¡£
ËûÃÇ»¹Ôö²¹µÀ¡°Ê±²»´ýÈË¡±£¬»¹ÖÒÑÔEDP²»ÒªÊµÑéʹÓóýRagnar LockerÒÔÍâµÄ½âÃÜÆ÷À´ÆƽâÎļþ£¬²»È»½«ÓÐÊý¾ÝÆÆËðºÍɥʧµÄΣº¦¡£
¹¥»÷Õß»¹ÞÉÂäEDPÈôÊÇÔÚϵͳ¼ÓÃÜÁ½ÌìºóÁªÏµËûÃÇ£¬Äܹ»ÏíÊÜÓŻݼÛÇ®¡£¿ÉÊÇ£¬ËûÃÇÒ²ÒªµÈ×Å£¬ÀÕË÷Èí¼þµÄ¼´Ê±Ì¸ÌìÒ²²»»áÈ«ÌìºòÔÚÏß¡£
×èÖ¹·¢ÎÄ£¬EDP¹«Ë¾¶Ô´ËÉÐδÖÃÆÀ¡£
Ragnar Locker¼ÓÃÜÀú³Ì
Ragnar LockerÀÕË÷Èí¼þÔÚ2019Äê12ÔÂβÊ״α»·¢Ã÷£¬×¨ÃÅÕë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ³£ÓÃÈí¼þ£¬À´ÈëÇÖÍøÂçÇÔÈ¡Êý¾ÝÎļþ¡£
MSPÇå¾²¹«Ë¾Huntress LabsµÄÊ×ϯִÐйÙKyle HanslovanÔÚ2ÔÂ˵µ½£¬ËûµÄ¹«Ë¾·¢Ã÷Ragnar Lockerͨ¹ýMSPÈí¼þConnectWise¾ÙÐÐÁË°²ÅÅ¡£
¾ÓÉÕì̽ºÍ°²ÅÅÇ°½×¶Î£¬¹¥»÷Õß¹¹½¨Õë¶ÔÐÔÇ¿µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþΪ¼ÓÃÜÎļþÌí¼ÓÁËÌض¨µÄÀ©Õ¹Ãû£¬¾ßÓÐǶÈëʽRSA-2048ÃÜÔ¿£¬²¢¼ÓÈë×Ô½ç˵ÀÕË÷Ʊ¾Ý¡£
Ragnar Locker¾ßÓжà´ÎµÄÊê½ð¼Í¼£¬Êê½ð¼Í¼°üÀ¨Êܺ¦ÕߵĹ«Ë¾Ãû³Æ¡¢TorÕ¾µãµÄÁ´½ÓÒÔ¼°°üÀ¨Êܺ¦ÕßÒÑÐû²¼Êý¾ÝµÄÊý¾Ý×ß©վµã£¬Êê½ð¹æÄ£´Ó20ÍòÃÀÔªµ½Ô¼Äª60ÍòÃÀÔª²»µÈ¡£
SentinelLabs¶ÔÕâÖÖÀÕË÷²¡¶¾¾ÙÐÐÆÊÎö£¬ÈÏÕæÈËVitali KremezÌá¼°£¬Ragnar LockerÊ×´ÎÆô¶¯Ê±½«¼ì²éÉèÖõÄWindowsÓïÑÔÊ×Ñ¡ÏÈôÊǽ«ËüÃÇÉèÖÃΪǰËÕÁª¹ú¼ÒÖ®Ò»£¬Ôò»áÖÕÖ¹¸ÃÀú³Ì²¢ÇÒ²î³ØÅÌËã»ú¾ÙÐмÓÃÜ¡£ÈôÊÇÊܺ¦Õßͨ¹ýÁ˴˼ì²é£¬ÔòÀÕË÷Èí¼þ½«×èÖ¹ÉÏÒ»½ÚÖÐËùÊöµÄÖÖÖÖWindows·þÎñ¡£
ÏÖÔÚÒѾ׼±¸ºÃ¶ÔÅÌËã»ú¾ÙÐмÓÃÜ£¬Ragnar Locker½«×îÏȶÔÅÌËã»úÉϵÄÎļþ¾ÙÐмÓÃÜ¡£
¼ÓÃÜÎļþʱ£¬Ëü½«Ìø¹ýÒÔÏÂÎļþ¼Ð¡¢ÎļþÃûºÍÀ©Õ¹ÃûÖеÄÎļþ£º
kernel32.dll
Windows
Windows.old
Tor browser
Internet Explorer
Opera
Opera Software
Mozilla
Mozilla Firefox
$Recycle.Bin
ProgramData
All Users
autorun.inf
boot.ini
bootfont.bin
bootsect.bak
bootmgr
bootmgr.efi
bootmgfw.efi
desktop.ini
iconcache.db
ntldr
ntuser.dat
ntuser.dat.log
ntuser.ini
thumbs.db
.sys
.dll
.lnk
.msi
.drv
.exe
¹ØÓÚÿ¸ö¼ÓÃÜÎļþ£¬ÎļþÃûºó¶¼»áÌí¼ÓÒ»¸öÔ¤ÉèÖõÄÀ©Õ¹Ãû£¬Èç.ragnar_22015ABC ¡£ÈçÏÂËùʾ£¬¡° RAGNAR¡±Îļþ±ê¼ÇÒ²½«Ìí¼Óµ½Ã¿¸ö¼ÓÃÜÎļþµÄĩβ¡£
¼ÓÃÜÎļþ±ê¼Ç
×îºó£¬½«½¨ÉèÒ»¸öÃûΪ.RGNR_ [extension] .txtµÄÊê½ðƱ¾Ý£¬ÆäÖаüÀ¨ÓйØÊܺ¦ÕßÎļþ±¬·¢ÁËʲôÇéÐΡ¢Êê½ð½ð¶î¡¢±ÈÌرÒÖ§¸¶µØµã¡¢Óë¹¥»÷Õß¾ÙÐÐͨѶµÄTOX̸ÌìIDµÈÐÅÏ¢£¬ÈôÊÇTOXÔòÓñ¸·ÝµÄµç×ÓÓʼþµØµã¡£
Ragnar LockerÀÕË÷Ʊ¾Ý
ÏÖÔÚÕë¶ÔRagnar LockerÀÕË÷Èí¼þ¼ÓÃÜÎļþÉÐÎÞ·¨½âÃÜ£¬ºóÐø±¾ÎĽ«Ò»Á¬¸ú½ø¡£
£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©
Copyright ? ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø °æȨËùÓÐ ¾©ICP±¸05032414ºÅ ¾©¹«Íø°²±¸11010802024551ºÅ