码迷,mamicode.com
首页 > 其他好文 > 详细

记一次服务器被勒索!

时间:2018-12-02 22:31:55      阅读:404      评论:0      收藏:0      [点我收藏+]

标签:机器   wing   end   方式   span   file   修复   because   漏洞   

Hi, please view here: http://pastebin.com/raw/jtSjmJzS for information on how to obtain your files!

如果你在服务器看到上面的信息,恭喜你被勒索了

如果你还没有见过上面的信息,希望你以后也不要遇到

服务器是:腾讯云服务器

所有者是:我的一个同事

当我知道这个情况的时候我的同事已经把云机器重置系统了,,本来还想看一下机器上面的情况

现在只能根据现有信息进行分析了

今天同事照常登录系统,准备继续搞事,刚登录上就弹出:

Hi, please view here: http://pastebin.com/raw/jtSjmJzS for information on how to obtain your files!

心凉一截

进入上面给的链接查看下:

技术分享图片

YOU HAVE BEEN INFECTED WITH RANSOMWARE | YOU HAVE BEEN INFECTED WITH RANSOMWARE

You have been hacked.
When you were hacked, your files were sent to a server that we control and removed from you.

You must pay 0.25 BITCOIN to get your files back and prevent them from being leaked to this address:

14z9Rbpw5SozMuMRRrdwcKaSs4PsxiEHRE

We are the only ones in the world that can provide your files for you!

When you have sent payment, send e-mail to aariz@airmail.cc with: 
2) SERVER IP ADDRESS 
3) BTC TRANSACTION ID

FBI SUGGEST TO JUST PAY: https://www.tripwire.com/state-of-security/latest-security-news/ransomware-victims-should-just-pay-the-ransom-says-the-fbi/

When you pay, you will receive an FTP account where you can retrieve your files and delete all your data from us. If you do not pay, at end of the month we will collect all data that remains on server and leak it.

HOW TO PURCHASE BITCOIN:

You can purchase bitcoin from following:

http://localbitcoins.com
http://kraken.com
http://okcoin.com
http://coinbase.com

You can message aariz@airmail.cc for support, but we will not respond to questions such as "can i see files first?" because we do not have time for this

When you have sent payment, put [PAID] in email subject so we can attend to you before others!

果然,要币,而且要的真特么人性化啊

1、告诉你,你被黑了

2、付币,恢复文件,不付,月末删除文件,,FBI那个下面再说

3、付完后联系方式

4、没有币,没关系,还给你提供几个购买币的渠道

其中有一条是让看一下FBI提供的建议,,

技术分享图片

我建议大家遇到这种情况不要支付,据不完全可靠消息说:攻击者并没有留存受害者的文件,只是骗受害者去付钱,详细信息见下链接:

当然如果你的文件比较重要的话可以Try一下

当然如果你非常Rich的话也可以Try一下

当然FBI的建议下面的还是可以听取的

技术分享图片

备份很重要!这就和吃药是一样的,按时吃,要定期吃,病才会好,数据才会安全

再看一下为什么会被黑:

首先就是腾讯云已经提示可能存在的风险被忽略:

【腾讯云】您好,近日腾讯云安全中心监测到云主机搭建的Redis服务存在安全风险(腾讯云账号ID:10000*******),可能导致机器被入侵,黑客可以获取云主机的最高权限,导致数据丢失或被加密勒索,如果您的云主机中安装了Redis服务,为了避免您的业务受影响,建议您及时进行加固,具体可以参考<Redis未授权访问漏洞修复建议>:http://bbs.qcloud.com/thread-30706-1-1.html,如果您已经进行了加固,请忽略该通知,详细内容参见站内信。

 

记一次服务器被勒索!

标签:机器   wing   end   方式   span   file   修复   because   漏洞   

原文地址:https://www.cnblogs.com/LuckWJL/p/10055429.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!