标签:机器 wing end 方式 span file 修复 because 漏洞
Hi, please view here: http://pastebin.com/raw/jtSjmJzS for information on how to obtain your files!
如果你在服务器看到上面的信息,恭喜你被勒索了
如果你还没有见过上面的信息,希望你以后也不要遇到
服务器是:腾讯云服务器
所有者是:我的一个同事
当我知道这个情况的时候我的同事已经把云机器重置系统了,,本来还想看一下机器上面的情况
现在只能根据现有信息进行分析了
今天同事照常登录系统,准备继续搞事,刚登录上就弹出:
Hi, please view here: http://pastebin.com/raw/jtSjmJzS for information on how to obtain your files!
心凉一截
进入上面给的链接查看下:
YOU HAVE BEEN INFECTED WITH RANSOMWARE | YOU HAVE BEEN INFECTED WITH RANSOMWARE You have been hacked. When you were hacked, your files were sent to a server that we control and removed from you. You must pay 0.25 BITCOIN to get your files back and prevent them from being leaked to this address: 14z9Rbpw5SozMuMRRrdwcKaSs4PsxiEHRE We are the only ones in the world that can provide your files for you! When you have sent payment, send e-mail to aariz@airmail.cc with: 2) SERVER IP ADDRESS 3) BTC TRANSACTION ID FBI SUGGEST TO JUST PAY: https://www.tripwire.com/state-of-security/latest-security-news/ransomware-victims-should-just-pay-the-ransom-says-the-fbi/ When you pay, you will receive an FTP account where you can retrieve your files and delete all your data from us. If you do not pay, at end of the month we will collect all data that remains on server and leak it. HOW TO PURCHASE BITCOIN: You can purchase bitcoin from following: http://localbitcoins.com http://kraken.com http://okcoin.com http://coinbase.com You can message aariz@airmail.cc for support, but we will not respond to questions such as "can i see files first?" because we do not have time for this When you have sent payment, put [PAID] in email subject so we can attend to you before others!
果然,要币,而且要的真特么人性化啊
1、告诉你,你被黑了
2、付币,恢复文件,不付,月末删除文件,,FBI那个下面再说
3、付完后联系方式
4、没有币,没关系,还给你提供几个购买币的渠道
其中有一条是让看一下FBI提供的建议,,
我建议大家遇到这种情况不要支付,据不完全可靠消息说:攻击者并没有留存受害者的文件,只是骗受害者去付钱,详细信息见下链接:
当然如果你的文件比较重要的话可以Try一下
当然如果你非常Rich的话也可以Try一下
当然FBI的建议下面的还是可以听取的
备份很重要!这就和吃药是一样的,按时吃,要定期吃,病才会好,数据才会安全
再看一下为什么会被黑:
首先就是腾讯云已经提示可能存在的风险被忽略:
【腾讯云】您好,近日腾讯云安全中心监测到云主机搭建的Redis服务存在安全风险(腾讯云账号ID:10000*******),可能导致机器被入侵,黑客可以获取云主机的最高权限,导致数据丢失或被加密勒索,如果您的云主机中安装了Redis服务,为了避免您的业务受影响,建议您及时进行加固,具体可以参考<Redis未授权访问漏洞修复建议>:http://bbs.qcloud.com/thread-30706-1-1.html,如果您已经进行了加固,请忽略该通知,详细内容参见站内信。
标签:机器 wing end 方式 span file 修复 because 漏洞
原文地址:https://www.cnblogs.com/LuckWJL/p/10055429.html