1. 程式人生 > >記一次服務器被勒索!

記一次服務器被勒索!

bitcoin str ftp ron rrd support width 當我 一個

Hi, please view here: http://pastebin.com/raw/jtSjmJzS for information on how to obtain your files!

如果你在服務器看到上面的信息,恭喜你被勒索了

如果你還沒有見過上面的信息,希望你以後也不要遇到

服務器是:騰訊雲服務器

所有者是:我的一個同事

當我知道這個情況的時候我的同事已經把雲機器重置系統了,,本來還想看一下機器上面的情況

現在只能根據現有信息進行分析了

今天同事照常登錄系統,準備繼續搞事,剛登錄上就彈出:

Hi, please view here: http://pastebin.com/raw/jtSjmJzS for information on how to obtain your files!

心涼一截

進入上面給的鏈接查看下:

技術分享圖片

YOU HAVE BEEN INFECTED WITH RANSOMWARE | YOU HAVE BEEN INFECTED WITH RANSOMWARE

You have been hacked.
When you were hacked, your files were sent to a server that we control and removed from you.

You must pay 0.25 BITCOIN to get your files back and prevent them from being leaked to this address:

14z9Rbpw5SozMuMRRrdwcKaSs4PsxiEHRE

We are the only ones 
in the world that can provide your files for you! When you have sent payment, send e-mail to aariz@airmail.cc with: 2) SERVER IP ADDRESS 3) BTC TRANSACTION ID FBI SUGGEST TO JUST PAY: https://www.tripwire.com/state-of-security/latest-security-news/ransomware-victims-should-just-pay-the-ransom-says-the-fbi/
When you pay, you will receive an FTP account where you can retrieve your files and delete all your data from us. If you do not pay, at end of the month we will collect all data that remains on server and leak it. HOW TO PURCHASE BITCOIN: You can purchase bitcoin from following: http://localbitcoins.com http://kraken.com http://okcoin.com http://coinbase.com You can message aariz@airmail.cc for support, but we will not respond to questions such as "can i see files first?" because we do not have time for this When you have sent payment, put [PAID] in email subject so we can attend to you before others!

果然,要幣,而且要的真特麽人性化啊

1、告訴你,你被黑了

2、付幣,恢復文件,不付,月末刪除文件,,FBI那個下面再說

3、付完後聯系方式

4、沒有幣,沒關系,還給你提供幾個購買幣的渠道

其中有一條是讓看一下FBI提供的建議,,

技術分享圖片

我建議大家遇到這種情況不要支付,據不完全可靠消息說:攻擊者並沒有留存受害者的文件,只是騙受害者去付錢,詳細信息見下鏈接:

https://www.bleepingcomputer.com/news/security/hacked-redis-servers-being-used-to-install-the-fairware-ransomware-attack/

當然如果你的文件比較重要的話可以Try一下

當然如果你非常Rich的話也可以Try一下

當然FBI的建議下面的還是可以聽取的

技術分享圖片

備份很重要!這就和吃藥是一樣的,按時吃,要定期吃,病才會好,數據才會安全

再看一下為什麽會被黑:

首先就是騰訊雲已經提示可能存在的風險被忽略:

【騰訊雲】您好,近日騰訊雲安全中心監測到雲主機搭建的Redis服務存在安全風險(騰訊雲賬號ID:10000*******),可能導致機器被入侵,黑客可以獲取雲主機的最高權限,導致數據丟失或被加密勒索,如果您的雲主機中安裝了Redis服務,為了避免您的業務受影響,建議您及時進行加固,具體可以參考<Redis未授權訪問漏洞修復建議>:http://bbs.qcloud.com/thread-30706-1-1.html,如果您已經進行了加固,請忽略該通知,詳細內容參見站內信。

記一次服務器被勒索!