½üÈÕ£¬¹¥»÷ÕßÀûÓÃRagnar LockerÀÕË÷Èí¼þÏ®»÷ÁËÆÏÌÑÑÀ¿ç¹úÄÜÔ´¹«Ë¾EDP£¨Energias de Portugal£©£¬²¢ÇÒË÷Òª1580µÄ±ÈÌØ±ÒÊê½ð£¨ÕÛºÏÔ¼1090ÍòÃÀÔª/990ÍòÅ·Ôª£©¡£¶Ô´Ë£¬EDPÉÐδ×÷³ö»Ø¸´¡£
EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄܳö²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¶È/µØÓòÕ¼ÓÐÒµÎñ£¬Õ¼Óг¬¹ý11500ÃûÔ±¹¤£¬²¢Îª³¬¹ý1100Íò¿Í»§ÌṩÄÜÔ´¡£

¹¥»÷ÕßÑïÑÔ¡°ËºÆ±¡±10TBµÄÇÔÃÜÊý¾Ý
ÔÚÕâ´Î¹¥»÷¹ý³ÌÖУ¬Ragnar LockerÀÕË÷Èí¼þµÄÄ»ºóºÚÊÖÐû³ÆÒѾ»ñÈ¡Á˹«Ë¾10TBµÄÃô¸ÐÊý¾ÝÎļþ£¬ÈôÊÇEDP²»Ö§¸¶Êê½ð£¬ÄÇôËûÃǽ«ÔÚ¹«¿ªÐ¹Â¶ÕâЩÊý¾Ý¡£
¾ÝRagnarµÄйÃÜÍøÕ¾Ëµµ½£º
ÎÒÃÇÒѾÏÂÔØÁËEDP×éÖ¯·þÎñÆ÷10TBµÄ˽ÃÜÐÅÏ¢¡£×÷Ϊ֤¾Ý£¬ÎÒÃÇÌṩÁËһЩÄã·½ÆóÒµÍøÂçÖÐÏÂÔØµÄÎļþ½ØÆÁ£¡´Ë¿ÌÕâ¸öÌû×ÓÖ»ÊÇһʱ£¬µ«ÊÇÈôÊÇÄãÃDz»Ö§¸¶Êê½ð£¬ÕâÒ²»á³ÉΪÓÀÔ¶ÐÔµÄÒ³Ãæ£¡ÎÒÃǽ«ÔÚ¸÷´ó³ÛÃû±¨É硢ýÌå¡¢²©¿Í¹«¿ªÕâЩÎļþ×ÊÁÏ£¬²¢ÇÒ·î¸æÄãÃǵĿͻ§¡¢ºÏ×÷ͬ°éºÍ¾ºÕùµÐÊÖ£¬ËùÒÔÕâЩÎļþÊÇ»úÃÜ»¹Êǹ«¿ªÆëȫȡ¾öÓÚÄãÃÇ£¡

Ragnar ÍøÕ¾µÄÍþв֪ͨ
ÆäÖУ¬¹¥»÷Õßй¶Á˲¿ÃÅÎļþÀ´ÖÒ¸æEDP£¬Ô̺¬Ò»¸öedpradmin2.kdbµÄÎļþ£¬ÕâÊÇKeePassÃÜÂëÖÎÀíÊý¾Ý¿â¡£µ±µã¿ªÕâ¸öй¶ÎļþµÄÁ´½Ó£¬»áÖ±½Óµ¼³öEDPÔ±¹¤µÄµÇ¼Ãû¡¢ÃÜÂë¡¢ÕÊ»§¡¢URLSÒÔ¼°×¢½â¡£

MalwareHunterÍŶӷ¢ÏÖÁËÕâ´ÎÀÕË÷Èí¼þµÄ¹¥»÷Ñù±¾£¬²¢ÕÒµ½Êê½ð¼Í¼ºÍTor¸¶¿îÒ³Ãæ£¬¹¥»÷ÕßÔÚÆäÖоßÌåÃèÊöÏàʼûܹý³ÌºÍÀÕË÷½ð¶î¡£
ƾ¾ÝEDP¼ÓÃÜϵͳÉϵÄÊê½ð¼Í¼£¬¹¥»÷Õß¿ÉÄÜÇÔÈ¡ÓйØÕ˵¥¡¢ºÏͬ¡¢ÂòÂô¡¢¿Í»§ºÍºÏ×÷ͬ°éµÄ»úÃÜÐÅÏ¢¡£
Êê½ð×¢Ã÷˵£º¡°²¢È·±££¬ÈôÊÇÄú²»¸¶¿î£¬ËùÓÐÎļþºÍÎĵµ½«±»°ä²¼¸øËùÓÐÈ˲鿴£¬²¢ÇÒÎÒÃǽ«Í¨¹ýÖ±½ÓÁ´½Ó֪ͨËùÓпͻ§ºÍºÏ×÷ͬ°éÓйØÕâ´Îй©µÄÐÅÏ¢¡£¡±

ͼƬÀ´×ÔÍÆÌØ
ËùÒÔÈôÊÇÄãÃDz»ÏëÃûÉùÊÜËð£¬×îºÃ¾¡¿ì°´ÒªÇóÖ§¸¶Êê½ð¡£
¹¥»÷ÕßÔÚ¼´Ê±´°¿ÚÖг°·íEDP
Ragnar LockerÀÕË÷Èí¼þ±³ºóµÄ°Ñ³ÖÕß»¹ÔÚͨ¹ý¡°¿Í·þ´°¿Ú¡±ºÍEDP½øÐÐʵʱ̸Ì죬ҪÇóËûÃDz鳹«Ë¾ÍøÕ¾¹ØÓÚÕâ¸öйÃÜÍþвµÄ֪ͨ£¬²¢Ñ¯Îʹ«Ë¾ÊÇ·ñÔ¸Òâ¿´µ½ÆóÒµ¸öÈËÐÅÏ¢³Ê´Ë¿Ì¿ìѶ¡¢¼¼Êõ²©¿ÍºÍ¹ÉÊÐÍøÕ¾ÉÏ¡£
ËûÃÇ»¹²¹³ä·¡°Ê±²»´ýÈË¡±£¬»¹ÖÒ¸æEDP²»Òª³¢ÊÔʹÓóýRagnar LockerÒÔ±íµÄ½âÃÜÆ÷À´ÆÆ½âÎļþ£¬²»È»½«º±¼û¾Ý·ÛËéºÍÃÔʧµÄ·çÏÕ¡£
¹¥»÷Õß»¹µ÷Ù©EDPÈôÊÇÔÚϵͳ¼ÓÃÜÁ½ÌìºóÁªÏµËûÃÇ£¬¿ÉÄÜÏíÊÜÓŻݼÛÖµ¡£µ«ÊÇ£¬ËûÃÇÒ²ÒªµÈ×Å£¬ÀÕË÷Èí¼þµÄ¼´Ê±Ì¸ÌìÒ²²»»áÈ«ÌìºòÔÚÏß¡£
½ØÖ¹·¢ÎÄ£¬EDP¹«Ë¾¶Ô´ËÉÐδÖÃÆÀ¡£
Ragnar Locker¼ÓÃܹý³Ì
Ragnar LockerÀÕË÷Èí¼þÔÚ2019Äê12Ôµ׳õ´Î±»·¢ÏÖ£¬×¨ÃÅÕë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ³£ÓÃÈí¼þ£¬À´ÈëÇÖÍøÂçÇÔÈ¡Êý¾ÝÎļþ¡£
MSP°²È«¹«Ë¾Huntress LabsµÄÊ×ϯִÐйÙKyle HanslovanÔÚ2ÔÂ˵µ½£¬ËûµÄ¹«Ë¾·¢ÏÖRagnar Lockerͨ¹ýMSPÈí¼þConnectWise½øÐÐÁ˲¿Êð¡£

¾¹ý¿úËźͲ¿Êðǰ½×¶Î£¬¹¥»÷Õß¹¹½¨Õë¶ÔÐÔÇ¿µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¬¸Ã¿ÉÖ´ÐÐÎļþΪ¼ÓÃÜÎļþÔö³¤ÁËÌØ¶¨µÄÀ©´óÃû£¬ÓµÓÐǶÈëʽRSA-2048ÃÜÔ¿£¬²¢²ÎÓë×Ô½ç˵ÀÕË÷µ¥¾Ý¡£
Ragnar LockerÓµÓÐÂŴεÄÊê½ð¼Í¼£¬Êê½ð¼Í¼Ô̺¬Êܺ¦ÕߵĹ«Ë¾Ãû³Æ¡¢TorÕ¾µãµÄÁ´½ÓÒÔ¼°Ô̺¬Êܺ¦ÕßÒѰ䲼Êý¾ÝµÄÊý¾Ýй©վµã£¬Êê½ðÁìÓò´Ó20ÍòÃÀÔªµ½Ô¼Äª60ÍòÃÀÔª²»µÈ¡£
SentinelLabs¶ÔÕâÖÖÀÕË÷²¡¶¾½øÐзÖÎö£¬ÕƹÜÈËVitali KremezÌá¼°£¬Ragnar Locker³õ´ÎÆô¶¯Ê±½«²é³ÅäÖõÄWindows˵»°Ê×Ñ¡ÏÈôÊǽ«ËüÃÇÉèÖÃΪǰËÕÁª¹ú¶ÈÖ®Ò»£¬Ôò»áÖÕÖ¹¸Ã¹ý³Ì²¢ÇÒ²»ºÏÍÆËã»ú½øÐмÓÃÜ¡£ÈôÊÇÊܺ¦Õßͨ¹ýÁ˴˲鳣¬ÔòÀÕË÷Èí¼þ½«ÖÕ³¡ÉÏÒ»½ÚÖÐËùÊöµÄ¸÷ÀàWindows·þÎñ¡£
´Ë¿ÌÒѾ³ï±¸ºÃ¶ÔÍÆËã»ú½øÐмÓÃÜ£¬Ragnar Locker½«ÆðÍ·¶ÔÍÆËã»úÉϵÄÎļþ½øÐмÓÃÜ¡£
¼ÓÃÜÎļþʱ£¬Ëü½«Ìø¹ýÒÔÏÂÎļþ¼Ó×¢ÎļþÃûºÍÀ©´óÃûÖеÄÎļþ£º
kernel32.dll
Windows
Windows.old
Tor browser
Internet Explorer
Opera
Opera Software
Mozilla
Mozilla Firefox
$Recycle.Bin
ProgramData
All Users
autorun.inf
boot.ini
bootfont.bin
bootsect.bak
bootmgr
bootmgr.efi
bootmgfw.efi
desktop.ini
iconcache.db
ntldr
ntuser.dat
ntuser.dat.log
ntuser.ini
thumbs.db
.sys
.dll
.lnk
.msi
.drv
.exe
¶ÔÓÚÿ¸ö¼ÓÃÜÎļþ£¬ÎļþÃûºó³ÇÊÐÔö³¤Ò»¸öÔ¤ÅäÖõÄÀ©´óÃû£¬Èç.ragnar_22015ABC ¡£ÈçÏÂËùʾ£¬¡° RAGNAR¡±ÎļþÏóÕ÷Ò²½«Ôö³¤µ½Ã¿¸ö¼ÓÃÜÎļþµÄĩβ¡£

¼ÓÃÜÎļþÏóÕ÷
×îºó£¬½«´´½¨Ò»¸öÃûΪ.RGNR_ [extension] .txtµÄÊê½ðµ¥¾Ý£¬ÆäÖÐÔ̺¬ÓйØÊܺ¦ÕßÎļþ²úÉúÁËʲôÇé¿ö¡¢Êê½ð½ð¶î¡¢±ÈÌØ±ÒÖ§¸¶µØÖ·¡¢Óë¹¥»÷Õß½øÐÐͨѶµÄTOX̸ÌìIDµÈÐÅÏ¢£¬ÈôÊÇTOXÔòÓñ¸·ÝµÄµç×ÓÓʼþµØÖ·¡£

Ragnar LockerÀÕË÷µ¥¾Ý
ĿǰÕë¶ÔRagnar LockerÀÕË÷Èí¼þ¼ÓÃÜÎļþÉÐÎÞ·¨½âÃÜ£¬ºóÐø±¾ÎĽ«³ÖÐø¸ú½ø¡£
£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©
Copyright ? GA»Æ½ð¼× °æÈ¨ËùÓÐ ¾©ICP±¸05032414ºÅ
¾©¹«Íø°²±¸11010802024551ºÅ