|
病毒家族 | mallbox |
---|---|---|
病毒别名 | mallab | |
影响系统 | Windows | |
出现时间 | 2023年 |
所有文件被加上原文件名.mallab后缀(扩展名);
数据和文件被加密,小于10K的文件不加密,
Windows系统核心文件未加密,Windows系统可以运行;
系统安全服务、SQL服务、虚拟机、杀毒软件等被关闭禁用;
Windows系统备份被删除;
病毒文件自销毁;
Windows日志被删除;
文件夹下生成 HOW TO BACK FILES.txt;
HOW TO BACK FILES.txt 文本内容如下:
Hello
Your files are encrypted and can not be used
We have downloaded your confidential data and are ready to publish it on our blog
To return your files in work condition you need decryption tool
Follow the instructions to decrypt all your data
Do not try to change or restore files yourself, this will break them
If you want, on our site you can decrypt one file for free. Free test decryption allowed only for not valuable file with size less than 3MBHow to get decryption tool:
1) Download and install *** browser by this link: https://www.***.org/download/
2) If TOR blocked in your country and you can't access to the link then use any *** software
3) Run TOR browser and open the site: ***********************************************************************.onion/mallox/privateSignin
4) Copy your private ID in the input field. Your Private key: *************************************
5) You will see payment information and we can make free test decryption here
Our blog of leaked companies:
*****************************************************.onion
If you are unable to contact us through the site, then you can email us: *****@onionmail.org
Waiting for a response via mail can be several days. Do not use it if you have not tried contacting through the site.
暗网界面如下:
根据勒索病毒的计算机数据加密原理,国瑞团队修复或者解密被加密数据,不限任何扩展名,但需要针对不同病毒家族、版本,了解病毒的特性和加密率,用来决策采取对应的处理方法手段。 所以,当您寻求国瑞团队救援数据或其他专业数据恢复或安全机构的帮助之前,最好掌握一些信息,提前介绍给专业人员,以便我们更快速准确判断和解决灾难事件。
核心数据服务器上,分区数量、分区空间使用量,被加密文件的总数量(比如几百个、几万个、百万级),核心数据大小(比如:数据库总共20个、总大小1T、最大的库100G等),数据备份损失情况,是否有未被加密文件情况。