888 家族详情

888

低活跃

暂无信息

首次发现 :
勒索信 : !RESTORE_FILES!.txt
算法 : AES-256
扩展名 : 888

情报摘要:

别名 :
Crypt888(历史关联,待确认)
IOC数量 :
5
受害记录 :
0
ATT&CK战术 :
19

概览

暂无信息

加密特征

暂无加密特征数据。

勒索信

勒索信文件 : !RESTORE_FILES!.txt

+----------------------------------------------------------------------------+ | !!!ALL YOUR FILES ARE ENCRYPTED, AS A RESULT OF A BREACH IN SECURITY!!! | +----------------------------------------------------------------------------+ No worries - you can get them back! It's impossible to decrypt without contacting us. +----------------------------------------------------------------------------+ | !!!DON'T TRY TO CHANGE ENCRYPTED FILES!!! | | !!!DON'T RENAME ENCRYPTED FILES!!! | | !!!DON'T USE ADDITIONAL RECOVERY SOFTWARE!!! | | !!!IT WILL MAKE THEM IMPOSSIBLE TO DECRYPT!!! | +----------------------------------------------------------------------------+ How to return all your data back in safe: 1. Copy and sent us your KEY. 2. We can decrypt 2 small files, no databases (.jpg, .txt, .doc, ets.. (up to 3mb)) as your warranty. 3. After payment, you will receive a special software for decryption. ----------------------------------------------------------------------------------------------------------------- KEY: xxxxxxxxxxxxxxxxxxxxxxx ----------------------------------------------------------------------------------------------------------------- EMAILS: nemesis@888recover.4wrd.cc nemesissupport@firemail.cc Zero cheats, all integrity.

勒索信文件 : SnowSoul.txt

Just Relax We are Snow Soul, All data has been encrypted --- Adopting military grade AES-RSA encryption Warning! Do not delete or modify encrypted files, it will lead to problems with decryption of files! Contact us for payment, and we will decrypt it please pay Monero -!!!!We accept XMR, (The price won't be too high) XMR (Long term no contact, key at risk of automatic deletion) Send your encrypted IP address, write to the following address, and wait for a reply: ↓ ↓ ↓ ↓ ↓ ↓ ↓ troyal@tutamail.com (No reply?) ↓ theroyalt@onionmail.org (No reply?) ↓ telegram ;:: https://xxxxxxxxxxxxxxxxxxxxx ↓ discord.com/ :: @theroyalteam963 ↓ github.com/qTox/qTox Download Qtox tox id :2383E6FB5C55CA86EE55B4A278170EF97A0D2B57FDEDFDBD888B151F9E62EA097429A2461128 放轻松 我只是使用这个软件, 注意!!不要使用比特币 (我们收xmr) 所有数据已被加密 不要使用第三方工具或备份来恢复文件。任何此类操作都将导致数据不可逆丢失 价格不会太高 (门罗币) (长期无联系,密钥有自动删除的风险) 注意!!! 我们收门罗币 等虚拟货币...... 发送您的IP地址,写入以下地址,等待回复: ↓ ↓ ↓ ↓ ↓ ↓ ↓ troyal@tutamail.com (联系不上?) ↓ theroyalt@onionmail.org (联系不上?) ↓ 电报 :: https://xxxxxxxxxxxxxxxxxxxxxxx ↓ discord.com :: @theroyalteam963 ↓ github.com/qTox/qTox 下载qtox tox id :2383E6FB5C55CA86EE55B4A278170EF97A0D2B57FDEDFDBD888B151F9E62EA097429A2461128

勒索信文件 : how_to_decrypt1.txt

ALL YOUR DATA WAS ENCRYPTED Whats Happen? Your files are encrypted, and currently unavailable. You can check it: By the way, everything is possible to restore, but you need to follow our instructions. Otherwise, you cant return your data. What guarantees? It's just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will not cooperate with us. It's not in our interests. If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause just we have the private key. In practise - time is much more valuable than money. What should You include in your message? 1. Your country and city 2. This TXT file 3. Some files for free decryption Free decryption as guarantee! Before paying you send us up to 1 files for free decryption Less than 50M. Send pictures, text files. To get this software you need write on our e-mail: eosbtc@tutamail.com If there is no reply on the email address above, it is very likely that I have not received your email. Please contact the email address below eosdata@cock.li Russian Federation users please do not use mail.ru to send me emails, because I cannot receive emails from mail.ru. You can register tutanota.com email or protonmail.com to contact me, or other email addresses! ! Your personal ID:772E072EC9FE79D509367E76A1F2D99D2210228BF35267830FA4F16A3 4F3A8A4C45F772BC9B1DF0955E3F8DB8884CAFC239F1A54A9CD411250C9A45ACF827AF 8009472BBC580573F071CCF2198CE5ED35B4895030F3F71A 937477ED8AC51100CF38A0582725CACB16D3530D3F79A661A43C 650585AFC83476681E4A5A4C497E1CE00831AC87E7C8FF38FB1DC B57F4DA9CB2073A9CC55655F7BEE69A0E2B8C5E 134D6B2D97C0E2C1B02EFB1013F01F 9CFAADB1F4C7F6ABCAF5D717A4942DFEC57A0AAACA8F3FCCF 429975B13770A93E74306CD27DDDE4C7B6CAA77199B3DE498 6FCE53FD09CDE9AE68C1875765154243 6924B4C1D3B8602EFA689E5A2BE8F261225 9A5D45CC99D09A5B070E69D86E3B67A6FDD7D 1A489777BB743DF62252AAF46B99992 D1186F949D45D7B86426CE42083CF2862A8E9E372B6FD9D523B 63D58E72EA8EEC5F3CACBDFF1DD0660B86240285E0DB98A15D6 EDBB69BE331F96914B6C89BAE69DE93EDE29B17CD43B64 2C11392192DB0B9B3A0970B7CCDA5C81D714D60243A257 12205C5B28FD88C31816E5094E0F6407CEAB7F57AE00 BD71E0DAAEF884D220FF79A255556ECD4674A915EA 802E1C24B02B93CF0A0BCCAFDD4CD1C995A365113121ADAFC7 B6DDF2C9AF8AABFCFC8EC500EFBD0770B2FC641F0655AEC9ECC03A 664FF0E2B5F343777992DDC5AC4EF44CD0952 9761B7A673F42E69601BB

勒索信文件 : RECOVERY INFO.txt

Your files has been encrypted To recover them you need decryption tool Instruction: 1)Download TOR Browser https://xxxxxxxxxxxxxxxxx 2)Open TOR browser and follow by link below: http://xxxxxxxxxxxxxxxxxxxx Or email: datahelper@cyberfear.com Our guarantee: we provide free decyrption for 3 files up to 3 megabytes (not zip,db,backup)

勒索信文件 : +README-WARNING+.txt

::: Greetings ::: Little FAQ: .1. Q: Whats Happen? A: Your files have been encrypted. The file structure was not damaged, we did everything possible so that this could not happen. .2. Q: How to recover files? A: If you wish to decrypt your files you will need to pay us. .3. Q: What about guarantees? A: Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will cooperate with us. Its not in our interests. To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg,xls,doc, etc... not databases!) and low sizes(max 1 mb), we will decrypt them and send back to you. That is our guarantee. .4. Q: How to contact with you? A: You can write us to our mailbox: RestoreBackup@cock.li Or you can contact us via TOX: ADA6E26332F26451E45768179C771CA87A7F0F4E234DA8D882888F505494925DCF274A3EA555 You don't know about TOX? Go to https://xxxxxxxxx .5. Q: How will the decryption process proceed after payment? A: After payment we will send to you our scanner-decoder program and detailed instructions for use. With this program you will be able to decrypt all your encrypted files. .6. Q: If I don抰 want to pay bad people like you? A: If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause only we have the private key. In practice - time is much more valuable than money. :::BEWARE::: DON'T try to change encrypted files by yourself! If you will try to use any third party software for restoring your data or antivirus solutions - please make a backup for all encrypted files! Any changes in encrypted files may entail damage of the private key and, as result, the loss all data.

技术细节

“888”勒索软件的公开技术细节较少,当前更适合作为基于勒索扩展名的威胁标签处理,而非已充分定义的独立勒索家族。公开资料未稳定披露其开发语言、互斥体名称、配置结构、样本哈希、C2 域名或固定文件路径;因此这些字段应标记为暂无公开信息。

从已知勒索样本命名习惯看,疑似 888 样本可能具备以下特征:加密后为文件追加 .888 扩展名,或采用类似 Dharma/CrySiS 的命名模式,将受害者 ID、联系邮箱和扩展名组合进文件名;赎金说明通常要求受害者通过邮件或即时通信工具联系攻击者。文件加密流程一般会遍历本地磁盘、可移动介质和网络共享,跳过系统关键目录以保持主机可启动。

持久化方面暂无公开信息,未见可靠资料证明其固定创建注册表 Run 键、计划任务或服务。规避方面也缺乏明确证据,不能确认是否具备虚拟机检测、调试器检测、代码混淆或安全进程终止能力。C2 通信同样暂无公开信息;部分勒索软件并不依赖实时 C2,而是在样本中内置公钥和联系信息。防御侧应重点监控异常批量改名、短时间高频文件写入、卷影副本删除命令、远程桌面暴力破解痕迹以及未知可执行文件从用户目录启动等行为。

威胁指标

email

恶意邮箱

nemesis@888recover.4wrd.cc

来源 : SolarA028项目捕获
首次录入 : 2024-10-15
最后更新 : 2026-09-01

email

恶意邮箱

nemesissupport@firemail.cc

来源 : SolarA028项目捕获
首次录入 : 2024-10-15
最后更新 : 2026-09-01

MD5

恶意软件样本

5807d78434e578865d60acbcd7030df1

来源 : Solar263项目捕获
首次录入 : 2026-01-23
最后更新 : 2026-09-01

MD5

恶意软件样本

87aaae78b96ca76c0152c2d38ba14f38

来源 : Solar259项目捕获
首次录入 : 2026-01-21
最后更新 : 2026-09-01

MD5

恶意软件样本

f6f828fa9c1b9381dfe8453b20513754

来源 : Solar020项目捕获
首次录入 : 2025-06-20
最后更新 : 2026-09-01

受害者信息

暂无受害者记录。

MITRE ATT&CK

  • 初始访问:暂无公开信息能够确认 888 的固定入侵路径。若其确属 Dharma/CrySiS 相关分支,常见入口包括暴露的 RDP 暴力破解或凭据填充,对应 ATT&CK T1110T1133;也可能通过钓鱼附件或恶意下载器投递,对应 T1566T1204,但不能作为该标签的确定结论。

  • 执行:勒索载荷通常由攻击者手动运行、通过远程管理工具运行,或由脚本/批处理触发,可映射到 T1059T1106。公开资料未确认 888 是否使用 PowerShell、.NET、C/C++ 或 Go 等具体实现语言。

  • 持久化:暂无公开信息。若出现注册表 Run 键、计划任务或服务安装,应分别关注 T1060/T1547.001T1053.005T1543.003,但这些属于检测假设,不应视为已验证家族特征。

  • 防御规避:同类勒索活动常终止安全软件、清理日志或删除备份,涉及 T1562.001T1070T1490。对于 888,是否稳定执行这些动作暂无公开信息,建议以主机行为日志确认。

  • 发现与横向移动:攻击者可能枚举磁盘、共享、域用户和在线主机,对应 T1083T1135T1018。如结合 RDP、SMB 或 PsExec 扩散,可关联 T1021.001T1021.002T1570,但暂无公开资料证明其为固定 TTP。

  • 加密勒索:核心影响行为是批量加密用户文件并追加 .888 标识,投递勒索说明,属于 T1486。若删除卷影副本或系统恢复点,则对应 T1490;该行为在 888 中暂无可靠公开确认。

处置建议

  1. 优先核查远程接入(VPN/RDP)暴露面与弱口令,启用 MFA。

  2. 验证备份的离线可用性,确保备份不可被加密或删除。

  3. 及时清理高权限账号与可疑会话,排查 AD 域控异常。

  4. 结合 IOC 对历史日志、终端文件与网络连接进行回溯。

  5. 隔离疑似受影响资产,保留勒索信与样本供分析。

常见行业

金融
中小企业
零售

常见入口

  • VPN 暴露
  • RDP 弱口令
  • 钓鱼邮件
  • 公开服务
  • 供应链入口
  • 远程运维

操作协助

把热线、演示和资料入口拆开,让应急处置、产品评估和补充阅读各自清晰

电话咨询

出现加密、停摆或勒索提示时,优先直接联系应急响应团队。

400-613-6816

预约演练

如果你在评估产品、后台和家族库能力,可以先预约一个简短演示。

预约30分钟

查看资料

把文章、工具和方案入口集中到一起,方便团队继续同步研判。

进入资料中心

5000+

服务客户

99.8%

平均恢复率

<5min

首次响应

50+

安全专家