Live 家族详情

Live

低活跃

LIVE勒索病毒家族最早被曝光是在23年12月份,360的论坛发布了该家族的被加密样本,其加密特征为文件名后直接添加LIVE后缀,这时候还是该家族勒索病毒的1.0版本。之后该家族还发布了1.5版本和2.0版本,其发布版本均已被我司破解,解密工具已发布在微信公众号上,可以关注微信公众号获取解密工具。

首次发现 :
勒索信 : readme_for_unlock_oct2024.txt、README lockbit.txt
算法 : AES_OFB
扩展名 : .LIVE

情报摘要:

别名 :
IOC数量 :
5
受害记录 :
0
ATT&CK战术 :
0

概览

LIVE勒索病毒家族最早被曝光是在23年12月份,360的论坛发布了该家族的被加密样本,其加密特征为文件名后直接添加LIVE后缀,这时候还是该家族勒索病毒的1.0版本。之后该家族还发布了1.5版本和2.0版本,其发布版本均已被我司破解,解密工具已发布在微信公众号上,可以关注微信公众号获取解密工具。

加密特征

暂无加密特征数据。

勒索信

勒索信文件 : readme_for_unlock_oct2024.txt

Urgent! Your files have been encrypted - act now to recover them! Greetings, We are a Ransomware Group, and we have successfully infiltrated your system and encrypted your valuable files. We have the only working decryptor, which is the one way to restore your data. Do not attempt to recover the files yourself or involve any third-party organizations, such as law enforcement or cybersecurity firms. Any attempts to do so will result in the permanent deletion of your files without any chance of recovery. To regain access to your files, you must follow these steps: Download & Install TOR browser: https://xxxxxxxxxxxxx For contact us via LIVE CHAT open our > Website: http://xxxxxxxxxxxxxxxxxxxxxxxxxx > Login: [snip] > Password: [snip] > Secret Question: [snip] If Tor is restricted in your area, use VPN. We offer a free trial decryption of two insignificant files (<5 MB) to demonstrate our capabilities and build trust. We will provide you with further instructions and the exact amount of ransom required to decrypt your files. Make the payment in Bitcoin to the provided wallet address. Once the payment is confirmed, we will send you the decryptor. Please note that you have a limited time to act before the deadline expires. After that, the decryptor will be destroyed, and your files will remain encrypted forever. Do not ignore this message or attempt to deceive us. We have already infiltrated your system, and we can easily detect any attempts to bypass our ransom demands. Take this situation seriously and act quickly to recover your files. Write to us in the chat to begin the process. Sincerely, Ransomware Group

勒索信文件 : GoTC8BXIp.README.txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ █▓▒░ 您好!您的系統已被 Global Secret Group 駭入 ░▒▓█ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> ALL YOUR DATA HAS BEEN STOLEN AND ENCRYPTED <<< We have successfully breached your system. Your critical files are now inaccessible. You have 72 hours to contact us. If you do not contact us and pay the ransom, your data will be PUBLISHED on our TOR website or SHARE and SOLD. You have 72 hours to contact us. ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– >>>Contact us now to our WebSite: You have 72 hours to contact us. 🔐 Your Personal Company CODE: >>> 01685fe8-4f79-40d3-9446-53383d093ccd <<< ✔Download TOR from https://www.torproject.org or https://xxxxxxxxxxxxxxxx ✔And access our WebSite: http://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– 📌 Another method to contact us now to:Tox ID – Support: 067B77E88F54A78E91C97B73F5A8F1426661CDFD7B3017D7643715C7A1FA5D1502C7AD1F52A5 ✔ Get the ransom price ✔ Receive working decryption software ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– 🟩 TOX SUPPORT (PRIMARY CONTACT METHOD): Tox ID – XLock Support: 067B77E88F54A78E91C97B73F5A8F1426661CDFD7B3017D7643715C7A1FA5D1502C7AD1F52A5 ▶ How to reach us via qTox: 1. Download qTox → https://xxxxxxxxxxxxxxxxxxxxx Or direct: https://xxxxxxxxxxxxxxxxxxxxxxxxxxxx 2. Install and create a username. 3. Copy your Tox ID. 4. Add our Tox ID and wait for approval. 5. Start chat and send us your message. ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– ⚠ IMPORTANT WARNINGS: ❗ Do NOT delete or rename encrypted files. Doing so may make recovery impossible. ❗ Ignoring this message will lead to: – Permanent loss of all data – Public data leaks – Repeated future attacks ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– 🛡 OUR GUARANTEE: We are not politically motivated. We only want financial compensation. If you pay: ✔ You will receive fully working decryption software. ✔ We will delete all your stolen data permanently. We value our **reputation**. If we don’t deliver, nobody would pay us. ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– 🔐 Your Personal CompanyCODE: >>> 01685fe8-4f79-40d3-9446-53383d093ccd <<< ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ⚠ BE WISE. TIME IS TICKING... YOUR FILES ARE WORTH MORE THAN MONEY ⚠ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

勒索信文件 : README lockbit.txt

~~~ LockBit 4.0 the world's fastest ransomware since 2019~~~ >>>> Your data are stolen and encrypted >>>> What guarantees that we will not deceive you? We are not a politically motivated group and we do not need anything other than your money. If you pay, we will provide you the programs for decryption and we will delete your data. Life is too short to be sad. Be not sad, money, it is only paper. If we do not give you decrypters, or we do not delete your data after payment, then nobody will pay us in the future. Therefore to us our reputation is very important. We attack the companies worldwide and there is no dissatisfied victim after payment. You can obtain information about us on twitter https://xxxxxxxxxxxxxxxxxxxxx >>>> you can contact us in mail or tox. Tox ID LockBitSupp: 66049CB849C457B325359CC17A6ADF558DAC3A911E29CE1C3EAD3D403C16E74FF8AEB5030A11 mail Support: lockaaaabbbbit@proton.me >>>> Your personal DECRYPTION ID: 373A04D048940414D2D27CB96D148A55 >>>> Warning! Do not DELETE or MODIFY any files, it can lead to recovery problems! >>>> Warning! If you do not pay the ransom we will attack your company repeatedly again! >>>> Advertisement Would you like to earn millions of dollars $$$ ? Our company acquire access to networks of various companies, as well as insider information that can help you steal the most valuable data of any company. You can provide us accounting data for the access to any company, for example, login and password to RDP, VPN, corporate email, etc. Open our letter at your email. Launch the provided virus on any computer in your company. You can do it both using your work computer or the computer of any other employee in order to divert suspicion of being in collusion with us. Companies pay us the foreclosure for the decryption of files and prevention of data leak. You can contact us using Tox messenger without registration and SMS https://xxxxxxxxxxxxxxxxxxxxx Using Tox messenger, we will never know your real name, it means your privacy is guaranteed. If you want to contact us, write in jabber or tox. Tox ID LockBitSupp: 66049CB849C457B325359CC17A6ADF558DAC3A911E29CE1C3EAD3D403C16E74FF8AEB5030A11 mail Support: lockaaaabbbbit@proton.me

勒索信文件 : Look at this instruction.txt

Your network systems were attacked and encrypted. Contact us in order to restore your data. Don't make any changes in your file structure: touch no files, don't try to recover by yourself, that may lead to it's complete loss. To contact us you have to download "tox" messenger: https://xxxxxxxxxxxxxxxxxxx Add user with the following ID to get your instructions: A4B3B0845DA242A64BF17E0DB4278EDF85855739667D3E2AE8B89D5439015F07E81D12D767FC Alternative way: swikipedia@onionmail.org Your ID: [snip] You should know that we have been downloading data from your network for a significant time before the attack: financial, client, business, post, technical and personal files. In 10 days - it will be posted at our site http://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxhttp://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx with links send to your clients, partners, competitors and news agencies, that will lead to a negative impact on your company: potential financial, business and reputational loses. ---!!!---

勒索信文件 : [rand].README.txt

[ TENGU ] --------- Ticket ID: [snip] Blog: http://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx To Management, If you are reading this, your company is at a critical juncture. The decisions you make in the next hours will determine its future. We are here to present the only viable path forward. Your Current Reality ├─ Your network infrastructure has been comprehensively compromised. ├─ All accessible backups—virtual and physical—have been securely wiped. └─ A significant volume of your most sensitive corporate data has been exfiltrated prior to encryption. The Path to Resolution ├─ We aim for a swift, discreet, and financially reasonable settlement. ├─ We will analyze your financial health to determine a fair demand. └─ If you have cyber insurance, inform us for guidance on the process. Benefits of Cooperation ├─ Your systems can be fully operational in approximately 24 hours after payment. ├─ Our decryptor is tested and guaranteed. Request a free decryption test for verification. └─ Paying us is cheaper than prolonged downtime and reputational damage. What You Must Not Do ├─ Do not modify, rename, or attempt to repair encrypted files. ├─ Do not shut down affected systems or run aggressive antivirus scans. ├─ Do not engage data recovery firms or third-party negotiators. └─ Do not delay. Time is your most valuable and depleting resource. The Stakes ├─ We possess: Corporate databases, financial records, legal documents, internal communications, and all backup sets. └─ Violating our terms will result in permanent destruction of decryption keys and public release of your data. Your Next Steps └─ Contact us via live chat to begin the process and request a decryption test. The clock is ticking. Your next move defines your outcome.

技术细节

LIVE病毒全版本样本分析已发布在微信公众号及各大平台,如有需要请自行查看。

威胁指标

ip地址

恶意IP地址

192.229.211.108

来源 : 项目捕获
首次录入 : 2024-03-08
最后更新 : 2026-09-01

ip地址

恶意IP地址

20.99.185.48

来源 : 项目捕获
首次录入 : 2024-03-08
最后更新 : 2026-09-01

IP地址

恶意IP地址

23.55.168.75

来源 : 项目捕获
首次录入 : 2024-03-08
最后更新 : 2026-09-01

MD5

恶意软件样本

0c029e5a29312f5af38087d77a8b881b

来源 : 项目捕获
首次录入 : 2025-03-08
最后更新 : 2026-09-01

sha256

恶意软件样本

e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

来源 : 第三方源捕获
首次录入 : 2025-10-23
最后更新 : 2026-09-01

受害者信息

暂无受害者记录。

MITRE ATT&CK

暴力破解

处置建议

  1. 优先核查远程接入(VPN/RDP)暴露面与弱口令,启用 MFA。

  2. 验证备份的离线可用性,确保备份不可被加密或删除。

  3. 及时清理高权限账号与可疑会话,排查 AD 域控异常。

  4. 结合 IOC 对历史日志、终端文件与网络连接进行回溯。

  5. 隔离疑似受影响资产,保留勒索信与样本供分析。

常见行业

中小企业
零售

常见入口

  • 钓鱼邮件
  • 暴露的 RDP 服务
  • 漏洞利用

操作协助

把热线、演示和资料入口拆开,让应急处置、产品评估和补充阅读各自清晰

电话咨询

出现加密、停摆或勒索提示时,优先直接联系应急响应团队。

400-613-6816

预约演练

如果你在评估产品、后台和家族库能力,可以先预约一个简短演示。

预约30分钟

查看资料

把文章、工具和方案入口集中到一起,方便团队继续同步研判。

进入资料中心

5000+

服务客户

99.8%

平均恢复率

<5min

首次响应

50+

安全专家