勒索信文件 : readme.txt
############################################################################### !!!!!!!!!!!! THE FILES ON YOUR DEVICE HAVE BEEEN ENCRYPTED !!!!!!!!!!!!!! ############################################################################### Due to a security breach, all files on your computer have been encrypted, for decryption, send an email to us: Be sure to specify this ID in the header of the letter when contacting us: vfpFIU7U To decrypt your files, you will need to pay a certain amount in bitcoins.The decryption rate depends on the speed of your computer. After payment, you will receive a special tool for decrypting fileson your computer. ####################################### As a guarantee, we make a free decryption #######################################


验证后进入模式选择,加密方式:
加密内容:
如果选第三个选项 Encrypt multiselect 会额外选择一次要加密的存储设备
选择完毕后会根据选择的模式进行文件加密,加密公钥如下
加密后还会生成一条受害者信息,将该信息发送到攻击者的 MySQL 数据库中,首先连接数据库 94.232.249.179:3306:
通过内存中解密的账号密码登录数据库:
向数据库插入生成的受害者信息,包括随机生成的 company_id、计算机名、指定联系的邮箱等信息
生成的勒索信如下:
