全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 635|回复: 3

【邮件附件要小心】大清早收到psychz的邮件,以为5刀机器无了

[复制链接]
发表于 2021-6-1 08:35:11 | 显示全部楼层 |阅读模式
本帖最后由 52mfzy 于 2021-6-1 08:36 编辑

rt,这邮件主题是Compromised Email - SERVER TERMINATION
看起来应该是员工都在远程办公,其中一个员工电脑被黑了,然后对外发送包含带毒附件的邮件?

Dear Psychz User,

It has come to our attention one of our employee's machine was compromised. Unfortunately this is one of the challenges when employees work remote during the pandemic. Policies were not follow and those are being re-visited while we continue our investigation.

We're reaching out to ensure you did not open the previous email's attachment. If it was opened please scan as well as see if there are processes that are unknown running within your windows task. So far we can see the exe file makes a request to a server in Bulgaria with IP -> 5.181.80.177 this is another method to see if you can see if you were compromised.

To know more about the file being sent to you this is what was posted - https://www.hybrid-analysis.com/sample/16b1d0cbb8eb4804ccedaed0abd454606f0d237abe3d4f8ac212ff3a027270c7/60b4e347e6e900384249f21c

In terms of the extent of the damage your billing information is safe such as your credit card, PayPal, or ach info are safe. There is no evidence of the billing being viewed or being downloaded.

Server credentials we should not have that information. Every single server provisioned are required to changed their password upon delivery of services. Thus we do not know or should have your password to your servers.

We apologize for this nuisance. Should you have any question or concerns please reach out.

机翻一下
亲爱的 Psychz 用户,

我们注意到我们员工的一台机器遭到破坏。不幸的是,这是员工在大流行期间远程工作时面临的挑战之一。没有遵循政策,在我们继续调查的同时,正在重新审视这些政策。

我们正在联系以确保您没有打开上一封电子邮件的附件。如果它被打开,请扫描并查看是否有未知进程在您的 Windows 任务中运行。到目前为止,我们可以看到 exe 文件使用 IP -> 5.181.80.177 向保加利亚的服务器发出请求,这是查看您是否受到威胁的另一种方法。

要了解有关发送给您的文件的更多信息,这是发布的内容 - https://www.hybrid-analysis.com/sample/16b1d0cbb8eb4804ccedaed0abd454606f0d237abe3d4f8ac212ff3a027270c7/60b4e3403216e4

就损坏程度而言,您的账单信息是安全的,例如您的信用卡、PayPal 或 ach 信息是安全的。没有证据表明正在查看或下载账单。

服务器凭据我们不应该有这些信息。提供的每台服务器都需要在提供服务时更改其密码。因此,我们不知道或不应该知道您的服务器密码。

对此造成的困扰,我们深表歉意。如果您有任何问题或疑虑,请联系。
发表于 2021-6-1 08:51:26 | 显示全部楼层
Psychz = 心灵 ?
亲爱的心灵用户,

它提出了我们的员工的一个员工妥协。
发表于 2021-6-1 08:55:52 来自手机 | 显示全部楼层
zxxx 发表于 2021-6-1 08:51
Psychz = 心灵 ?

机翻去z了 自动纠错
发表于 2021-6-1 08:58:18 | 显示全部楼层
Fliggy 发表于 2021-6-1 08:55
机翻去z了 自动纠错

原来是这个样子,学到一个单词
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-4-27 10:42 , Processed in 0.092003 second(s), 8 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表