本帖最后由 AI-Compare 于 2026-9-2 20:02 编辑
https://www.solarsecurity.cn/family.html?id=33
勒索信的名称被挡住了,目前根据已展示信息
该勒索家族的已加密内容,解密难度非常困难
现在应该检查网站,系统,数据库等是否存在漏洞
安装并常驻杀毒软件,提防因漏洞未补勒索再造访
尽可能开启杀毒软件勒索诱捕功能,不要开放不必要端口,启用IP白名单
启用长亭雷池WAF类似防火墙产品,雇佣技术人员进行网站安全巡检备份
索勒相关分析帖子
【全网首发】Weax 与 Sorry 勒索病毒席卷全国中小企业,深度还原全链路攻击,疑似黑客利用 AI 挖掘管家婆 0day 漏洞
https://www.52pojie.cn/thread-2115892-1-1.html 2026-07-06 15:25
【病毒分析】新崛起的 weaxor 勒索家族:疑似 mallox 家族衍生版,深度解析两者关联!
https://www.52pojie.cn/thread-1992738-1-1.html 2024-12-19 16:45
索勒数据库关于该家族简述
created at:
2024-12-10 18:09:52
updated at:
2026-03-18 13:26:10
id:
22
virus family:
33
病毒家族:
weaxor
加密后缀:
.rx
wxx
.rox
.xor
.wxr
.001
.wxr
.wax
.wex
.weax <<<本次命中
.wexor
.weaxor
.roxaew
勒索信息:
FILE RECOVERY.txt
RECOVERY INFO.txt
RECOVERY INFORMATION.txt
常用邮箱:
serve@tuta.com
lazylazy@dnmx.su
lazylazy@tuta.com
datahelper@cyberfear.com <<<本次命中
目前OCR读取的勒索后缀名(已格式化)
zbintel117_erp_backup_2026_07_27_200001_4344872.bak.weax
zbintel117_erp_backup_2026_07_28_200001_3846649.bak.weax
目前OCR读取的勒索信内容(已格式化)
Your files have been encrypted To recover them you need decryption tool
You can contact us in two ways:
1 Download Browser
https://www. .org/dowmload
(in some cases required to dowmload)
2 Open browser and follow by link below:
http://weaxor .onion/1saHqOhaJLOyrVSPvtJajdzqrftqz01t/1CB7C3EB9D51C0AC7FDB4E2B2DB9519535D22E277E076E350A9DF791422FC3F2
3 or Contact by email:
datahelper@cyberfear.com
Your key:
1CB7C3EB9D51C0AC7FCDB4E2B2DB9519535D22E277E076E350A9DF791422FC3F
Include your key in your letter Our guarantee:
we provide free decyrption for 3 files up to 3 megabytes (not zip, db, backup)
|