<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>勒索病毒 :: 标签 :: x7peeps</title><link>https://x7peeps.com/tags/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><description/><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Sat, 20 Jun 2026 10:11:00 +0800</lastBuildDate><atom:link href="https://x7peeps.com/tags/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.xml" rel="self" type="application/rss+xml"/><item><title>1. 服务器存漏洞感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/1.%E6%9C%8D%E5%8A%A1%E5%99%A8%E5%AD%98%E6%BC%8F%E6%B4%9E%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:00:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/1.%E6%9C%8D%E5%8A%A1%E5%99%A8%E5%AD%98%E6%BC%8F%E6%B4%9E%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某医院服务器因MS17-010漏洞开放445端口，遭受永恒之蓝勒索病毒感染，部分文件被加密。</description></item><item><title>应急响应报告网站收集</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A%E7%BD%91%E7%AB%99%E6%94%B6%E9%9B%86/index.html</link><pubDate>Fri, 19 Jun 2026 09:00:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A%E7%BD%91%E7%AB%99%E6%94%B6%E9%9B%86/index.html</guid><description>收集互联网上可完整访问的真实安全事件应急响应分析报告，涵盖勒索病毒处置、Webshell入侵、钓鱼邮件、篡改挂马、DDoS攻击等具体案例，便于后续深入学习分析。</description></item><item><title>2. 终端电脑遭遇钓鱼邮件感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/2.%E7%BB%88%E7%AB%AF%E7%94%B5%E8%84%91%E9%81%AD%E9%81%87%E9%92%93%E9%B1%BC%E9%82%AE%E4%BB%B6%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:01:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/2.%E7%BB%88%E7%AB%AF%E7%94%B5%E8%84%91%E9%81%AD%E9%81%87%E9%92%93%E9%B1%BC%E9%82%AE%E4%BB%B6%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某电网公司办公终端遭遇sage2.2勒索病毒攻击，部分Office文档、图片文档、pdf文档多了sage后缀。</description></item><item><title>3. 工业生产网与办公网边界模糊，感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/3.%E5%B7%A5%E4%B8%9A%E7%94%9F%E4%BA%A7%E7%BD%91%E4%B8%8E%E5%8A%9E%E5%85%AC%E7%BD%91%E8%BE%B9%E7%95%8C%E6%A8%A1%E7%B3%8A%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:02:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/3.%E5%B7%A5%E4%B8%9A%E7%94%9F%E4%BA%A7%E7%BD%91%E4%B8%8E%E5%8A%9E%E5%85%AC%E7%BD%91%E8%BE%B9%E7%95%8C%E6%A8%A1%E7%B3%8A%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某大型制造企业因工业生产网与办公网边界模糊，WannaMine3.0和永恒之蓝勒索蠕虫变种感染大量主机。</description></item><item><title>4. 服务器配置不当感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/4.%E6%9C%8D%E5%8A%A1%E5%99%A8%E9%85%8D%E7%BD%AE%E4%B8%8D%E5%BD%93%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:03:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/4.%E6%9C%8D%E5%8A%A1%E5%99%A8%E9%85%8D%E7%BD%AE%E4%B8%8D%E5%BD%93%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某交通运输行业重要服务器因远程桌面端口直接映射公网且存在弱口令，感染Crysis勒索病毒变种。</description></item><item><title>5. 专网被攻击，58家医院连锁感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/5.%E4%B8%93%E7%BD%91%E8%A2%AB%E6%94%BB%E5%87%BB58%E5%AE%B6%E5%8C%BB%E9%99%A2%E8%BF%9E%E9%94%81%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:04:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/5.%E4%B8%93%E7%BD%91%E8%A2%AB%E6%94%BB%E5%87%BB58%E5%AE%B6%E5%8C%BB%E9%99%A2%E8%BF%9E%E9%94%81%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某地骨科医院爆发Globelmposte勒索病毒，攻击者利用卫生专网弱口令暴破3389端口，不到一天全省57家医院相继感染。</description></item><item><title>6. OA服务器远程桌面映射公网，感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/6.OA%E6%9C%8D%E5%8A%A1%E5%99%A8%E8%BF%9C%E7%A8%8B%E6%A1%8C%E9%9D%A2%E6%98%A0%E5%B0%84%E5%85%AC%E7%BD%91%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:05:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/6.OA%E6%9C%8D%E5%8A%A1%E5%99%A8%E8%BF%9C%E7%A8%8B%E6%A1%8C%E9%9D%A2%E6%98%A0%E5%B0%84%E5%85%AC%E7%BD%91%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某热电企业为方便运维将OA服务器远程桌面映射到公网且存在弱口令，感染Sodinokibi勒索病毒导致23个系统被加密。</description></item><item><title>7. 内网主机使用弱口令致感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/7.%E5%86%85%E7%BD%91%E4%B8%BB%E6%9C%BA%E4%BD%BF%E7%94%A8%E5%BC%B1%E5%8F%A3%E4%BB%A4%E8%87%B4%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:06:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/7.%E5%86%85%E7%BD%91%E4%B8%BB%E6%9C%BA%E4%BD%BF%E7%94%A8%E5%BC%B1%E5%8F%A3%E4%BB%A4%E8%87%B4%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某国有企业内网主机因IPC暴力破解、弱口令被攻破，感染Hermes837勒索病毒，多台机器文件被加密。</description></item><item><title>8. 8003端口映射在公网感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/8.8003%E7%AB%AF%E5%8F%A3%E6%98%A0%E5%B0%84%E5%9C%A8%E5%85%AC%E7%BD%91%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:07:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/8.8003%E7%AB%AF%E5%8F%A3%E6%98%A0%E5%B0%84%E5%9C%A8%E5%85%AC%E7%BD%91%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某医疗卫生行业应用服务器8003端口映射公网，被上传Webshell后投放Phobos家族勒索病毒，2台服务器和11台终端感染。</description></item><item><title>9. 私自下载破解软件致服务器感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/9.%E7%A7%81%E8%87%AA%E4%B8%8B%E8%BD%BD%E7%A0%B4%E8%A7%A3%E8%BD%AF%E4%BB%B6%E8%87%B4%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:08:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/9.%E7%A7%81%E8%87%AA%E4%B8%8B%E8%BD%BD%E7%A0%B4%E8%A7%A3%E8%BD%AF%E4%BB%B6%E8%87%B4%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某公司员工通过非官方渠道下载破解版软件导致个人电脑感染勒索病毒，再通过RDP暴破扩散至内网十余台服务器。</description></item><item><title>10. 服务器补丁安装不及时感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/10.%E6%9C%8D%E5%8A%A1%E5%99%A8%E8%A1%A5%E4%B8%81%E5%AE%89%E8%A3%85%E4%B8%8D%E5%8F%8A%E6%97%B6%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:09:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/10.%E6%9C%8D%E5%8A%A1%E5%99%A8%E8%A1%A5%E4%B8%81%E5%AE%89%E8%A3%85%E4%B8%8D%E5%8F%8A%E6%97%B6%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某药业公司服务器因补丁安装不及时，被境外恶意IP通过远程桌面登录感染fair勒索病毒。</description></item><item><title>11. 擅自修改网络配置致服务器感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/11.%E6%93%85%E8%87%AA%E4%BF%AE%E6%94%B9%E7%BD%91%E7%BB%9C%E9%85%8D%E7%BD%AE%E8%87%B4%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:10:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/11.%E6%93%85%E8%87%AA%E4%BF%AE%E6%94%B9%E7%BD%91%E7%BB%9C%E9%85%8D%E7%BD%AE%E8%87%B4%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某医疗行业运维人员为方便管理擅自修改网络配置，将RDP端口映射到公网，导致Phobos勒索病毒感染。</description></item><item><title>12. 用户名口令被暴力破解感染勒索病毒</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/12.%E7%94%A8%E6%88%B7%E5%90%8D%E5%8F%A3%E4%BB%A4%E8%A2%AB%E6%9A%B4%E5%8A%9B%E7%A0%B4%E8%A7%A3%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</link><pubDate>Sat, 20 Jun 2026 10:11:00 +0800</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/0x04%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94%E6%8A%A5%E5%91%8A/%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/12.%E7%94%A8%E6%88%B7%E5%90%8D%E5%8F%A3%E4%BB%A4%E8%A2%AB%E6%9A%B4%E5%8A%9B%E7%A0%B4%E8%A7%A3%E6%84%9F%E6%9F%93%E5%8B%92%E7%B4%A2%E7%97%85%E6%AF%92/index.html</guid><description>某政府部门运维人员为方便将3389端口映射公网，攻击者利用FRP代理暴破用户名口令，感染VoidCrypt勒索病毒。</description></item></channel></rss>