Screenshot der Akira-Leakseite (Tor Hidden Service)
.LynxEncrypted (variabel generierte Endung) - Erweiterung verschlüsselter Dateien[RANDOM]-Lynx-README.txt - Erpressernachricht mit KontaktinformationenSHA-256:
9d52fc6efc8f23a8a3fca79e5d7b493f6bfb0210e2e3a02b0f843cbf61d3e9d01f6c01ad43f139e560b14a405f3e021b83d020a7124538a6c2fd74d1d0e534d6
vssadmin delete shadows /all /quiet
bcdedit /set {current} safeboot minimal
wmic shadowcopy delete
netsh advfirewall set allprofiles state off
taskkill /f /im sqlwriter.exe
schtasks /change /tn "Microsoft\\Windows\\Defrag\\ScheduledDefrag" /disable
sc stop VeeamTransportSvc
sc stop BackupExecAgentAccelerator
AnyDeskRustDesklynxsec2cj32jhdzxx75bcx2acp75tthoyg5ji7ilf4qgwe3l3akssyd.onionlynxblogxutufossaeawlij3j3uikaloll5ko6grzhkwdclrjngrfoid.onionlynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onionlynxblogmx3rbiwg3rpj4nds25hjsnrwkpxt5gaznetfikz4gz2csyad.onionlynxblogco7r37jt7p5wrmfxzqze7ghxw6rihzkqc455qluacwotciyd.onionlynxblogijy4jfoblgix2klxmkbgee4leoeuge7qt4fpfkj4zbi2sjyd.onionlynxblogtwatfsrwj3oatpejwxk5bngqcd5f7s26iskagfu7ouaomjad.onionT1078 - Valid Accounts (z.B. RDP ohne MFA), T1133 - External Remote ServicesT1059 - Command and Scripting Interpreter (PowerShell, CMD)T1547 - Boot or Logon Autostart ExecutionT1068 - Exploitation for Privilege EscalationT1562 - Impair Defenses (Deaktivierung AV, Löschung Shadow Copies)T1003 - OS Credential Dumping (z.B. LaZagne, mimikatz)T1087 - Account Discovery, T1018 - Remote System DiscoveryT1021 - Remote Services (SMB, WinRM)T1119 - Automated CollectionT1041 - Exfiltration Over C2 Channel (Rclone, MegaCLI)T1486 - Data Encrypted for Impact, T1490 - Inhibit System Recovery
Your data is stolen and encrypted.
Your unique identificator is [snip]
Use this TOR site to contact with us:
http://lynxch2k5xi35j7hlbmwl7d6u2oz4vp2wqp6qkwol624cod3d6iqiyqd.onion/login
Use this email to contact with us:
martina.lestariid1898@proton.me
Our blog
~ TOR Network: http://lynxbllrfr5262yvbgtqoyq76s7mpztcqkv6tjjxgpilpma7nyoeohyd.onion/disclosures
~ Mirror #1: http://lynxblog.net/
Your data is stolen and encrypted.
Download TOR Browser to contact with us.
ID
~ [snip]
Chat site:
~ TOR Network: http://lynxchatly4zludmhmi75jrwhycnoqvkxb4prohxmyzf4euf5gjxroad.onion/login
~ TOR Mirror #1: http://lynxchatfw4rgsclp4567i4llkqjr2kltaumwwobxdik3qa2oorrknad.onion/login
~ TOR Mirror #2: http://lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion/login
~ TOR Mirror #3: http://lynxchatbykq2vycvyrtjqb3yuj4ze2wvdubzr2u6b632trwvdbsgmyd.onion/login
~ TOR Mirror #4: http://lynxchatde4spv5x6xlwxf47jdo7wtwwgikdoeroxamphu3e7xx5doqd.onion/login
~ TOR Mirror #5: http://lynxchatdy3tgcuijsqofhssopcepirjfq2f4pvb5qd4un4dhqyxswqd.onion/login
~ TOR Mirror #6: http://lynxchatdykpoelffqlvcbtry6o7gxk3rs2aiagh7ddz5yfttd6quxqd.onion/login
~ TOR Mirror #7: http://lynxch2k5xi35j7hlbmwl7d6u2oz4vp2wqp6qkwol624cod3d6iqiyqd.onion/login
Our blog:
~ TOR Network: http://lynxblogxstgzsarfyk2pvhdv45igghb4zmthnzmsipzeoduruz3xwqd.onion/
~ TOR Mirror #1: http://lynxblogco7r37jt7p5wrmfxzqze7ghxw6rihzkqc455qluacwotciyd.onion/
~ TOR Mirror #2: http://lynxblogijy4jfoblgix2klxmkbgee4leoeuge7qt4fpfkj4zbi2sjyd.onion/
~ TOR Mirror #3: http://lynxblogmx3rbiwg3rpj4nds25hjsnrwkpxt5gaznetfikz4gz2csyad.onion/
~ TOR Mirror #4: http://lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion/
~ TOR Mirror #5: http://lynxblogtwatfsrwj3oatpejwxk5bngqcd5f7s26iskagfu7ouaomjad.onion/
~ TOR Mirror #6: http://lynxblogxutufossaeawlij3j3uikaloll5ko6grzhkwdclrjngrfoid.onion/
~ Mirror #7: http://lynxblog.net/
Dateiendung(en): *.LynxEncrypted (variabel pro Angriff)
Ransom Note: *-Lynx-README.txt
Leak Site (Tor): lynxsec2cj32jhdzxx75bcx2acp75tthoyg5ji7ilf4qgwe3l3akssyd.onion
Verdächtige Prozesse: psexesvc.exe, sqlwriter.exe, defrag.exe
Remote Tools: AnyDesk, RustDesk, WinSCP
Command-Line IOCs:
- vssadmin delete shadows /all /quiet
- bcdedit /set {current} safeboot minimal
- wmic shadowcopy delete
- netsh advfirewall set allprofiles state off
- schtasks /change /tn \"Microsoft\Windows\Defrag\ScheduledDefrag\" /disable
- sc stop VeeamTransportSvc
Hash-Beispiel (SHA256):
- 9d52fc6efc8f23a8a3fca79e5d7b493f6bfb0210e2e3a02b0f843cbf61d3e9d0
- 1f6c01ad43f139e560b14a405f3e021b83d020a7124538a6c2fd74d1d0e534d6