服务器只安装了Proxmox Virtual Environment
============================================================= !!! YOUR NETWORK HAS BEEN COMPROMISED !!! ============================================================= Hi there, If you are reading this, your company's internal computer system is down. All your backups — digital and physical — that we found have been deleted. We also stole a large amount of your company data before we locked your files. Let's talk calmly. We know we have caused serious problems for you. Here is what you need to know: Self-assess your company size (you tell us, we verify against the data we stole): Tier 1 — Personal (solo, single individual): starting quote: $2,000 Tier 2 — SOHO (1-10 staff, small office / home office): starting quote: $5,000 Tier 3 — Small business (11-50 staff): starting quote: $15,000 Tier 4 — Mid-market (51-500 staff): starting quote: $30,000 Tier 5 — Enterprise (500+ staff): starting quote: $60,000 Reply with your tier and we will provide a final quote based on your cyber insurance coverage and the data volume we have on you. If you under-report your company size, we will verify against the stolen data (employee records, internal email domains, financial documents). Lying will void any discount we offered. If we do not hear back in 72 hours, the price increases 50%. After payment is confirmed, the recovery process is: - Decryption tool delivery: within 24-48 hours - Full system recovery: 24-72 hours depending on your infrastructure size - Data deletion proof (recorded video): within 48 hours - Security report: within 7 days Our decryption tool works for all your files and systems. You can ask for a free test first to prove it works. If you try to recover files on your own, you might permanently lose or break some data, and we cannot help you then. After you pay, we will send you a security report. It will tell you the weak spots in your system that we used to break in. Your own security team or normal audits will never find these problems. If we cannot reach an agreement within 7 days: 1. Your entire dataset will be simultaneously distributed across multiple dark web leak sites and publicly auctioned: • darkforums.ru • breached.to • xss.is • leakbase.io • [additional rotating sites] We use a redundant multi-site distribution strategy — the takedown of any single site by law enforcement will not affect the accessibility of the others. Any visitor will be able to browse, preview and download the full archive. 2. We will contact your customers directly using your compromised email database 3. Your business partners will receive a breach notification from us, not from you 4. Relevant regulators (GDPR / SEC / local authorities) will be notified under your company's name A final and important clarification: • Engaging outside counsel or hiring a third-party incident-response firm will NOT accelerate resolution. The longer the communication chain and the wider the circle of trust, the higher the probability that your data leaks into the open. • Contacting law enforcement (FBI / Interpol / local cybercrime units) will NOT cause us to lower the price or release the data. We will treat it as a refusal to negotiate, and will immediately trigger every action listed in items 1-4 above. • The only controlled, quiet, and fast resolution is for you to negotiate with us directly. We have helped many organizations of similar size resolve this kind of incident with minimal fallout. We are open to negotiation. We can find a fast solution that works for both sides. ——————————————————————————————————————— NEGOTIATION ENTRY POINT (Keep Confidential — Do Not Share) ——————————————————————————————————————— Our negotiation site .onion address: [http://zdfepqzxnyjlkxumqdx2brtd2emgqyx75hmh6au4mle47eqky6ykrrad.onion] Registration invite code is at the bottom of the text (56-character v3 onion address — only resolvable via the Tor network) Once you reach the site, you will be prompted to register an account. Please use the following fields: • Username (required): Use your company's full legal name (e.g., Example Corporation, Inc.) — This username will serve as your unique negotiation identifier, and it cannot be changed or transferred. — We will verify the name in real time against the internal records we already hold — any impersonation will be detected immediately. • Primary domain (required): Enter your primary domain (e.g., example.com) — Used as a secondary identity-verification signal. • Company-size tier (required): Honestly select the Tier (1-5) that matches your organization. — If our stolen-data analysis identifies a larger organization than the Tier you self-report, you will lose the discount on this round of pricing. Once registration succeeds, the site will automatically load the negotiation interface tailored to your case, and will display a sample of your stolen data so you can verify its authenticity. ——————————————————————————————————————— If you want to fix this, please follow these steps: 1. Download and install the Tor Browser (https://www.torproject.org/ — free and open source, no phone verification required) 2. Open Tor Browser and visit our negotiation site at: (the .onion address shown in the "Negotiation Entry Point" section above) 3. Register an account on the site using your company's full legal name as the username, then submit your primary domain + Tier (1-5) + type of cyber insurance you carry (if any) 4. Once registered, you will gain access to your dedicated negotiation interface Please note: - Do NOT access our .onion site from your company network / IP address (your IT department may monitor outbound traffic and trace the source) - Do NOT visit the .onion site from a company computer during business hours - We only accept contact submitted via our .onion site. Any other channel (plaintext email, third-party intermediaries) will be ignored The sooner you contact us, the less damage you will take. Registration invite code: ahsbee183jsne