¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«ÃæÆÊÎö

Ðû²¼Ê±¼ä 2019-04-25

1¡¢¸Å Êö


    ½üÈÕ £¬¶¶È¦Îª¶Ä¶øÉúADLab²¶×½µ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ £¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3 £¬±àÒëʱ¼äΪ4ÔÂ14ÈÕ £¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁÅ°½ö½öÒ»¸ö¶àÔ¡£¡°ÏÀµÁ¡±V5.2¿ªÊ¼ËÁÅ°ÖйúµÄʱ¼äΪ3ÔÂ11ÈÕ £¬²¢ÒÑѬȾÁËÎÒ¹úÉÏǧ̨Õþ¸®¡¢ÆóÒµºÍÏà¹Ø¿ÆÑлú¹¹µÄ¼ÆËã»ú¡£ºþ±±Ê¡Ò˲ýÊÐÒÄÁêÇøÕþ¸®¡¢Öйú¿ÆѧԺ½ðÊôÑо¿Ëù¡¢ÔÆÄÏʦ·¶´óѧÒÔ¼°´óÁ¬Êй«°²¾ÖµÈ»ú¹¹¾ùÔÚÆä¹ÙÍøÐû²¼ÁË·À·¶²¡¶¾¹¥»÷µÄͨ¸æ¡£


    ¡°ÏÀµÁ¡±²¡¶¾µÄµÚÒ»¸ö°æ±¾µ®ÉúÓÚ2018Äê1Ô £¬Ä¿Ç°ÎªÖ¹ £¬ÒѾ­¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öС°æ±¾¡£ÆäÖ÷ҪĿµÄÊÇͨ¹ý¼ÓÃÜÊܺ¦Óû§µÄ¼ÆËã»úÎļþÀ´¶ÔÊܺ¦Óû§½øÐÐÀÕË÷¡£¡°GandCrab¡±ÀÕË÷²¡¶¾Ö®ËùÒÔ±»È˳ÆΪ¡°ÏÀµÁ¡± £¬ÊÇÒòΪÆäÔø¾­¡°È˵ÀµØ¡±ÎªÎÞÁ¦Ö§¸¶¡°Êê½ð¡±µÄÐðÀûÑǸ¸Ç×½âÃÜÁËÆäÔÚÕ½ÕùÖÐÉ¥ÉúµÄ¶ù×ÓµÄÕÕƬ £¬²¢·Å³öÁ˲¿ÃÅÐðÀûÑǵØÓò֮ǰ°æ±¾µÄ½âÃÜÃÜÔ¿ £¬»¹½«ÐðÀûÑÇÒÔ¼°ÆäËûÕ½ÂÒµØÓò¼Ó½øѬȾÇøÓò¡°°×Ãûµ¥¡±¡£


¡°ÏÀµÁ¡±»á½«Óû§Îļþ¼ÓÃܺóÌí¼ÓÉÏÀÕË÷ºó׺Ãû £¬È»ºóÔÙ¸ü»»Ñ¬È¾ÏµÍ³µÄ×ÀÃæΪÀÕË÷ͼƬ £¬ÀÕË÷ͼƬÉϵÄÎÄ×ÖÌáʾÊܺ¦Óû§ÔĶÁÆäÀÕË÷ÊÖ²áÎı¾Îļþ,ÔÚÀÕË÷ÊÖ²áÎı¾ÎļþÖнøÒ»²½Òýµ¼Êܺ¦Óû§Êê»ØÓû§Îļþ¡£ÔÚ5.2֮ǰµÄ°æ±¾ÖÐ £¬ÀÕË÷ÊÖ²áÎļþÒýµ¼Êܺ¦Óû§Í¨¹ýTorÍøÂçÊê»ØÎļþ £¬Êê½ðÖ§³Ö´ïÊÀ±ÒºÍ±ÈÌرÒÖ§¸¶ £»¶øÔÚ×îеÄ5.3°æ±¾ÖÐ £¬ÀÕË÷ÊÖ²áÖÐÖ»¸ø³öÁ˺ڿ͵ÄÓÊÏä £¬ÒªÇóÊܺ¦ÕßÓʼþÁªÏµËûÃÇ £¬³ýÁËÕâÒ»µã±ä»¯ £¬¡°ÏÀµÁ¡±5.3»¹¸üÐÂÁ˺ڿ͹«Ô¿¡£Ä¿Ç°Éв»Çå³þGandcrab5.3ÀÕË÷²¡¶¾¿ÉÄÜ»áÒªÇó½âÃÜÕßÖ§¸¶¼¸¶àÇ® £¬µ«Ö®Ç°µÄ°æ±¾ÒªÇóÔÚ±ÈÌرһò´ïÊÀ±ÒÉÏÖ§¸¶500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£


2¡¢²¡¶¾Á÷´«


    ¡°ÏÀµÁ¡±²¡¶¾Á÷´«Í¾¾¶Ö÷ÒªÓÐRDP¡¢VNC;¾¶½øÐб©Á¦ÆƽâºÍÈëÇÖ¡¢¶¨ÏòÓã²æµöÓãÓʼþͶ·Å¡¢À¦°ó¶ñÒâÈí¼þºÍÍøÒ³¹ÒÂí¹¥»÷¡¢½©Ê¬ÍøÂçÒÔ¼°Â©¶´ÀûÓÃÁ÷´«µÈ¡£


    Ä¿Ç°ÔÚ°µÍøÖÐ £¬¡°ÏÀµÁ¡±Ä»ºóÍŶӽÓÄÉ¡°ÀÕË÷¼´·þÎñ¡±£¨¡°ransomware as-a-service¡± £©µÄ·½Ê½ £¬ÏòºÚ¿Í·ÅËÁÊÛÂôV5.3°æ±¾²¡¶¾ £¬¼´ÓÉ¡°ÏÀµÁ¡±ÍŶÓÌṩ²¡¶¾ £¬ºÚ¿ÍÔÚÈ«ÇòÑ¡ÔñÄ¿±ê½øÐй¥»÷ÀÕË÷ £¬¹¥»÷ÀÖ³Éºó ¡°ÏÀµÁ¡±ÍŶÓÔÙ´ÓÖгéÈ¡30%-40%µÄÀûÈ󡣡°À¬»øÓʼþÖÆÔìÕßÃÇ £¬ÄãÃÇÏÖÔÚ¿ÉÒÔÓëÍøÂçר¼Ò½øÐкÏ×÷ £¬²»Òª´íʧ»ñÈ¡ÃÀºÃÉú»îµÄÃÅƱ £¬ÎÒÃÇÔÚµÈÄã¡£¡±ÊÇ¡°ÏÀµÁ¡±ÍŶÓÔÚ°µÍøÖдò³öµÄ¡°ÕÐÉ̹ã¸æ¡±¡£


¡°ÏÀµÁ¡±ÊÇÄ¿Ç°µÚÒ»¸öÀÕË÷´ïÊÀ±ÒµÄÀÕË÷²¡¶¾ £¬ºóÀ´²Å¼ÓÁ˱ÈÌØ±Ò £¬Òª¼Û500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£¾Ý¡°ÏÀµÁ¡±ÍŶÓ2018Äê12ÔÂÐû²¼µÄÊý¾Ý £¬Æä×ܼÆÊÕÈë±ÈÌرÒÒÔ¼°´ïÊÀ±ÒºÏ¼ÆÒѸߴï285ÍòÃÀÔª¡£


3¡¢ÆƽâÀúÊ·


    Ïñ´ó²¿ÃÅÀÕË÷ÎļþÒ»Ñù £¬¡°ÏÀµÁ¡±Ê¹ÓÃÁËRSA¼ÓÃÜËã·¨ £¬³ý·ÇÄõ½ºÚ¿Í³ÖÓеÄRSA-2048˽Կ £¬²ÅÆø¹»¶ÔѬȾÎļþ½øÐнâÃÜ £¬·ñÔòÎÞ·¨½âÃÜ¡£


    ÒòΪ¡°ÏÀµÁ¡±Ê¼þ £¬¹¥»÷Õ߷ųöÁËÀÕË÷²¡¶¾²¿ÃÅÔçÆÚ°æ±¾µÄ½âÃÜÃÜÔ¿ £¬¶à¸öÄþ¾²³§ÉÌËæºóÏà¼ÌÐû²¼Á˽âÃܹ¤¾ß¡£´Ó18Äê10Ôµ½½ñÄê2Ô £¬BitdefenderÏȺóÐû²¼ÁË¡°ÏÀµÁ¡±¶à¸ö°æ±¾µÄ½âÃܹ¤¾ß £¬×îеĽâÃܹ¤¾ßÏÂÔصØַΪ£ºhttps://labs.bitdefender.com/wp-content/uploads/downloads/gandcrab-removal-tool-v1-v4-v5/ £¬¸Ã¹¤¾ß¿ÉÒÔ½âÃܵİ汾Èç±í1Ëùʾ¡£Æä½âÃÜÔ­ÀíÊÇͨ¹ýÔÚÏßÏòBitdefender·þÎñÆ÷Ìá½»¼ÓÃÜID £¬À´»ñÈ¡¿ÉÓõĽâÃÜ˽Կ£¨ RSA-2048£©À´½øÐнâÃÜ¡£Óû§¿ÉÒÔƾ¾Ý±íÖеļÓÃÜÎļþºó׺»òÀÕË÷˵Ã÷Îı¾ÎļþµÄ¿ªÊ¼À´ºË¶Ô²¡¶¾°æ±¾¡£



ÇøÓò±êÖ¾·û

ÓïÑÔ£¨¹ú¼Ò£©

0x419

¶íÓ¶íÂÞ˹£©

0x422

ÎÚ¿ËÀ¼ÓÎÚ¿ËÀ¼£©

0x423

°×¶íÂÞ˹Ó°×¶íÂÞ˹£©

0x428

Ëþ¼ª¿Ë

0x42B

ÑÇÃÀÄáÑÇÓÑÇÃÀÄáÑÇ£©

0x42C

°¢ÔóÀïÓ°¢Èû°Ý½® £¬À­¶¡Ó

0x437

¸ñ³¼ªÑÇÓ¸ñ³¼ªÑÇ£©

0x43F

¹þÈø¿ËÓ¹þÈø¿Ë˹̹£©

0x440

¼ª¶û¼ªË¹Ó¼ª¶û¼ªË¹Ì¹£©

0x442

ÍÁ¿âÂü

0x443

ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹ £¬À­¶¡Ó

0x444

÷²÷°Ó¶íÂÞ˹£©

0x818

ÂÞÂíÄáÑÇÓĦ¶û¶àÍßµØÓò£©

0x819

¶íÓĦ¶û¶àÍßµØÓò£©

0x82C

°¢ÔóÀïÓ°¢Èû°Ý½® £¬Î÷Àï¶ûÓ

0x843

ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹ £¬Î÷Àï¶ûÓ

0x45A

ÐðÀûÑÇÓÐðÀûÑÇ£©

0x2801

°¢À­²®ÓÐðÀûÑÇ£©



±í2 ÅųýµÄÓïÑÔ£¨¹ú¼Ò£©


5.2 ÖÕÖ¹Äþ¾²Èí¼þ



¡°ÏÀµÁ¡±±éÀúѬȾÉ豸ϵͳ½ø³Ì £¬Èç¹û·¢ÏÖѬȾÉ豸ÓÐÔËÐп¨°Í˹»ù¡¢Åµ¶ÙµÈÄþ¾²Èí¼þ £¬¾ÍÇ¿ÖƽáÊøµôÄ¿±ê½ø³Ì £¬·ÀÖ¹×Ô¼º±»É±¶¾Èí¼þ²éɱ¡£Ïà¹ØµÄÄþ¾²Èí¼þÈçÏÂͼ4Ëùʾ¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ4 Ïà¹ØÄþ¾²Èí¼þ½ø³Ì



5.3 ÖÕÖ¹Ìض¨·¨Ê½



¡°ÏÀµÁ¡±»á±éÀúѬȾÉ豸ϵͳµ±Ç°½ø³ÌÁбí £¬Èç¹ûÆ¥Åäµ½Ö¸¶¨µÄ½ø³ÌÔò½áÊø¸Ã½ø³Ì £¬ÒÔ·ÀÖ¹ÒÅ©µôÒòÓû§Îļþ±»Õ¼Óöø²»Äܱ»¼ÓÃܵÄÓû§Îļþ¡£ÈçWord¡¢Excel¡¢PowerPoint¡¢Onenote¡¢Visio¡¢Oracle¡¢SQLserver¡¢MySQLµÈ³£¼ûÓ¦Óýø³Ì £¬ÏêϸĿ±ê½ø³ÌÈçͼ5Ëùʾ£º

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ5 ÖÕÖ¹µÄÄ¿±ê½ø³Ì


5.4 È·¶¨¼ÓÃÜÎļþÀàÐÍ


5.4.1 Îļþºó׺°×Ãûµ¥


ΪÁËÅųýµôûÓмÛÖµµÄÀÕË÷Êý¾ÝÎļþ £¬¡°ÏÀµÁ¡±ÄÚÖÃÁËÒ»·ÝÎļþºó׺°×Ãûµ¥ £¬Èçͼ6Ëùʾ¡£ÎÒÃǽ«ÆäÁе½±í3ÖÐ £¬ÆäÖаüÂÞµÄÎļþÓпÉÖ´ÐÐÎļþ¡¢ÏµÍ³¶¯Ì¬µ÷ÓÿâÎļþ¡¢ÏµÍ³Çý¶¯ÎļþºÍ¡°ÏÀµÁ¡±Ïà¹ØµÄÎļþµÈ¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ6 ²»¼ÓÃܵÄÎļþÀàÐÍ


°×Ãûµ¥Â·¾¶

"\\ProgramData\\"

"\\IETldCache\\"

"\\Boot\\"

"\\Program Files\\"

"\\Tor Browser\\"

"\\All Users\\"

"\\Local Settings\\"

"\\Windows\\"




±í4 ϵͳĿ¼°×Ãûµ¥


±í5ÖеÄϵͳÎļþÒ²²»ÔÚ¼ÓÃÜÄ¿±êÖ®ÁУº



¼ÓÃܵÄÎļþºó׺

.1st  .602 .docb .xlm .xlsx .xlsm .xltx .xltm .xlsb .xla .xlam .xll .xlw .ppt .pot  .pps .pptx .pptm

.potx  .potm .ppam .ppsx .ppsm .sldx .sldm .xps .xls .xlt ._doc .dotm ._docx .abw  .act .adoc .aim

.ans  .apkg .apt .asc .asc .ascii .ase .aty .awp .awt .aww .bad .bbs .bdp .bdr  .bean .bib .bib .bibtex

.bml  .bna .boc .brx .btd .bzabw .calca .charset .chart .chord .cnm .cod .crwl .cws  .cyi .dca .dfti

.dgs  .diz .dne .dot .doc .docm .dotx .docx .docxml .docz .dox .dropbox .dsc .dvi  .dwd .dx .dxb .dxp

.eio  .eit .emf .eml .emlx .emulecollection .epp .err .err .etf .etx .euc  .fadein.template .faq .fbl

.fcf  .fdf .fdr .fds .fdt .fdx .fdxt .fft .fgs .flr .fodt .fountain .fpt .frt .fwd  .fwdn .gmd .gpd

.gpn  .gsd .gthr .gv .hbk .hht .hs .hwp .hwp .hz .idx .iil .ipf .ipspot .jarvis  .jis .jnp .joe .jp1

.jrtf  .jtd .kes .klg .klg .knt .kon .kwd .latex .lbt .lis .lnt .log .lp2 .lst .lst  .ltr .ltx .lue

.luf  .lwp .lxfml .lyt .lyx .man .mbox .mcw .md5 .me .mell .mellel .min .mnt .msg  .mw .mwd .mwp

.nb  .ndoc .nfo .ngloss .njx .note .notes .now .nwctxt .nwm .nwp .ocr .odif .odm  .odo .odt .ofl .opeico

.openbsd  .ort .ott .p7s .pages .pages-tef .pdpcmd .pfx .pjt .plain .plantuml .pmo .prt  .prt .psw .pu

.pvj  .pvm .pwd .pwdp .pwdpl .pwi .pwr .qdl .qpf .rad .readme .rft .ris .rpt .rst  .rtd .rtf .rtfd .rtx

.run  .rvf .rzk .rzn .saf .safetext .sam .sam .save .scc .scm .scriv .scrivx .sct  .scw .sdm .sdoc .sdw

.se  .session .sgm .sig .skcard .sla .sla.gz .smf .sms .ssa .story .strings .stw  .sty .sublime-project

.sublime-workspace  .sxg .sxw .tab .tab .tdf .tdf .template .tex .text .textclipping .thp .tlb  .tm .tmd

.tmdx  .tmv .tmvx .tpc .trelby .tvj .txt .u3i .unauth .unx .uof .uot .upd .utf8  .utxt .vct .vnt .vw

.wbk  .webdoc .wn .wp .wp4 .wp5 .wp6 .wp7 .wpa .wpd .wpd .wpd .wpl .wps .wps .wpt  .wpt .wpw

.wri  .wsd .wtt .wtx .xbdoc .xbplate .xdl .xdl .xwp .xwp .xwp .xy .xy3 .xyp .xyw  .zabw .zrtf .zw.rar

.zip  .cab .arj .lzh .tar .7z .gzip .iso .z .7-zip .lzma .vmx .vmdk .vmem .vdi .vbo



±í6 ¼ÓÃܵÄÎļþºó׺



5.5 ¼ÓÃÜÓû§Îļþ



¡°ÏÀµÁ¡±»á±éÀúѬȾÉ豸¹²ÏíĿ¼ºÍµ±µØ´ÅÅÌ¡£½ÓÄÉRSA-2048+Salsa20Ëã·¨¼ÓÃÜѬȾÉ豸Îļþ¡£
¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþÈçͼ8Ëùʾ£º


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ8 ¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþ


¼ÓÃܵ±µØ´ÅÅÌĿ¼ÏÂÎļþÈçͼ9Ëùʾ£º


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ9 ¼ÓÃܵ±µØ´ÅÅÌĿ¼ÏÂÎļþ



5.6 Éú³ÉMANUALÎļþ


¡°ÏÀµÁ¡±ÏȽ«ÀÕË÷ÐÅÏ¢½âÃܵ½ÄÚ´æÖÐ £¬ÔÚ½øÐа汾ºÍºó׺ÐÅϢƴ½Óºó £¬½«Õû¸öÀÕË÷ÐÅϢдÈëMANUALÎļþÖÐ £¬Èçͼ10ºÍͼ11Ëùʾ£º

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ10 ´´½¨MANUALÎļþ £¬Ð´ÈëÀÕË÷ÐÅÏ¢


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ11 ½âÃܵ½ÄÚ´æÖеÄÀÕË÷ÐÅÏ¢


    ×îÖÕµÄMANUALÎļþÓÉÀÕË÷ÐÅÏ¢¡¢¼ÓÃܺóµÄ˽ԿÐÅÏ¢ºÍ¼ÓÃܺóµÄѬȾÉ豸ÐÅÏ¢×é³É¡£ÆäÖкڿÍÌØÒâÇ¿µ÷Êܺ¦Óû§²»ÒªÐÞ¸Ä˽ԿÐÅÏ¢ÄÚÈÝ £¬ÒòΪһµ©Ë½Ô¿ÐÅÏ¢Ò»µ©±»¸Ä±ä £¬¾ÍÎÞ·¨¶ÔÎļþ½øÐнâÃÜ¡£



5.7 Ì滻ѬȾÉ豸×ÀÃæ


´´½¨ÀÕË÷×ÀÃæ±ÚÖ½µ½¡°C:\Documents and Settings\[username]\LocalSettings\Temp\bxmeoengtf.bmp¡±,Èçͼ12Ëùʾ£º


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ12 ´´½¨ÀÕË÷ͼƬ £¬ÉèÖÃÀÕË÷×ÀÃæ


ͼ13ÖÐ £¬ÀÕË÷ͼƬÉÏдÓС°YOURFILES ARE UNDER STRONG PROTECTION BY OUR SOFTWARE. IN ORDER TO RESTORE IT YOUMUST BUY DECRYPTOR £¬For further stepsread %s-DECRYPT.%s that is located in every encrypted folder¡± £¬ÌáʾѬȾÓû§ÔĶÁManualÎļþÖ§¸¶Êê½ð¡£


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ13 ÀÕË÷±ÚÖ½



5.8 ɾ³ý¾íÓ°¿½±´


¡°ÏÀµÁ¡±»áɾ³ýѬȾ¼ÆËã»ú¾íÓ°¸±±¾ £¬ÕâÊÇÀÕË÷²¡¶¾µÄͨÀý²Ù×÷ £¬ÕâÑù×öµÄÄ¿µÄÊÇ·ÀÖ¹Êܺ¦Óû§Í¨¹ýWindows Recovery¶ÔÎļþ½øÐлָ´ £¬Èçͼ14¡£


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ14 ɾ³ý¾íÓ°¸±±¾


Èçͼ15 £¬¡°ÏÀµÁ¡±µ÷Óá°shell32.ShellExecuteW¡±Ö´ÐÐÃüÁî¡°/c vssadmin delete shadows /all /quiet¡±


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ15 Ö´ÐÐɾ³ýÃüÁî



5.9 Á¬½ÓC&C


¡°ÏÀµÁ¡±»á·ÃÎÊÖ¸¶¨ÓòÃûµÄ80ºÍ443¶Ë¿Ú £¬¡°ÏÀµÁ¡±ÔÚÁ¬½ÓºÚ¿Í¿ØÖƵÄÔ¶³Ì·þÎñÆ÷£¨Èçhttp://www.kakaocorp.link£©Àֳɺó £¬ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍѬȾÉ豸ÐÅÏ¢ £¬Èçͼ16¡£


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ16 ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍѬȾÉ豸ÐÅÏ¢



ÆäÖÐ £¬rc4keyΪ".oj=294~!z3)9n-1,8^)o((q22)lb$"
strPCdataÉú´æÔÚ¡±*-MANUAL.txt¡±ÎļþÖУ¨*ÌåÏÖ´óдµÄ¼ÓÃÜÎļþºó׺Ãû£© £¬¼ûͼ18£º


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ18 Base64´æ´¢µÄPCÏà¹ØÃÜÎÄÐÅÏ¢


        ÓÉÓÚC&CʧЧ £¬ËùÓÐÎÒÃÇûÓÐ×¥µ½·¢ËÍ·¢ËÍstrPCdataµÄÊý¾Ý°ü¡£



6.2 ½âÃÜpubkey


¡°ÏÀµÁ¡±ÏÈÉú³É64×Ö½ÚÁ÷input3£¨ÓÉSalsakey3£¨ÀιÌ×Ö½Ú£©ºÍIV3£¨ÀιÌ×Ö½Ú£©ºÍ³£Á¿×é³É£© £¬Èçͼ19:


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ19 Éú³ÉµÄinput3


        ¡°ÏÀµÁ¡±ÔÚʹÓÃSalsa20Ëã·¨½âÃܺڿ͵ÄRSA2048¹«Ô¿ £¬ÎÒÃǽ«¹«Ô¿ÃÜÎļÇΪpubkeyEncrypted £¬½«½âÃܺóµÄ¹«Ô¿¼ÇΪhackerPubkey £¬Ëã·¨ÈçÏ£º



hackerPubkey=  Salse20(input3, pubkeyEncrypted)


hackerPubkeyEncrypted¼ûͼ20£º



×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ20 ½âÃÜÇ°µÄhackerPubkey


½âÃܵõ½hackerPubkey¼ûͼ21 £¬¶Ô±È¡°ÏÀµÁ¡±5.2µÄºÚ¿Í¹«Ô¿£¨Í¼22£© £¬ÎÒÃÇ·¢ÏÖÔÚ5.3°æ±¾Öкڿ͸üÐÂÁËÆä³ÖÓеĹ«Ô¿¡£


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ21 GandCrab5.3½âÃܺóµÄ¹«Ô¿


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ22 GandCrab5.2 ºÚ¿Í¹«Ô¿



6.3 µ±µØÉú³ÉRSA¹«Ë½«h¶Ô


        ºÚ¿ÍÀûÓÃ΢Èí¡°advapi32¡±¿âº¯Êýµ±µØÉú³ÉRSA-2048¹«Ë½«h¶Ô £¬ÎÒÃÇ·Ö±ð¼ÇΪlocPubkeyºÍlocPrikey £¬Õë¶Ôÿ¸öѬȾÕßµ±µØ¹«Ë½«h¶ÔÖ»Éú³ÉÒ»´Î¡£ÆäÖÐ £¬locPubkeyÓÃÓÚ¼ÓÃÜSalsaFileKeyºÍIV2 £¬¶ølocPrikeyʹÓÃSalsa20Ëã·¨¼ÓÃܺó×îÖÕÉú´æµ½µ±µØ¡£


locPubkey£¨0x114×Ö½Ú£©¼ûͼ23:

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ23 ÄÚ´æÖеÄlocPubkey


locPrikey£¨0x494×Ö½Ú£©¼ûÏÂͼ24£º


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ24 ÄÚ´æÖеÄlocPrikey



6.4 ¼ÓÃܵ±µØ˽Կ


        ¡°ÏÀµÁ¡±Ê×ÏÈÉú³ÉSalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£© £¬Ôٺͳ£Á¿Ò»ÆðÉú³É64×Ö½ÚÊäÈëÁ÷ £¬ÎÒÃǼÇΪinput1 £¬È»ºó £¬¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜlocPrikey £¬Ëã·¨ÈçÏ£º


data3  = Salsa20(input1,locPrikey)


        SalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©·Ö±ð±»ºÚ¿ÍµÄ¹«Ô¿¼ÓÃÜ £¬ÈçÏÂ:


data1= RSA2048(hackerPubkey, SalsaKey)

data2 = RSA2048(hackerPubkey, IV1)


        ×îºó £¬¡°ÏÀµÁ¡±½«¡°data1¡±¡¢¡°data2¡±¡¢¡°data3¡±base64¼ÓÃܺóÉú´æÔÚµ±µØ £¬ÈçÏÂ(ÆäÖÐ0x00000494ΪlocPrikey³¤¶È)£º


gandcrabKey=base64encode(0x00000494+ data1+  data2+ data3)


Éú´æÔÚ¡°****-MANUAL.txt¡±ÎļþÖÐ £¬Èçͼ25£º

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ25 Base64´æ´¢µÄµ±µØRSA-2048˽ԿÃÜÎÄÐÅÏ¢



6.5 ¼ÓÃÜѬȾÕßÎļþ


¡°ÏÀµÁ¡±µÚÒ»²½Éú³ÉSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©¡¢IV2£¨8×Ö½ÚËæ»úÊý£©ÒÔ¼°³£Á¿Éú³ÉµÄ64×Ö½ÚÊäÈëÁ÷ £¬ÎÒÃǼÇΪinput2 £¬input2Õë¶Ôÿһ¸öÓû§Îļþ¶¼Î¨Ò»Éú³É £¬È»ºó¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜÓû§Îļþ £¬Ëã·¨ÈçÏ£º


data4  = Salsa20(input2,userFile)


        µÚ¶þ²½Óõ±µØ¹«Ô¿locPubkey¼ÓÃÜSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©ºÍIV2£¨8×Ö½ÚËæ»úÊý£© £¬Ëã·¨ÈçÏ£º


data5 = RSA2048(locPubkey, SalsaFileKey)

data6 = RSA2048(locPubkey, IV2)


         ×îºó £¬¡°ÏÀµÁ¡±½«¡°data4¡±¡¢¡°data5¡±¡¢¡°data6¡±ºÍÀι̵Ä×Ö½ÚÆ´½Ó³É¼ÓÃÜÎļþ £¬ÈçÏÂ(ÆäÖÐlenUserFileΪÓû§Ô­Ê¼Îļþ¾Þϸ)£º


finalFile=data4 +data5+data6+lenUserFile+ÀιÌ×Ö½Ú


¼ÓÃܺóµÄÎļþ½á¹¹Èçͼ26£º


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͼ26 ¼ÓÃܵÄÎļþ½á¹¹



7.×ܽáÓ뽨Òé


        ÒòΪ´ó²¿ÃÅÀÕË÷²¡¶¾¼ÓÃܺóµÄÎļþ¶¼ÎÞ·¨½âÃÜ £¬ËùÒÔÓ¦¶ÔÀÕË÷²¡¶¾ÒÔÔ¤·ÀºÍ±¸·ÝΪÖ÷¡£½¨ÒéÓû§×öºÃÈÕ³£µÄ·À·¶´ëÊ©£º


  •             ¼°Ê±¸üвÙ×÷ϵͳ £¬¼°Ê±¸ø¼ÆËã»ú´ò²¹¶¡¡£
  •             ¶ÔÖØÒªµÄÊý¾ÝÎļþÒª½øÐÐÒìµØ±¸·Ý¡£
  •             ¾¡Á¿¹Ø±Õ²»ÐëÒªµÄÎļþ¹²Ïí £¬»ò°Ñ¹²Ïí´ÅÅÌÉèÖÃΪֻ¶ÁÊôÐÔ £¬²»ÔÊÐí¾ÖÓòÍøÓû§¸ÄдÎļþ¡£
  •             ¾¡Á¿¹Ø±Õ²»ÐëÒªµÄ·þÎñºÍ¶Ë¿Ú¡£È磺135 £¬139 £¬445¶Ë¿Ú £¬¶ÔÓÚÔ¶³Ì×ÀÃæ·þÎñ£¨3389£© £¬VNC·þÎñÐèÒª½øÐа×Ãûµ¥ÉèÖà £¬½öÔÊÐí°×Ãûµ¥ÄÚµÄIPµÇ½¡£
  •             ½ÓÄɲ»ÉÙÓÚ10λµÄ¸ßÇ¿¶ÈÃÜÂë £¬²¢¶¨ÆÚ¸ü»»ÃÜÂë £¬Í¨¹ýwindows×é¼ÆıÅäÖÃÕË»§Ëø¶¨¼Æı £¬¶Ô¶Ìʱ¼äÄÚÁ¬ÐøµÇ½ʧ°ÜµÄÕË»§½øÐÐËø¶¨¡£
  •             °²×°¾ß±¸×Ô± £»¤¹¦Ð§µÄ·À²¡¶¾Èí¼þ £¬²¢¼°Ê±¸üв¡¶¾¿â»òÈí¼þ°æ±¾¡£
  •             ¼ÓÇ¿Ô±¹¤Äþ¾²ÒâʶÅàѵ £¬²»ÇáÒ×´ò¿ªÄ°ÉúÓʼþ»òÔËÐÐÀ´Ô´²»Ã÷µÄ·¨Ê½ £¬ÇжÏÀÕË÷²¡¶¾µÄÓʼþÁ÷´«·½Ê½¡£