¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«ÃæÆÊÎö

Ðû²¼Ê±¼ä 2019-04-25

1¡¢¸Å Êö


    ½üÈÕ£¬¶«É­Æ½Ì¨ADLab²¶×½µ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬±àÒëʱ¼äΪ4ÔÂ14ÈÕ£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁÅ°½ö½öÒ»¸ö¶àÔ¡£¡°ÏÀµÁ¡±V5.2¿ªÊ¼ËÁÅ°ÖйúµÄʱ¼äΪ3ÔÂ11ÈÕ£¬²¢ÒÑѬȾÁËÎÒ¹úÉÏǧ̨Õþ¸®¡¢ÆóÒµºÍÏà¹Ø¿ÆÑлú¹¹µÄ¼ÆËã»ú¡£ºþ±±Ê¡Ò˲ýÊÐÒÄÁêÇøÕþ¸®¡¢Öйú¿ÆѧԺ½ðÊôÑо¿Ëù¡¢ÔÆÄÏʦ·¶´óѧÒÔ¼°´óÁ¬Êй«°²¾ÖµÈ»ú¹¹¾ùÔÚÆä¹ÙÍøÐû²¼ÁË·À·¶²¡¶¾¹¥»÷µÄͨ¸æ¡£


    ¡°ÏÀµÁ¡±²¡¶¾µÄµÚÒ»¸ö°æ±¾µ®ÉúÓÚ2018Äê1Ô£¬Ä¿Ç°ÎªÖ¹£¬ÒѾ­¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öС°æ±¾¡£ÆäÖ÷ҪĿµÄÊÇͨ¹ý¼ÓÃÜÊܺ¦Óû§µÄ¼ÆËã»úÎļþÀ´¶ÔÊܺ¦Óû§½øÐÐÀÕË÷¡£¡°GandCrab¡±ÀÕË÷²¡¶¾Ö®ËùÒÔ±»È˳ÆΪ¡°ÏÀµÁ¡±£¬ÊÇÒòΪÆäÔø¾­¡°È˵ÀµØ¡±ÎªÎÞÁ¦Ö§¸¶¡°Êê½ð¡±µÄÐðÀûÑǸ¸Ç×½âÃÜÁËÆäÔÚÕ½ÕùÖÐÉ¥ÉúµÄ¶ù×ÓµÄÕÕƬ£¬²¢·Å³öÁ˲¿ÃÅÐðÀûÑǵØÓò֮ǰ°æ±¾µÄ½âÃÜÃÜÔ¿£¬»¹½«ÐðÀûÑÇÒÔ¼°ÆäËûÕ½ÂÒµØÓò¼Ó½øѬȾÇøÓò¡°°×Ãûµ¥¡±¡£


¡°ÏÀµÁ¡±»á½«Óû§Îļþ¼ÓÃܺóÌí¼ÓÉÏÀÕË÷ºó׺Ãû£¬È»ºóÔÙ¸ü»»Ñ¬È¾ÏµÍ³µÄ×ÀÃæΪÀÕË÷ͼƬ£¬ÀÕË÷ͼƬÉϵÄÎÄ×ÖÌáʾÊܺ¦Óû§ÔĶÁÆäÀÕË÷ÊÖ²áÎı¾Îļþ,ÔÚÀÕË÷ÊÖ²áÎı¾ÎļþÖнøÒ»²½Òýµ¼Êܺ¦Óû§Êê»ØÓû§Îļþ¡£ÔÚ5.2֮ǰµÄ°æ±¾ÖУ¬ÀÕË÷ÊÖ²áÎļþÒýµ¼Êܺ¦Óû§Í¨¹ýTorÍøÂçÊê»ØÎļþ£¬Êê½ðÖ§³Ö´ïÊÀ±ÒºÍ±ÈÌرÒÖ§¸¶£»¶øÔÚ×îеÄ5.3°æ±¾ÖУ¬ÀÕË÷ÊÖ²áÖÐÖ»¸ø³öÁ˺ڿ͵ÄÓÊÏ䣬ҪÇóÊܺ¦ÕßÓʼþÁªÏµËûÃÇ£¬³ýÁËÕâÒ»µã±ä»¯£¬¡°ÏÀµÁ¡±5.3»¹¸üÐÂÁ˺ڿ͹«Ô¿¡£Ä¿Ç°Éв»Çå³þGandcrab5.3ÀÕË÷²¡¶¾¿ÉÄÜ»áÒªÇó½âÃÜÕßÖ§¸¶¼¸¶àÇ®£¬µ«Ö®Ç°µÄ°æ±¾ÒªÇóÔÚ±ÈÌرһò´ïÊÀ±ÒÉÏÖ§¸¶500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£


2¡¢²¡¶¾Á÷´«


    ¡°ÏÀµÁ¡±²¡¶¾Á÷´«Í¾¾¶Ö÷ÒªÓÐRDP¡¢VNC;¾¶½øÐб©Á¦ÆƽâºÍÈëÇÖ¡¢¶¨ÏòÓã²æµöÓãÓʼþͶ·Å¡¢À¦°ó¶ñÒâÈí¼þºÍÍøÒ³¹ÒÂí¹¥»÷¡¢½©Ê¬ÍøÂçÒÔ¼°Â©¶´ÀûÓÃÁ÷´«µÈ¡£


    Ä¿Ç°ÔÚ°µÍøÖУ¬¡°ÏÀµÁ¡±Ä»ºóÍŶӽÓÄÉ¡°ÀÕË÷¼´·þÎñ¡±£¨¡°ransomware as-a-service¡± £©µÄ·½Ê½£¬ÏòºÚ¿Í·ÅËÁÊÛÂôV5.3°æ±¾²¡¶¾£¬¼´ÓÉ¡°ÏÀµÁ¡±ÍŶÓÌṩ²¡¶¾£¬ºÚ¿ÍÔÚÈ«ÇòÑ¡ÔñÄ¿±ê½øÐй¥»÷ÀÕË÷£¬¹¥»÷ÀÖ³Éºó ¡°ÏÀµÁ¡±ÍŶÓÔÙ´ÓÖгéÈ¡30%-40%µÄÀûÈ󡣡°À¬»øÓʼþÖÆÔìÕßÃÇ£¬ÄãÃÇÏÖÔÚ¿ÉÒÔÓëÍøÂçר¼Ò½øÐкÏ×÷£¬²»Òª´íʧ»ñÈ¡ÃÀºÃÉú»îµÄÃÅƱ£¬ÎÒÃÇÔÚµÈÄã¡£¡±ÊÇ¡°ÏÀµÁ¡±ÍŶÓÔÚ°µÍøÖдò³öµÄ¡°ÕÐÉ̹ã¸æ¡±¡£


¡°ÏÀµÁ¡±ÊÇÄ¿Ç°µÚÒ»¸öÀÕË÷´ïÊÀ±ÒµÄÀÕË÷²¡¶¾£¬ºóÀ´²Å¼ÓÁ˱ÈÌرÒ£¬Òª¼Û500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£¾Ý¡°ÏÀµÁ¡±ÍŶÓ2018Äê12ÔÂÐû²¼µÄÊý¾Ý£¬Æä×ܼÆÊÕÈë±ÈÌرÒÒÔ¼°´ïÊÀ±ÒºÏ¼ÆÒѸߴï285ÍòÃÀÔª¡£


3¡¢ÆƽâÀúÊ·


    Ïñ´ó²¿ÃÅÀÕË÷ÎļþÒ»Ñù£¬¡°ÏÀµÁ¡±Ê¹ÓÃÁËRSA¼ÓÃÜËã·¨£¬³ý·ÇÄõ½ºÚ¿Í³ÖÓеÄRSA-2048˽Կ£¬²ÅÆø¹»¶ÔѬȾÎļþ½øÐнâÃÜ£¬·ñÔòÎÞ·¨½âÃÜ¡£


    ÒòΪ¡°ÏÀµÁ¡±Ê¼þ£¬¹¥»÷Õ߷ųöÁËÀÕË÷²¡¶¾²¿ÃÅÔçÆÚ°æ±¾µÄ½âÃÜÃÜÔ¿£¬¶à¸öÄþ¾²³§ÉÌËæºóÏà¼ÌÐû²¼Á˽âÃܹ¤¾ß¡£´Ó18Äê10Ôµ½½ñÄê2Ô£¬BitdefenderÏȺóÐû²¼ÁË¡°ÏÀµÁ¡±¶à¸ö°æ±¾µÄ½âÃܹ¤¾ß£¬×îеĽâÃܹ¤¾ßÏÂÔصØַΪ£ºhttps://labs.bitdefender.com/wp-content/uploads/downloads/gandcrab-removal-tool-v1-v4-v5/£¬¸Ã¹¤¾ß¿ÉÒÔ½âÃܵİ汾Èç±í1Ëùʾ¡£Æä½âÃÜÔ­ÀíÊÇͨ¹ýÔÚÏßÏòBitdefender·þÎñÆ÷Ìá½»¼ÓÃÜID£¬À´»ñÈ¡¿ÉÓõĽâÃÜ˽Կ£¨ RSA-2048£©À´½øÐнâÃÜ¡£Óû§¿ÉÒÔƾ¾Ý±íÖеļÓÃÜÎļþºó׺»òÀÕË÷˵Ã÷Îı¾ÎļþµÄ¿ªÊ¼À´ºË¶Ô²¡¶¾°æ±¾¡£



ÇøÓò±êÖ¾·û

ÓïÑÔ£¨¹ú¼Ò£©

0x419

¶íÓ¶íÂÞ˹£©

0x422

ÎÚ¿ËÀ¼ÓÎÚ¿ËÀ¼£©

0x423

°×¶íÂÞ˹Ó°×¶íÂÞ˹£©

0x428

Ëþ¼ª¿Ë

0x42B

ÑÇÃÀÄáÑÇÓÑÇÃÀÄáÑÇ£©

0x42C

°¢ÔóÀïÓ°¢Èû°Ý½®£¬À­¶¡Ó

0x437

¸ñ³¼ªÑÇÓ¸ñ³¼ªÑÇ£©

0x43F

¹þÈø¿ËÓ¹þÈø¿Ë˹̹£©

0x440

¼ª¶û¼ªË¹Ó¼ª¶û¼ªË¹Ì¹£©

0x442

ÍÁ¿âÂü

0x443

ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹£¬À­¶¡Ó

0x444

÷²÷°Ó¶íÂÞ˹£©

0x818

ÂÞÂíÄáÑÇÓĦ¶û¶àÍßµØÓò£©

0x819

¶íÓĦ¶û¶àÍßµØÓò£©

0x82C

°¢ÔóÀïÓ°¢Èû°Ý½®£¬Î÷Àï¶ûÓ

0x843

ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹£¬Î÷Àï¶ûÓ

0x45A

ÐðÀûÑÇÓÐðÀûÑÇ£©

0x2801

°¢À­²®ÓÐðÀûÑÇ£©



±í2 ÅųýµÄÓïÑÔ£¨¹ú¼Ò£©


5.2 ÖÕÖ¹Äþ¾²Èí¼þ



¡°ÏÀµÁ¡±±éÀúѬȾÉ豸ϵͳ½ø³Ì£¬Èç¹û·¢ÏÖѬȾÉ豸ÓÐÔËÐп¨°Í˹»ù¡¢Åµ¶ÙµÈÄþ¾²Èí¼þ£¬¾ÍÇ¿ÖƽáÊøµôÄ¿±ê½ø³Ì£¬·ÀÖ¹×Ô¼º±»É±¶¾Èí¼þ²éɱ¡£Ïà¹ØµÄÄþ¾²Èí¼þÈçÏÂͼ4Ëùʾ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ4 Ïà¹ØÄþ¾²Èí¼þ½ø³Ì



5.3 ÖÕÖ¹Ìض¨·¨Ê½



¡°ÏÀµÁ¡±»á±éÀúѬȾÉ豸ϵͳµ±Ç°½ø³ÌÁбí£¬Èç¹ûÆ¥Åäµ½Ö¸¶¨µÄ½ø³ÌÔò½áÊø¸Ã½ø³Ì£¬ÒÔ·ÀÖ¹ÒÅ©µôÒòÓû§Îļþ±»Õ¼Óöø²»Äܱ»¼ÓÃܵÄÓû§Îļþ¡£ÈçWord¡¢Excel¡¢PowerPoint¡¢Onenote¡¢Visio¡¢Oracle¡¢SQLserver¡¢MySQLµÈ³£¼ûÓ¦Óýø³Ì£¬ÏêϸĿ±ê½ø³ÌÈçͼ5Ëùʾ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ5 ÖÕÖ¹µÄÄ¿±ê½ø³Ì


5.4 È·¶¨¼ÓÃÜÎļþÀàÐÍ


5.4.1 Îļþºó׺°×Ãûµ¥


ΪÁËÅųýµôûÓмÛÖµµÄÀÕË÷Êý¾ÝÎļþ£¬¡°ÏÀµÁ¡±ÄÚÖÃÁËÒ»·ÝÎļþºó׺°×Ãûµ¥£¬Èçͼ6Ëùʾ¡£ÎÒÃǽ«ÆäÁе½±í3ÖУ¬ÆäÖаüÂÞµÄÎļþÓпÉÖ´ÐÐÎļþ¡¢ÏµÍ³¶¯Ì¬µ÷ÓÿâÎļþ¡¢ÏµÍ³Çý¶¯ÎļþºÍ¡°ÏÀµÁ¡±Ïà¹ØµÄÎļþµÈ¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ6 ²»¼ÓÃܵÄÎļþÀàÐÍ


°×Ãûµ¥Â·¾¶

"\\ProgramData\\"

"\\IETldCache\\"

"\\Boot\\"

"\\Program Files\\"

"\\Tor Browser\\"

"\\All Users\\"

"\\Local Settings\\"

"\\Windows\\"




±í4 ϵͳĿ¼°×Ãûµ¥


±í5ÖеÄϵͳÎļþÒ²²»ÔÚ¼ÓÃÜÄ¿±êÖ®ÁУº



¼ÓÃܵÄÎļþºó׺

.1st  .602 .docb .xlm .xlsx .xlsm .xltx .xltm .xlsb .xla .xlam .xll .xlw .ppt .pot  .pps .pptx .pptm

.potx  .potm .ppam .ppsx .ppsm .sldx .sldm .xps .xls .xlt ._doc .dotm ._docx .abw  .act .adoc .aim

.ans  .apkg .apt .asc .asc .ascii .ase .aty .awp .awt .aww .bad .bbs .bdp .bdr  .bean .bib .bib .bibtex

.bml  .bna .boc .brx .btd .bzabw .calca .charset .chart .chord .cnm .cod .crwl .cws  .cyi .dca .dfti

.dgs  .diz .dne .dot .doc .docm .dotx .docx .docxml .docz .dox .dropbox .dsc .dvi  .dwd .dx .dxb .dxp

.eio  .eit .emf .eml .emlx .emulecollection .epp .err .err .etf .etx .euc  .fadein.template .faq .fbl

.fcf  .fdf .fdr .fds .fdt .fdx .fdxt .fft .fgs .flr .fodt .fountain .fpt .frt .fwd  .fwdn .gmd .gpd

.gpn  .gsd .gthr .gv .hbk .hht .hs .hwp .hwp .hz .idx .iil .ipf .ipspot .jarvis  .jis .jnp .joe .jp1

.jrtf  .jtd .kes .klg .klg .knt .kon .kwd .latex .lbt .lis .lnt .log .lp2 .lst .lst  .ltr .ltx .lue

.luf  .lwp .lxfml .lyt .lyx .man .mbox .mcw .md5 .me .mell .mellel .min .mnt .msg  .mw .mwd .mwp

.nb  .ndoc .nfo .ngloss .njx .note .notes .now .nwctxt .nwm .nwp .ocr .odif .odm  .odo .odt .ofl .opeico

.openbsd  .ort .ott .p7s .pages .pages-tef .pdpcmd .pfx .pjt .plain .plantuml .pmo .prt  .prt .psw .pu

.pvj  .pvm .pwd .pwdp .pwdpl .pwi .pwr .qdl .qpf .rad .readme .rft .ris .rpt .rst  .rtd .rtf .rtfd .rtx

.run  .rvf .rzk .rzn .saf .safetext .sam .sam .save .scc .scm .scriv .scrivx .sct  .scw .sdm .sdoc .sdw

.se  .session .sgm .sig .skcard .sla .sla.gz .smf .sms .ssa .story .strings .stw  .sty .sublime-project

.sublime-workspace  .sxg .sxw .tab .tab .tdf .tdf .template .tex .text .textclipping .thp .tlb  .tm .tmd

.tmdx  .tmv .tmvx .tpc .trelby .tvj .txt .u3i .unauth .unx .uof .uot .upd .utf8  .utxt .vct .vnt .vw

.wbk  .webdoc .wn .wp .wp4 .wp5 .wp6 .wp7 .wpa .wpd .wpd .wpd .wpl .wps .wps .wpt  .wpt .wpw

.wri  .wsd .wtt .wtx .xbdoc .xbplate .xdl .xdl .xwp .xwp .xwp .xy .xy3 .xyp .xyw  .zabw .zrtf .zw.rar

.zip  .cab .arj .lzh .tar .7z .gzip .iso .z .7-zip .lzma .vmx .vmdk .vmem .vdi .vbo



±í6 ¼ÓÃܵÄÎļþºó׺



5.5 ¼ÓÃÜÓû§Îļþ



¡°ÏÀµÁ¡±»á±éÀúѬȾÉ豸¹²ÏíĿ¼ºÍµ±µØ´ÅÅÌ¡£½ÓÄÉRSA-2048+Salsa20Ëã·¨¼ÓÃÜѬȾÉ豸Îļþ¡£
¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþÈçͼ8Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ8 ¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþ


¼ÓÃܵ±µØ´ÅÅÌĿ¼ÏÂÎļþÈçͼ9Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ9 ¼ÓÃܵ±µØ´ÅÅÌĿ¼ÏÂÎļþ



5.6 Éú³ÉMANUALÎļþ


¡°ÏÀµÁ¡±ÏȽ«ÀÕË÷ÐÅÏ¢½âÃܵ½ÄÚ´æÖУ¬ÔÚ½øÐа汾ºÍºó׺ÐÅϢƴ½Óºó£¬½«Õû¸öÀÕË÷ÐÅϢдÈëMANUALÎļþÖУ¬Èçͼ10ºÍͼ11Ëùʾ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ10 ´´½¨MANUALÎļþ£¬Ð´ÈëÀÕË÷ÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ11 ½âÃܵ½ÄÚ´æÖеÄÀÕË÷ÐÅÏ¢


    ×îÖÕµÄMANUALÎļþÓÉÀÕË÷ÐÅÏ¢¡¢¼ÓÃܺóµÄ˽ԿÐÅÏ¢ºÍ¼ÓÃܺóµÄѬȾÉ豸ÐÅÏ¢×é³É¡£ÆäÖкڿÍÌØÒâÇ¿µ÷Êܺ¦Óû§²»ÒªÐÞ¸Ä˽ԿÐÅÏ¢ÄÚÈÝ£¬ÒòΪһµ©Ë½Ô¿ÐÅÏ¢Ò»µ©±»¸Ä±ä£¬¾ÍÎÞ·¨¶ÔÎļþ½øÐнâÃÜ¡£



5.7 Ì滻ѬȾÉ豸×ÀÃæ


´´½¨ÀÕË÷×ÀÃæ±ÚÖ½µ½¡°C:\Documents and Settings\[username]\LocalSettings\Temp\bxmeoengtf.bmp¡±,Èçͼ12Ëùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ12 ´´½¨ÀÕË÷ͼƬ£¬ÉèÖÃÀÕË÷×ÀÃæ


ͼ13ÖУ¬ÀÕË÷ͼƬÉÏдÓС°YOURFILES ARE UNDER STRONG PROTECTION BY OUR SOFTWARE. IN ORDER TO RESTORE IT YOUMUST BUY DECRYPTOR£¬For further stepsread %s-DECRYPT.%s that is located in every encrypted folder¡±£¬ÌáʾѬȾÓû§ÔĶÁManualÎļþÖ§¸¶Êê½ð¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ13 ÀÕË÷±ÚÖ½



5.8 ɾ³ý¾íÓ°¿½±´


¡°ÏÀµÁ¡±»áɾ³ýѬȾ¼ÆËã»ú¾íÓ°¸±±¾£¬ÕâÊÇÀÕË÷²¡¶¾µÄͨÀý²Ù×÷£¬ÕâÑù×öµÄÄ¿µÄÊÇ·ÀÖ¹Êܺ¦Óû§Í¨¹ýWindows Recovery¶ÔÎļþ½øÐлָ´£¬Èçͼ14¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ14 ɾ³ý¾íÓ°¸±±¾


Èçͼ15£¬¡°ÏÀµÁ¡±µ÷Óá°shell32.ShellExecuteW¡±Ö´ÐÐÃüÁî¡°/c vssadmin delete shadows /all /quiet¡±


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ15 Ö´ÐÐɾ³ýÃüÁî



5.9 Á¬½ÓC&C


¡°ÏÀµÁ¡±»á·ÃÎÊÖ¸¶¨ÓòÃûµÄ80ºÍ443¶Ë¿Ú£¬¡°ÏÀµÁ¡±ÔÚÁ¬½ÓºÚ¿Í¿ØÖƵÄÔ¶³Ì·þÎñÆ÷£¨Èçhttp://www.kakaocorp.link£©Àֳɺó£¬ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍѬȾÉ豸ÐÅÏ¢£¬Èçͼ16¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ16 ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍѬȾÉ豸ÐÅÏ¢



ÆäÖУ¬rc4keyΪ".oj=294~!z3)9n-1,8^)o((q22)lb$"
strPCdataÉú´æÔÚ¡±*-MANUAL.txt¡±ÎļþÖУ¨*ÌåÏÖ´óдµÄ¼ÓÃÜÎļþºó׺Ãû£©£¬¼ûͼ18£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ18 Base64´æ´¢µÄPCÏà¹ØÃÜÎÄÐÅÏ¢


        ÓÉÓÚC&CʧЧ£¬ËùÓÐÎÒÃÇûÓÐ×¥µ½·¢ËÍ·¢ËÍstrPCdataµÄÊý¾Ý°ü¡£



6.2 ½âÃÜpubkey


¡°ÏÀµÁ¡±ÏÈÉú³É64×Ö½ÚÁ÷input3£¨ÓÉSalsakey3£¨ÀιÌ×Ö½Ú£©ºÍIV3£¨ÀιÌ×Ö½Ú£©ºÍ³£Á¿×é³É£©£¬Èçͼ19:


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ19 Éú³ÉµÄinput3


        ¡°ÏÀµÁ¡±ÔÚʹÓÃSalsa20Ëã·¨½âÃܺڿ͵ÄRSA2048¹«Ô¿£¬ÎÒÃǽ«¹«Ô¿ÃÜÎļÇΪpubkeyEncrypted£¬½«½âÃܺóµÄ¹«Ô¿¼ÇΪhackerPubkey£¬Ëã·¨ÈçÏ£º



hackerPubkey=  Salse20(input3, pubkeyEncrypted)


hackerPubkeyEncrypted¼ûͼ20£º



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ20 ½âÃÜÇ°µÄhackerPubkey


½âÃܵõ½hackerPubkey¼ûͼ21£¬¶Ô±È¡°ÏÀµÁ¡±5.2µÄºÚ¿Í¹«Ô¿£¨Í¼22£©£¬ÎÒÃÇ·¢ÏÖÔÚ5.3°æ±¾Öкڿ͸üÐÂÁËÆä³ÖÓеĹ«Ô¿¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ21 GandCrab5.3½âÃܺóµÄ¹«Ô¿


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ22 GandCrab5.2 ºÚ¿Í¹«Ô¿



6.3 µ±µØÉú³ÉRSA¹«Ë½«h¶Ô


        ºÚ¿ÍÀûÓÃ΢Èí¡°advapi32¡±¿âº¯Êýµ±µØÉú³ÉRSA-2048¹«Ë½«h¶Ô£¬ÎÒÃÇ·Ö±ð¼ÇΪlocPubkeyºÍlocPrikey£¬Õë¶Ôÿ¸öѬȾÕßµ±µØ¹«Ë½«h¶ÔÖ»Éú³ÉÒ»´Î¡£ÆäÖУ¬locPubkeyÓÃÓÚ¼ÓÃÜSalsaFileKeyºÍIV2£¬¶ølocPrikeyʹÓÃSalsa20Ëã·¨¼ÓÃܺó×îÖÕÉú´æµ½µ±µØ¡£


locPubkey£¨0x114×Ö½Ú£©¼ûͼ23:

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ23 ÄÚ´æÖеÄlocPubkey


locPrikey£¨0x494×Ö½Ú£©¼ûÏÂͼ24£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ24 ÄÚ´æÖеÄlocPrikey



6.4 ¼ÓÃܵ±µØ˽Կ


        ¡°ÏÀµÁ¡±Ê×ÏÈÉú³ÉSalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©£¬Ôٺͳ£Á¿Ò»ÆðÉú³É64×Ö½ÚÊäÈëÁ÷£¬ÎÒÃǼÇΪinput1£¬È»ºó£¬¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜlocPrikey£¬Ëã·¨ÈçÏ£º


data3  = Salsa20(input1,locPrikey)


        SalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©·Ö±ð±»ºÚ¿ÍµÄ¹«Ô¿¼ÓÃÜ£¬ÈçÏÂ:


data1= RSA2048(hackerPubkey, SalsaKey)

data2 = RSA2048(hackerPubkey, IV1)


        ×îºó£¬¡°ÏÀµÁ¡±½«¡°data1¡±¡¢¡°data2¡±¡¢¡°data3¡±base64¼ÓÃܺóÉú´æÔÚµ±µØ£¬ÈçÏÂ(ÆäÖÐ0x00000494ΪlocPrikey³¤¶È)£º


gandcrabKey=base64encode(0x00000494+ data1+  data2+ data3)


Éú´æÔÚ¡°****-MANUAL.txt¡±ÎļþÖУ¬Èçͼ25£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ25 Base64´æ´¢µÄµ±µØRSA-2048˽ԿÃÜÎÄÐÅÏ¢



6.5 ¼ÓÃÜѬȾÕßÎļþ


¡°ÏÀµÁ¡±µÚÒ»²½Éú³ÉSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©¡¢IV2£¨8×Ö½ÚËæ»úÊý£©ÒÔ¼°³£Á¿Éú³ÉµÄ64×Ö½ÚÊäÈëÁ÷£¬ÎÒÃǼÇΪinput2£¬input2Õë¶Ôÿһ¸öÓû§Îļþ¶¼Î¨Ò»Éú³É£¬È»ºó¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜÓû§Îļþ£¬Ëã·¨ÈçÏ£º


data4  = Salsa20(input2,userFile)


        µÚ¶þ²½Óõ±µØ¹«Ô¿locPubkey¼ÓÃÜSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©ºÍIV2£¨8×Ö½ÚËæ»úÊý£©£¬Ëã·¨ÈçÏ£º


data5 = RSA2048(locPubkey, SalsaFileKey)

data6 = RSA2048(locPubkey, IV2)


         ×îºó£¬¡°ÏÀµÁ¡±½«¡°data4¡±¡¢¡°data5¡±¡¢¡°data6¡±ºÍÀι̵Ä×Ö½ÚÆ´½Ó³É¼ÓÃÜÎļþ£¬ÈçÏÂ(ÆäÖÐlenUserFileΪÓû§Ô­Ê¼Îļþ¾Þϸ)£º


finalFile=data4 +data5+data6+lenUserFile+ÀιÌ×Ö½Ú


¼ÓÃܺóµÄÎļþ½á¹¹Èçͼ26£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ26 ¼ÓÃܵÄÎļþ½á¹¹



7.×ܽáÓ뽨Òé


        ÒòΪ´ó²¿ÃÅÀÕË÷²¡¶¾¼ÓÃܺóµÄÎļþ¶¼ÎÞ·¨½âÃÜ£¬ËùÒÔÓ¦¶ÔÀÕË÷²¡¶¾ÒÔÔ¤·ÀºÍ±¸·ÝΪÖ÷¡£½¨ÒéÓû§×öºÃÈÕ³£µÄ·À·¶´ëÊ©£º


  •             ¼°Ê±¸üвÙ×÷ϵͳ£¬¼°Ê±¸ø¼ÆËã»ú´ò²¹¶¡¡£
  •             ¶ÔÖØÒªµÄÊý¾ÝÎļþÒª½øÐÐÒìµØ±¸·Ý¡£
  •             ¾¡Á¿¹Ø±Õ²»ÐëÒªµÄÎļþ¹²Ïí£¬»ò°Ñ¹²Ïí´ÅÅÌÉèÖÃΪֻ¶ÁÊôÐÔ£¬²»ÔÊÐí¾ÖÓòÍøÓû§¸ÄдÎļþ¡£
  •             ¾¡Á¿¹Ø±Õ²»ÐëÒªµÄ·þÎñºÍ¶Ë¿Ú¡£È磺135£¬139£¬445¶Ë¿Ú£¬¶ÔÓÚÔ¶³Ì×ÀÃæ·þÎñ£¨3389£©£¬VNC·þÎñÐèÒª½øÐа×Ãûµ¥ÉèÖ㬽öÔÊÐí°×Ãûµ¥ÄÚµÄIPµÇ½¡£
  •             ½ÓÄɲ»ÉÙÓÚ10λµÄ¸ßÇ¿¶ÈÃÜÂ룬²¢¶¨ÆÚ¸ü»»ÃÜÂ룬ͨ¹ýwindows×é¼ÆıÅäÖÃÕË»§Ëø¶¨¼Æı£¬¶Ô¶Ìʱ¼äÄÚÁ¬ÐøµÇ½ʧ°ÜµÄÕË»§½øÐÐËø¶¨¡£
  •             °²×°¾ß±¸×Ô±£»¤¹¦Ð§µÄ·À²¡¶¾Èí¼þ£¬²¢¼°Ê±¸üв¡¶¾¿â»òÈí¼þ°æ±¾¡£
  •             ¼ÓÇ¿Ô±¹¤Äþ¾²ÒâʶÅàѵ£¬²»ÇáÒ×´ò¿ªÄ°ÉúÓʼþ»òÔËÐÐÀ´Ô´²»Ã÷µÄ·¨Ê½£¬ÇжÏÀÕË÷²¡¶¾µÄÓʼþÁ÷´«·½Ê½¡£