¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«ÃæÆÊÎö
Ðû²¼Ê±¼ä 2019-04-251¡¢¸Å Êö
½üÈÕ£¬¶«Éƽ̨ADLab²¶×½µ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬±àÒëʱ¼äΪ4ÔÂ14ÈÕ£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁÅ°½ö½öÒ»¸ö¶àÔ¡£¡°ÏÀµÁ¡±V5.2¿ªÊ¼ËÁÅ°ÖйúµÄʱ¼äΪ3ÔÂ11ÈÕ£¬²¢ÒÑѬȾÁËÎÒ¹úÉÏǧ̨Õþ¸®¡¢ÆóÒµºÍÏà¹Ø¿ÆÑлú¹¹µÄ¼ÆËã»ú¡£ºþ±±Ê¡Ò˲ýÊÐÒÄÁêÇøÕþ¸®¡¢Öйú¿ÆѧԺ½ðÊôÑо¿Ëù¡¢ÔÆÄÏʦ·¶´óѧÒÔ¼°´óÁ¬Êй«°²¾ÖµÈ»ú¹¹¾ùÔÚÆä¹ÙÍøÐû²¼ÁË·À·¶²¡¶¾¹¥»÷µÄͨ¸æ¡£
¡°ÏÀµÁ¡±²¡¶¾µÄµÚÒ»¸ö°æ±¾µ®ÉúÓÚ2018Äê1Ô£¬Ä¿Ç°ÎªÖ¹£¬ÒѾ¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öС°æ±¾¡£ÆäÖ÷ҪĿµÄÊÇͨ¹ý¼ÓÃÜÊܺ¦Óû§µÄ¼ÆËã»úÎļþÀ´¶ÔÊܺ¦Óû§½øÐÐÀÕË÷¡£¡°GandCrab¡±ÀÕË÷²¡¶¾Ö®ËùÒÔ±»È˳ÆΪ¡°ÏÀµÁ¡±£¬ÊÇÒòΪÆäÔø¾¡°È˵ÀµØ¡±ÎªÎÞÁ¦Ö§¸¶¡°Êê½ð¡±µÄÐðÀûÑǸ¸Ç×½âÃÜÁËÆäÔÚÕ½ÕùÖÐÉ¥ÉúµÄ¶ù×ÓµÄÕÕƬ£¬²¢·Å³öÁ˲¿ÃÅÐðÀûÑǵØÓò֮ǰ°æ±¾µÄ½âÃÜÃÜÔ¿£¬»¹½«ÐðÀûÑÇÒÔ¼°ÆäËûÕ½ÂÒµØÓò¼Ó½øѬȾÇøÓò¡°°×Ãûµ¥¡±¡£
¡°ÏÀµÁ¡±»á½«Óû§Îļþ¼ÓÃܺóÌí¼ÓÉÏÀÕË÷ºó׺Ãû£¬È»ºóÔÙ¸ü»»Ñ¬È¾ÏµÍ³µÄ×ÀÃæΪÀÕË÷ͼƬ£¬ÀÕË÷ͼƬÉϵÄÎÄ×ÖÌáʾÊܺ¦Óû§ÔĶÁÆäÀÕË÷ÊÖ²áÎı¾Îļþ,ÔÚÀÕË÷ÊÖ²áÎı¾ÎļþÖнøÒ»²½Òýµ¼Êܺ¦Óû§Êê»ØÓû§Îļþ¡£ÔÚ5.2֮ǰµÄ°æ±¾ÖУ¬ÀÕË÷ÊÖ²áÎļþÒýµ¼Êܺ¦Óû§Í¨¹ýTorÍøÂçÊê»ØÎļþ£¬Êê½ðÖ§³Ö´ïÊÀ±ÒºÍ±ÈÌرÒÖ§¸¶£»¶øÔÚ×îеÄ5.3°æ±¾ÖУ¬ÀÕË÷ÊÖ²áÖÐÖ»¸ø³öÁ˺ڿ͵ÄÓÊÏ䣬ҪÇóÊܺ¦ÕßÓʼþÁªÏµËûÃÇ£¬³ýÁËÕâÒ»µã±ä»¯£¬¡°ÏÀµÁ¡±5.3»¹¸üÐÂÁ˺ڿ͹«Ô¿¡£Ä¿Ç°Éв»Çå³þGandcrab5.3ÀÕË÷²¡¶¾¿ÉÄÜ»áÒªÇó½âÃÜÕßÖ§¸¶¼¸¶àÇ®£¬µ«Ö®Ç°µÄ°æ±¾ÒªÇóÔÚ±ÈÌرһò´ïÊÀ±ÒÉÏÖ§¸¶500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£
2¡¢²¡¶¾Á÷´«
¡°ÏÀµÁ¡±²¡¶¾Á÷´«Í¾¾¶Ö÷ÒªÓÐRDP¡¢VNC;¾¶½øÐб©Á¦ÆƽâºÍÈëÇÖ¡¢¶¨ÏòÓã²æµöÓãÓʼþͶ·Å¡¢À¦°ó¶ñÒâÈí¼þºÍÍøÒ³¹ÒÂí¹¥»÷¡¢½©Ê¬ÍøÂçÒÔ¼°Â©¶´ÀûÓÃÁ÷´«µÈ¡£
Ä¿Ç°ÔÚ°µÍøÖУ¬¡°ÏÀµÁ¡±Ä»ºóÍŶӽÓÄÉ¡°ÀÕË÷¼´·þÎñ¡±£¨¡°ransomware as-a-service¡± £©µÄ·½Ê½£¬ÏòºÚ¿Í·ÅËÁÊÛÂôV5.3°æ±¾²¡¶¾£¬¼´ÓÉ¡°ÏÀµÁ¡±ÍŶÓÌṩ²¡¶¾£¬ºÚ¿ÍÔÚÈ«ÇòÑ¡ÔñÄ¿±ê½øÐй¥»÷ÀÕË÷£¬¹¥»÷ÀÖ³Éºó ¡°ÏÀµÁ¡±ÍŶÓÔÙ´ÓÖгéÈ¡30%-40%µÄÀûÈ󡣡°À¬»øÓʼþÖÆÔìÕßÃÇ£¬ÄãÃÇÏÖÔÚ¿ÉÒÔÓëÍøÂçר¼Ò½øÐкÏ×÷£¬²»Òª´íʧ»ñÈ¡ÃÀºÃÉú»îµÄÃÅƱ£¬ÎÒÃÇÔÚµÈÄã¡£¡±ÊÇ¡°ÏÀµÁ¡±ÍŶÓÔÚ°µÍøÖдò³öµÄ¡°ÕÐÉ̹ã¸æ¡±¡£
¡°ÏÀµÁ¡±ÊÇÄ¿Ç°µÚÒ»¸öÀÕË÷´ïÊÀ±ÒµÄÀÕË÷²¡¶¾£¬ºóÀ´²Å¼ÓÁ˱ÈÌرң¬Òª¼Û500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£¾Ý¡°ÏÀµÁ¡±ÍŶÓ2018Äê12ÔÂÐû²¼µÄÊý¾Ý£¬Æä×ܼÆÊÕÈë±ÈÌرÒÒÔ¼°´ïÊÀ±ÒºÏ¼ÆÒѸߴï285ÍòÃÀÔª¡£
3¡¢ÆƽâÀúÊ·
Ïñ´ó²¿ÃÅÀÕË÷ÎļþÒ»Ñù£¬¡°ÏÀµÁ¡±Ê¹ÓÃÁËRSA¼ÓÃÜËã·¨£¬³ý·ÇÄõ½ºÚ¿Í³ÖÓеÄRSA-2048˽Կ£¬²ÅÆø¹»¶ÔѬȾÎļþ½øÐнâÃÜ£¬·ñÔòÎÞ·¨½âÃÜ¡£
ÒòΪ¡°ÏÀµÁ¡±Ê¼þ£¬¹¥»÷Õ߷ųöÁËÀÕË÷²¡¶¾²¿ÃÅÔçÆÚ°æ±¾µÄ½âÃÜÃÜÔ¿£¬¶à¸öÄþ¾²³§ÉÌËæºóÏà¼ÌÐû²¼Á˽âÃܹ¤¾ß¡£´Ó18Äê10Ôµ½½ñÄê2Ô£¬BitdefenderÏȺóÐû²¼ÁË¡°ÏÀµÁ¡±¶à¸ö°æ±¾µÄ½âÃܹ¤¾ß£¬×îеĽâÃܹ¤¾ßÏÂÔصØַΪ£ºhttps://labs.bitdefender.com/wp-content/uploads/downloads/gandcrab-removal-tool-v1-v4-v5/£¬¸Ã¹¤¾ß¿ÉÒÔ½âÃܵİ汾Èç±í1Ëùʾ¡£Æä½âÃÜÔÀíÊÇͨ¹ýÔÚÏßÏòBitdefender·þÎñÆ÷Ìá½»¼ÓÃÜID£¬À´»ñÈ¡¿ÉÓõĽâÃÜ˽Կ£¨ RSA-2048£©À´½øÐнâÃÜ¡£Óû§¿ÉÒÔƾ¾Ý±íÖеļÓÃÜÎļþºó׺»òÀÕË÷˵Ã÷Îı¾ÎļþµÄ¿ªÊ¼À´ºË¶Ô²¡¶¾°æ±¾¡£
ÇøÓò±êÖ¾·û | ÓïÑÔ£¨¹ú¼Ò£© |
0x419 | ¶íÓ¶íÂÞ˹£© |
0x422 | ÎÚ¿ËÀ¼ÓÎÚ¿ËÀ¼£© |
0x423 | °×¶íÂÞ˹Ó°×¶íÂÞ˹£© |
0x428 | Ëþ¼ª¿Ë |
0x42B | ÑÇÃÀÄáÑÇÓÑÇÃÀÄáÑÇ£© |
0x42C | °¢ÔóÀïÓ°¢Èû°Ý½®£¬À¶¡Ó |
0x437 | ¸ñ³¼ªÑÇÓ¸ñ³¼ªÑÇ£© |
0x43F | ¹þÈø¿ËÓ¹þÈø¿Ë˹̹£© |
0x440 | ¼ª¶û¼ªË¹Ó¼ª¶û¼ªË¹Ì¹£© |
0x442 | ÍÁ¿âÂü |
0x443 | ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹£¬À¶¡Ó |
0x444 | ÷²÷°Ó¶íÂÞ˹£© |
0x818 | ÂÞÂíÄáÑÇÓĦ¶û¶àÍßµØÓò£© |
0x819 | ¶íÓĦ¶û¶àÍßµØÓò£© |
0x82C | °¢ÔóÀïÓ°¢Èû°Ý½®£¬Î÷Àï¶ûÓ |
0x843 | ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹£¬Î÷Àï¶ûÓ |
0x45A | ÐðÀûÑÇÓÐðÀûÑÇ£© |
0x2801 | °¢À²®ÓÐðÀûÑÇ£© |
±í2 ÅųýµÄÓïÑÔ£¨¹ú¼Ò£©
5.2 ÖÕÖ¹Äþ¾²Èí¼þ
¡°ÏÀµÁ¡±±éÀúѬȾÉ豸ϵͳ½ø³Ì£¬Èç¹û·¢ÏÖѬȾÉ豸ÓÐÔËÐп¨°Í˹»ù¡¢Åµ¶ÙµÈÄþ¾²Èí¼þ£¬¾ÍÇ¿ÖƽáÊøµôÄ¿±ê½ø³Ì£¬·ÀÖ¹×Ô¼º±»É±¶¾Èí¼þ²éɱ¡£Ïà¹ØµÄÄþ¾²Èí¼þÈçÏÂͼ4Ëùʾ¡£
ͼ4 Ïà¹ØÄþ¾²Èí¼þ½ø³Ì
5.3 ÖÕÖ¹Ìض¨·¨Ê½
¡°ÏÀµÁ¡±»á±éÀúѬȾÉ豸ϵͳµ±Ç°½ø³ÌÁÐ±í£¬Èç¹ûÆ¥Åäµ½Ö¸¶¨µÄ½ø³ÌÔò½áÊø¸Ã½ø³Ì£¬ÒÔ·ÀÖ¹ÒÅ©µôÒòÓû§Îļþ±»Õ¼Óöø²»Äܱ»¼ÓÃܵÄÓû§Îļþ¡£ÈçWord¡¢Excel¡¢PowerPoint¡¢Onenote¡¢Visio¡¢Oracle¡¢SQLserver¡¢MySQLµÈ³£¼ûÓ¦Óýø³Ì£¬ÏêϸĿ±ê½ø³ÌÈçͼ5Ëùʾ£º
ͼ5 ÖÕÖ¹µÄÄ¿±ê½ø³Ì
5.4 È·¶¨¼ÓÃÜÎļþÀàÐÍ
5.4.1 Îļþºó׺°×Ãûµ¥
ΪÁËÅųýµôûÓмÛÖµµÄÀÕË÷Êý¾ÝÎļþ£¬¡°ÏÀµÁ¡±ÄÚÖÃÁËÒ»·ÝÎļþºó׺°×Ãûµ¥£¬Èçͼ6Ëùʾ¡£ÎÒÃǽ«ÆäÁе½±í3ÖУ¬ÆäÖаüÂÞµÄÎļþÓпÉÖ´ÐÐÎļþ¡¢ÏµÍ³¶¯Ì¬µ÷ÓÿâÎļþ¡¢ÏµÍ³Çý¶¯ÎļþºÍ¡°ÏÀµÁ¡±Ïà¹ØµÄÎļþµÈ¡£
ͼ6 ²»¼ÓÃܵÄÎļþÀàÐÍ
°×Ãûµ¥Â·¾¶ |
"\\ProgramData\\" |
"\\IETldCache\\" |
"\\Boot\\" |
"\\Program Files\\" |
"\\Tor Browser\\" |
"\\All Users\\" |
"\\Local Settings\\" |
"\\Windows\\" |
±í4 ϵͳĿ¼°×Ãûµ¥
±í5ÖеÄϵͳÎļþÒ²²»ÔÚ¼ÓÃÜÄ¿±êÖ®ÁУº
¼ÓÃܵÄÎļþºó׺ |
.1st .602 .docb .xlm .xlsx .xlsm .xltx .xltm .xlsb .xla .xlam .xll .xlw .ppt .pot .pps .pptx .pptm .potx .potm .ppam .ppsx .ppsm .sldx .sldm .xps .xls .xlt ._doc .dotm ._docx .abw .act .adoc .aim .ans .apkg .apt .asc .asc .ascii .ase .aty .awp .awt .aww .bad .bbs .bdp .bdr .bean .bib .bib .bibtex .bml .bna .boc .brx .btd .bzabw .calca .charset .chart .chord .cnm .cod .crwl .cws .cyi .dca .dfti .dgs .diz .dne .dot .doc .docm .dotx .docx .docxml .docz .dox .dropbox .dsc .dvi .dwd .dx .dxb .dxp .eio .eit .emf .eml .emlx .emulecollection .epp .err .err .etf .etx .euc .fadein.template .faq .fbl .fcf .fdf .fdr .fds .fdt .fdx .fdxt .fft .fgs .flr .fodt .fountain .fpt .frt .fwd .fwdn .gmd .gpd .gpn .gsd .gthr .gv .hbk .hht .hs .hwp .hwp .hz .idx .iil .ipf .ipspot .jarvis .jis .jnp .joe .jp1 .jrtf .jtd .kes .klg .klg .knt .kon .kwd .latex .lbt .lis .lnt .log .lp2 .lst .lst .ltr .ltx .lue .luf .lwp .lxfml .lyt .lyx .man .mbox .mcw .md5 .me .mell .mellel .min .mnt .msg .mw .mwd .mwp .nb .ndoc .nfo .ngloss .njx .note .notes .now .nwctxt .nwm .nwp .ocr .odif .odm .odo .odt .ofl .opeico .openbsd .ort .ott .p7s .pages .pages-tef .pdpcmd .pfx .pjt .plain .plantuml .pmo .prt .prt .psw .pu .pvj .pvm .pwd .pwdp .pwdpl .pwi .pwr .qdl .qpf .rad .readme .rft .ris .rpt .rst .rtd .rtf .rtfd .rtx .run .rvf .rzk .rzn .saf .safetext .sam .sam .save .scc .scm .scriv .scrivx .sct .scw .sdm .sdoc .sdw .se .session .sgm .sig .skcard .sla .sla.gz .smf .sms .ssa .story .strings .stw .sty .sublime-project .sublime-workspace .sxg .sxw .tab .tab .tdf .tdf .template .tex .text .textclipping .thp .tlb .tm .tmd .tmdx .tmv .tmvx .tpc .trelby .tvj .txt .u3i .unauth .unx .uof .uot .upd .utf8 .utxt .vct .vnt .vw .wbk .webdoc .wn .wp .wp4 .wp5 .wp6 .wp7 .wpa .wpd .wpd .wpd .wpl .wps .wps .wpt .wpt .wpw .wri .wsd .wtt .wtx .xbdoc .xbplate .xdl .xdl .xwp .xwp .xwp .xy .xy3 .xyp .xyw .zabw .zrtf .zw.rar .zip .cab .arj .lzh .tar .7z .gzip .iso .z .7-zip .lzma .vmx .vmdk .vmem .vdi .vbo |
5.5 ¼ÓÃÜÓû§Îļþ
¡°ÏÀµÁ¡±»á±éÀúѬȾÉ豸¹²ÏíĿ¼ºÍµ±µØ´ÅÅÌ¡£½ÓÄÉRSA-2048+Salsa20Ëã·¨¼ÓÃÜѬȾÉ豸Îļþ¡£
¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþÈçͼ8Ëùʾ£º
ͼ8 ¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþ
¼ÓÃܵ±µØ´ÅÅÌĿ¼ÏÂÎļþÈçͼ9Ëùʾ£º
ͼ9 ¼ÓÃܵ±µØ´ÅÅÌĿ¼ÏÂÎļþ
5.6 Éú³ÉMANUALÎļþ
¡°ÏÀµÁ¡±ÏȽ«ÀÕË÷ÐÅÏ¢½âÃܵ½ÄÚ´æÖУ¬ÔÚ½øÐа汾ºÍºó׺ÐÅϢƴ½Óºó£¬½«Õû¸öÀÕË÷ÐÅϢдÈëMANUALÎļþÖУ¬Èçͼ10ºÍͼ11Ëùʾ£º
ͼ11 ½âÃܵ½ÄÚ´æÖеÄÀÕË÷ÐÅÏ¢
×îÖÕµÄMANUALÎļþÓÉÀÕË÷ÐÅÏ¢¡¢¼ÓÃܺóµÄ˽ԿÐÅÏ¢ºÍ¼ÓÃܺóµÄѬȾÉ豸ÐÅÏ¢×é³É¡£ÆäÖкڿÍÌØÒâÇ¿µ÷Êܺ¦Óû§²»ÒªÐÞ¸Ä˽ԿÐÅÏ¢ÄÚÈÝ£¬ÒòΪһµ©Ë½Ô¿ÐÅÏ¢Ò»µ©±»¸Ä±ä£¬¾ÍÎÞ·¨¶ÔÎļþ½øÐнâÃÜ¡£
5.7 Ì滻ѬȾÉ豸×ÀÃæ
´´½¨ÀÕË÷×ÀÃæ±ÚÖ½µ½¡°C:\Documents and Settings\[username]\LocalSettings\Temp\bxmeoengtf.bmp¡±,Èçͼ12Ëùʾ£º
ͼ12 ´´½¨ÀÕË÷ͼƬ£¬ÉèÖÃÀÕË÷×ÀÃæ
ͼ13ÖУ¬ÀÕË÷ͼƬÉÏдÓС°YOURFILES ARE UNDER STRONG PROTECTION BY OUR SOFTWARE. IN ORDER TO RESTORE IT YOUMUST BUY DECRYPTOR£¬For further stepsread %s-DECRYPT.%s that is located in every encrypted folder¡±£¬ÌáʾѬȾÓû§ÔĶÁManualÎļþÖ§¸¶Êê½ð¡£
ͼ13 ÀÕË÷±ÚÖ½
5.8 ɾ³ý¾íÓ°¿½±´
¡°ÏÀµÁ¡±»áɾ³ýѬȾ¼ÆËã»ú¾íÓ°¸±±¾£¬ÕâÊÇÀÕË÷²¡¶¾µÄͨÀý²Ù×÷£¬ÕâÑù×öµÄÄ¿µÄÊÇ·ÀÖ¹Êܺ¦Óû§Í¨¹ýWindows Recovery¶ÔÎļþ½øÐлָ´£¬Èçͼ14¡£
ͼ14 ɾ³ý¾íÓ°¸±±¾
Èçͼ15£¬¡°ÏÀµÁ¡±µ÷Óá°shell32.ShellExecuteW¡±Ö´ÐÐÃüÁî¡°/c vssadmin delete shadows /all /quiet¡±
ͼ15 Ö´ÐÐɾ³ýÃüÁî
5.9 Á¬½ÓC&C
¡°ÏÀµÁ¡±»á·ÃÎÊÖ¸¶¨ÓòÃûµÄ80ºÍ443¶Ë¿Ú£¬¡°ÏÀµÁ¡±ÔÚÁ¬½ÓºÚ¿Í¿ØÖƵÄÔ¶³Ì·þÎñÆ÷£¨Èçhttp://www.kakaocorp.link£©Àֳɺó£¬ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍѬȾÉ豸ÐÅÏ¢£¬Èçͼ16¡£
ͼ16 ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍѬȾÉ豸ÐÅÏ¢
ÆäÖУ¬rc4keyΪ".oj=294~!z3)9n-1,8^)o((q22)lb$"
strPCdataÉú´æÔÚ¡±*-MANUAL.txt¡±ÎļþÖУ¨*ÌåÏÖ´óдµÄ¼ÓÃÜÎļþºó׺Ãû£©£¬¼ûͼ18£º
ͼ18 Base64´æ´¢µÄPCÏà¹ØÃÜÎÄÐÅÏ¢
ÓÉÓÚC&CʧЧ£¬ËùÓÐÎÒÃÇûÓÐ×¥µ½·¢ËÍ·¢ËÍstrPCdataµÄÊý¾Ý°ü¡£
6.2 ½âÃÜpubkey
¡°ÏÀµÁ¡±ÏÈÉú³É64×Ö½ÚÁ÷input3£¨ÓÉSalsakey3£¨ÀιÌ×Ö½Ú£©ºÍIV3£¨ÀιÌ×Ö½Ú£©ºÍ³£Á¿×é³É£©£¬Èçͼ19:
ͼ19 Éú³ÉµÄinput3
¡°ÏÀµÁ¡±ÔÚʹÓÃSalsa20Ëã·¨½âÃܺڿ͵ÄRSA2048¹«Ô¿£¬ÎÒÃǽ«¹«Ô¿ÃÜÎļÇΪpubkeyEncrypted£¬½«½âÃܺóµÄ¹«Ô¿¼ÇΪhackerPubkey£¬Ëã·¨ÈçÏ£º
hackerPubkey= Salse20(input3, pubkeyEncrypted)
hackerPubkeyEncrypted¼ûͼ20£º
ͼ20 ½âÃÜÇ°µÄhackerPubkey
½âÃܵõ½hackerPubkey¼ûͼ21£¬¶Ô±È¡°ÏÀµÁ¡±5.2µÄºÚ¿Í¹«Ô¿£¨Í¼22£©£¬ÎÒÃÇ·¢ÏÖÔÚ5.3°æ±¾Öкڿ͸üÐÂÁËÆä³ÖÓеĹ«Ô¿¡£
ͼ22 GandCrab5.2 ºÚ¿Í¹«Ô¿
6.3 µ±µØÉú³ÉRSA¹«Ë½«h¶Ô
ºÚ¿ÍÀûÓÃ΢Èí¡°advapi32¡±¿âº¯Êýµ±µØÉú³ÉRSA-2048¹«Ë½«h¶Ô£¬ÎÒÃÇ·Ö±ð¼ÇΪlocPubkeyºÍlocPrikey£¬Õë¶Ôÿ¸öѬȾÕßµ±µØ¹«Ë½«h¶ÔÖ»Éú³ÉÒ»´Î¡£ÆäÖУ¬locPubkeyÓÃÓÚ¼ÓÃÜSalsaFileKeyºÍIV2£¬¶ølocPrikeyʹÓÃSalsa20Ëã·¨¼ÓÃܺó×îÖÕÉú´æµ½µ±µØ¡£
locPubkey£¨0x114×Ö½Ú£©¼ûͼ23:
ͼ23 ÄÚ´æÖеÄlocPubkey
locPrikey£¨0x494×Ö½Ú£©¼ûÏÂͼ24£º
ͼ24 ÄÚ´æÖеÄlocPrikey
6.4 ¼ÓÃܵ±µØ˽Կ
¡°ÏÀµÁ¡±Ê×ÏÈÉú³ÉSalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©£¬Ôٺͳ£Á¿Ò»ÆðÉú³É64×Ö½ÚÊäÈëÁ÷£¬ÎÒÃǼÇΪinput1£¬È»ºó£¬¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜlocPrikey£¬Ëã·¨ÈçÏ£º
data3 = Salsa20(input1,locPrikey)
SalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©·Ö±ð±»ºÚ¿ÍµÄ¹«Ô¿¼ÓÃÜ£¬ÈçÏÂ:
data2 = RSA2048(hackerPubkey, IV1)
×îºó£¬¡°ÏÀµÁ¡±½«¡°data1¡±¡¢¡°data2¡±¡¢¡°data3¡±base64¼ÓÃܺóÉú´æÔÚµ±µØ£¬ÈçÏÂ(ÆäÖÐ0x00000494ΪlocPrikey³¤¶È)£º
gandcrabKey=base64encode(0x00000494+ data1+ data2+ data3)
Éú´æÔÚ¡°****-MANUAL.txt¡±ÎļþÖУ¬Èçͼ25£º
ͼ25 Base64´æ´¢µÄµ±µØRSA-2048˽ԿÃÜÎÄÐÅÏ¢
6.5 ¼ÓÃÜѬȾÕßÎļþ
¡°ÏÀµÁ¡±µÚÒ»²½Éú³ÉSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©¡¢IV2£¨8×Ö½ÚËæ»úÊý£©ÒÔ¼°³£Á¿Éú³ÉµÄ64×Ö½ÚÊäÈëÁ÷£¬ÎÒÃǼÇΪinput2£¬input2Õë¶Ôÿһ¸öÓû§Îļþ¶¼Î¨Ò»Éú³É£¬È»ºó¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜÓû§Îļþ£¬Ëã·¨ÈçÏ£º
data4 = Salsa20(input2,userFile)
µÚ¶þ²½Óõ±µØ¹«Ô¿locPubkey¼ÓÃÜSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©ºÍIV2£¨8×Ö½ÚËæ»úÊý£©£¬Ëã·¨ÈçÏ£º
data6 = RSA2048(locPubkey, IV2)
×îºó£¬¡°ÏÀµÁ¡±½«¡°data4¡±¡¢¡°data5¡±¡¢¡°data6¡±ºÍÀι̵Ä×Ö½ÚÆ´½Ó³É¼ÓÃÜÎļþ£¬ÈçÏÂ(ÆäÖÐlenUserFileΪÓû§ÔʼÎļþ¾Þϸ)£º
finalFile=data4 +data5+data6+lenUserFile+ÀιÌ×Ö½Ú
¼ÓÃܺóµÄÎļþ½á¹¹Èçͼ26£º
7.×ܽáÓ뽨Òé
ÒòΪ´ó²¿ÃÅÀÕË÷²¡¶¾¼ÓÃܺóµÄÎļþ¶¼ÎÞ·¨½âÃÜ£¬ËùÒÔÓ¦¶ÔÀÕË÷²¡¶¾ÒÔÔ¤·ÀºÍ±¸·ÝΪÖ÷¡£½¨ÒéÓû§×öºÃÈÕ³£µÄ·À·¶´ëÊ©£º
- ¼°Ê±¸üвÙ×÷ϵͳ£¬¼°Ê±¸ø¼ÆËã»ú´ò²¹¶¡¡£
- ¶ÔÖØÒªµÄÊý¾ÝÎļþÒª½øÐÐÒìµØ±¸·Ý¡£
- ¾¡Á¿¹Ø±Õ²»ÐëÒªµÄÎļþ¹²Ïí£¬»ò°Ñ¹²Ïí´ÅÅÌÉèÖÃΪֻ¶ÁÊôÐÔ£¬²»ÔÊÐí¾ÖÓòÍøÓû§¸ÄдÎļþ¡£
- ¾¡Á¿¹Ø±Õ²»ÐëÒªµÄ·þÎñºÍ¶Ë¿Ú¡£È磺135£¬139£¬445¶Ë¿Ú£¬¶ÔÓÚÔ¶³Ì×ÀÃæ·þÎñ£¨3389£©£¬VNC·þÎñÐèÒª½øÐа×Ãûµ¥ÉèÖ㬽öÔÊÐí°×Ãûµ¥ÄÚµÄIPµÇ½¡£
- ½ÓÄɲ»ÉÙÓÚ10λµÄ¸ßÇ¿¶ÈÃÜÂ룬²¢¶¨ÆÚ¸ü»»ÃÜÂ룬ͨ¹ýwindows×é¼ÆıÅäÖÃÕË»§Ëø¶¨¼Æı£¬¶Ô¶Ìʱ¼äÄÚÁ¬ÐøµÇ½ʧ°ÜµÄÕË»§½øÐÐËø¶¨¡£
- °²×°¾ß±¸×Ô±£»¤¹¦Ð§µÄ·À²¡¶¾Èí¼þ£¬²¢¼°Ê±¸üв¡¶¾¿â»òÈí¼þ°æ±¾¡£
- ¼ÓÇ¿Ô±¹¤Äþ¾²ÒâʶÅàѵ£¬²»ÇáÒ×´ò¿ªÄ°ÉúÓʼþ»òÔËÐÐÀ´Ô´²»Ã÷µÄ·¨Ê½£¬ÇжÏÀÕË÷²¡¶¾µÄÓʼþÁ÷´«·½Ê½¡£