Shade(Troldesh)ÀÕË÷°ä·¢Í£Ô˲¢·Å³ö75Íò¸ö½âÃÜÃÜÔ¿

°ä²¼¹¦·ò 2020-04-30

0x00 ÊÂÎñ²¼¾°


ÀÕË÷Èí¼þShade±³ºó×éÖ¯ÓÚÖÜÄ©°ä·¢ÊÕÊÖ £¬²¢ÔÚGitHubÉϰ䲼Á˳¬¹ý75Íò¸ö½âÃÜÃÜÔ¿¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¿¨°Í˹»ù³¢ÊÔÊҵݲȫ×êÑÐÈËÔ±ÒѾ­Ö¤ÊµÏàʼûÜÃÜÔ¿µÄÓÐЧÐÔ £¬²¢ÇÒÔÚÖÂÁ¦ÓÚ´´½¨Ãâ·ÑµÄ½âÃܹ¤¾ß¡£

ÔÚGitHub´æ´¢¿âÖа䲼µÄ¶ÌÐÂÎÅÖУ¨https://github.com/shade-team/keys£© £¬ShadeÍŶÓÚ¹ÊÏç˵¼ÖÂËûÃÇ×ö³ö¾ö¶¨µÄÔ­Òò¡£

¡°ÎÒÃÇÊÇÒ»¸öÍÅ¶Ó £¬¿ª·¢ÁËÒ»¸öľÂí¼ÓÃÜ·¨Ê½ £¬Í¨³£±»³ÆÎªShade £¬Troldesh»òEncoder.858¡£ÏÖʵÉÏ £¬ÎÒÃÇÒÑÔÚ2019Äêµ×ÖÕ³¡·Ö·¢¡£´Ë¿Ì £¬ÎÒÃǾö¶¨Îª´ËÊ»­ÉϾäºÅ £¬²¢°ä²¼ÎÒÃÇÕ¼ÓеÄËùÓнâÃÜÃÜÔ¿£¨×ܹ²³¬¹ý750,000¸ö£©¡£ÎÒÃÇ»¹½«°ä²¼½âÃÜÈí¼þ¡£ÎÒÃÇ»¹µ«Ô¸ £¬ÓÐÁËÃÜÔ¿ £¬·À²¡¶¾¹«Ë¾½«ÄÜ¿ª·¢²¢°ä²¼Ô½·¢Óû§¶ØÄÀµÄ½âÃܹ¤¾ß¡£ÓëGA»Æ½ð¼×»î¶¯ÓйصÄËùÓÐÆäËûÊý¾Ý£¨Ô̺¬ÌØÂåÒÁľÂíµÄÔ´´úÂ룩¾ù±»²»³É²Ã³·µØÏú»Ù¡£ÎÒÃÇÏòËùÓÐÌØÂåÒÁľÂíÊܺ¦ÕßÖÂǸ £¬²¢µ«Ô¸ÎÒÃǰ䲼µÄÃÜÔ¿¿ÉÄÜÔ®ÊÖËûÃǸ´Ô­Êý¾Ý¡£¡±

¾­ÑéÖ¤ £¬Õâ´Î°ä²¼µÄ½âÃÜÃÜÔ¿¿ÉÒÔΪËùÓб»ÀÕË÷Èí¼þShade¼ÓÃܵÄÎļþ½âÃÜ¡£


0x01 Shade¼ò½é


Shade×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬ÆäʱÔÚ¶íÂÞ˹·¢ÏÖÁË´ó¹æÄ£µÄϰȾ¡£ShadeϰȾÔÚ2018Äê10ÔÂÆÚ¼äÓÐËùÔö³¤ £¬Ò»Ïò³ÖÐøµ½2018Äê12ÔÂϰëÔ £¬ÔÚÊ¥µ®½ÚÆÚ¼äÐÝÏ¢ £¬¶øºóÔÚ2019Äê1ÔÂÖÐÑ®¸´Ô­Ôö³¤Ò»±¶¡£2019Äê5ÔÂ×êÑÐÈËÔ±ÓÖ·¢ÏÖÁËÐÂÒ»²¨ShadeÀÕË÷Èí¼þ¹¥»÷ £¬Ô̺¬ÃÀ¹úºÍÈÕ±¾¡£ÊÜShadeÀÕË÷Èí¼þÓ°ÏìµÄǰÎå¸ö¹ú¶ÈÊÇÃÀ¹ú £¬ÈÕ±¾ £¬Ó¡¶È £¬Ì©¹úºÍ¼ÓÄôó £¬ÖØÒªÕë¶Ô¸ß¿Æ¼¼¡¢Åú·¢ºÍ½ÌÓýÐÐÒµ¡£

ShadeϰȾָ±êÊÇÔËÐÐ Microsoft Windows µÄÖ÷»ú¡£Í¨³£Í¨¹ýÀ¬»øÓʼþ£¨³ö¸ñÊǶñÒâµç×ÓÓʼþ¸½¼þ£©´«²¼¡£¸½¼þͨ³£ÊÇzipÎļþ £¬ÊÕ¼þÈ˽âѹËõ¸½¼þ²¢Ë«»÷¸ÃÎļþ £¬ÀÕË÷Èí¼þÆðÍ·ÔËÐС£ÆäÖÐÌáÈ¡µÄzipÄÚÈÝÊÇÒ»¸öJavascript¾ç±¾ £¬ÓÃÀ´ÏÂÔØ¶ñÒâpayload£¨ÀÕË÷Èí¼þ£© £¬¸Ãpayloadͨ³£ÍйÜÔÚCMSÕ¾µãÉÏ¡£

Ò»µ©ÏµÍ³Êܵ½Ï°È¾ £¬¶ñÒâ´úÂë¾Í»áÉèÖÃ×ÀÃæ²¼¾°À´°ä·¢Ï°È¾ £¬²¢ÇÒ½«ÃûΪREADME1.txtµ½README10.txtµÄDesktop 10¸öÎı¾Îļþ·ÅÔÚ×ÀÃæÉÏ £¬ÔÚREADME.txtÎļþÖоÍÔ̺¬ÓйØÍ¨¹ýµç×ÓÓʼþµØÖ·ÓëºÚ¿ÍÁªÏµµÄÅúʾ £¬ÒԱ㹵ͨÊê½ðÊÂÒË¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Shade¼ÓÃÜ·½Ê½Êǽ«ÎļþÔÚCBCģʽÏÂʹÓÃAES 256¼ÓÃÜ¡£¶ÔÓÚÿ¸ö¼ÓÃÜÎļþ £¬½«ÌìÉúÁ½¸öËæ»úµÄ256λAESÃÜÔ¿£ºÒ»¸öÓÃÓÚ¼ÓÃÜÎļþµÄÄÚÈÝ £¬ÁíÒ»¸öÓÃÓÚ¼ÓÃÜÎļþÃû¡£


0x02 ½âÃÜÃØÔ¿


½âÃÜÃØÔ¿ÏÂÔØ£ºhttps://github.com/shade-team/keys

ÏÂÔØ¾µÏñ£º

? https://yadi.sk/d/36uVFJ6bUBrdpQ £¨ËùÓÐÃÜÔ¿·Ö¸ô£»zipÖеÄËùÓÐÃÜÔ¿£»Èí¼þ£©

? https://cloud.mail.ru/public/5gy6/4UMfYqAp4 £¨ËùÓÐÃÜÔ¿·Ö¸ô£»zipÖеÄËùÓÐÃÜÔ¿£»Èí¼þ£©

? https://drive.google.com/open?id=1iA2KquslytIE83mwzlXPcL3u8Z0yoqat£¨zipÖÐµÄ ËùÓÐÃÜÔ¿£»Èí¼þ£©

? https://github.com/shade-team/keys £¨ËùÓÐÃÜÔ¿·Ö¸ô£©

? https://github.com/shade-binary/bin £¨Èí¼þ£©


0x03 ½âÃÜ×¢Ã÷


°ÑÎÈ£ºÄ³Ð©·À²¡¶¾Èí¼þ»á¼ì²âµ½Ä³Ð©ÒѰ䲼µÄÈí¼þ £¬ÓÉÓÚËüÓë¼ÓÃÜÆ÷һ·ʹÓÃÁ˳£¼ûµÄ´úÂë¿é¡£ÎªÔ¤·Àɾ³ýËüÃÇ £¬ËùÓÐexeÎļþ¾ùʹÓÃÒ»ÑùµÄÃÜÂëѹËõ£º123454321

ÈôÊÇÄúµÄ¼ÓÃÜÎļþÓµÓÐÒÔÏÂÀ©´óÃûÖ®Ò» £¬ÔòÔÚºóÐø²½ÖèÖÐ £¬Äú½«±ØÒª¡°keys¡±Îļþ¼ÐÖеġ°main¡±×ÓÎļþ¼Ð£º

? xtbl

? ytbl

? breaking_bad

? Heisenberg

? better_call_saul

? los_pollos

? da_vinci_code

? magic_software_syndicate

? windows10

? windows8

? no_more_ransom

? Tyson

? crypted000007

? crypted000078

? rsa3072

? decrypt_it

ÈôÊÇÄúµÄ¼ÓÃÜÎļþÓµÓÐÒÔÏÂÀ©´óÃûÖ®Ò» £¬ÔòÔÚºóÐø²½ÖèÖÐ £¬Äú½«±ØÒª¡°keys¡±Îļþ¼ÐÖеġ°alt¡±×ÓÎļþ¼Ð£º

? dexter

? miami_california

ËùÐèµÄ×ÓÎļþ¼Ð±ÉÈËÃæ°µÊ¾Îª¡£¡°master¡±×ÓÎļþ¼ÐºÏÓÃÓÚijЩ·À²¡¶¾¹«Ë¾ £¬ËûÃÇÒѾ­±»·î¸æÒªÊ¹ÓøÃÎļþ¼Ð¡£

1. Ç¿ÁÒ½¨Ò鹨¹ØÍÆËã»úÉϵÄËùÓз¨Ê½£¨Ô̺¬É±¶¾Èí¼þ£© £¬²¢Ô¤·ÀÔÚ½âÃܹý³ÌÖÐÖ´ÐÐÈÎºÎÆäËû²Ù×÷¡£ÈôÊÇÄúÕ¼ÓÐÍÆËã»úµÄID £¬Çëתµ½µÚ2¶Î¡£²»È» £¬Çëתµ½µÚ3¶Î¡£´ËIDÊÇÒ»¸ö20¸ö·ûºÅµÄ×Ö·û´® £¬Ô̺¬´óд×ÖĸºÍÊý×Ö£¨ÀýÈçAABBCCDDEEFF00112233£© £¬²¢±£ÁôÔŲ́ʽ»úºÍREADME.txtÎļþÖС£ËùÓдÅÅ̵ĸùÎļþ¼Ð¡£ÔÚ¸ü¸ß°æ±¾µÄ¼ÓÃÜÈí¼þÖÐ £¬ÎļþÃûÖ®ºóÒ²Ôö³¤ÁËID¡£

2. ÈôÊÇREADME.txtÎļþÖеĴúÂëÔÚÊúÏߺóÔ̺¬Á㣨ÀýÈçAABBCCDDEEFF00112233|0£© £¬Çë³ÖÐøÖ´ÐеÚ2.1¶Î¡£ÈôÊÇREADME.txtÎļþÖеĴúÂëÔ̺¬Èý¸öÊúÏߣ¨ÀýÈçAABBCCDDEEFF00112233|765|8|1£© £¬Çë³ÖÐøÖ´ÐеÚ2.2¶Î¡£

2.1 ½øÈë/keys//dynamic//Îļþ¼Ð £¬ÆäÖÐÊÇ´úÂëµÄµÚÒ»¸ö·ûºÅ£¨ÔÚGA»Æ½ð¼×ʾÀýÖÐΪA£©¡£/keys/alt/dynamic/Îļþ¼Ð½«ËùÓÐÎļþ¶¼Ô̺¬ÔÚÄÚ £¬¶øÎÞÐè°´´úÂëµÄÊ××Öĸ½øÐл®·Ö¡£ÕÒµ½Ãû³ÆÔ̺¬ÄúµÄIDµÄ.txtÎļþ²¢ÏÂÔØ£¨ÈôÊÇÓжà¸öÕâÑùµÄÎļþ £¬ÇëÏÂÔØËùÓÐÎļþ £¬¶øºó¶Ôÿ¸öÎļþ³Á¸´Õû¸ö½âÃܹý³Ì£©¡£ÄúÄܹ»Ê¹ÓÃÍøÒ³ÉϵÄËÑË÷£¨ä¯ÀÀÆ÷ÖеÄCtrl + F×éºÏ¼ü£©À´¼Ó¿ìËÑË÷¹ý³Ì¡£ÈôÊÇÕÒµ½Îļþ £¬Çë³ÖÐøÖ´ÐеÚ4¶Î¡£

2.2 ½øÈë/keys//static/Îļþ¼Ð £¬¶øºóÕÒµ½Ãû³ÆÎª´úÂëµÚÒ»¸öÊúÏߺóµÄÊý×ÖµÄÎļþ£¨ÔÚGA»Æ½ð¼×ʾÀýÖÐΪ765£©¡£ÏÂÔØËü²¢³ÖÐøÖ´ÐеÚ4¶Î¡£

3. ÏÂÔØ²¢Ö´ÐÐ/bin/getid.exe·¨Ê½¡£Ëü»áÏÔʾÄúµÄID £¬¶øºóÄúÓ¦¸Ãתµ½ËüµÄµÚ2¶Î¡£ÈôÊÇÕâÑù×öûÓÐÔ®ÊÖ £¬Çë³¢ÊÔÖ´ÐÐ3.1¶ÎÂäÖеÄ×¢Ã÷¡£

3.1 ÔÚÍÆËã»úÉÏ´´½¨Ò»¸öÎļþ¼Ð £¬Æäõè¾¶½öÔ̺¬Ó¢ÎÄ×Öĸ»òÊý×Ö¡£ÏÂÔØÎļþ/bin/decrypt_bruteforce.exe £¬½«Æä±£Áôµ½´ËÎļþ¼Ð²¢ÔÚÆäÖд´½¨Îļþ¼Ó×°keys¡±¡£¶øºó´Ó/keys//static/Îļþ¼ÐÏÂÔØËùÓÐÎļþ £¬²¢½«ËüÃÇ·ÅÔÚ¡°keys¡±Îļþ¼ÐÖС£È¡³öÈκμÓÃÜÎļþ £¬²¢½«Æä·ÅÈëc:\1\Îļþ¼Ð¡£ÔËÐÐcrypto_bruteforce.exe²¢ÆÚ´ýʵÏÖ¡£ÈôÊÇÕÒµ½ÃÜÔ¿ £¬ÔòÆäÎļþÃû½«ÏÔʾÔÚ´°¿ÚÖС£»ñµÃÃÜÔ¿Îļþ²¢³ÖÐøÖ´ÐеÚ4¶Î¡£

4. ÔÚÍÆËã»úÉÏ´´½¨Ò»¸öÎļþ¼Ð £¬¸ÃÎļþ¼ÐµÄõè¾¶½öÔ̺¬Ó¢ÎÄ×Öĸ»òÊý×Ö¡£ÏÂÔØ/bin/decrypt.exeÎļþ²¢½«Æä±£Áôµ½´ËÎļþ¼Ð¡£ÄúÒ²Äܹ»¸ÄÓÃ/bin/decrypt_nolog.exe·¨Ê½¡£¶øºóʹÓÃÉÏÒ»²½ÖлñµÃµÄÃÜÔ¿»ñÈ¡Îļþ £¬²¢½«Æä¸éÖÃÔÚ¸ÃĿ¼ÖÐ £¬²¢´øÓÓ×°key.txt¡±Ãû³Æ£¨»òÕß £¬ÈôÊÇϵͳ²»ÏÔʾÎļþÀ©´óÃû £¬ÔòÖ»ÊÇ¡°key¡±£©¡£ÈôÊǼÓÃÜÎļþλÓÚÄúµÄÍÆËã»úÉÏ £¬ÔòÖ»ÐèÔËÐÐcrypto.exe¡£ÈôÊǼÓÃÜÎļþλÓÚ±í²¿Çý¶¯Æ÷ÉÏ £¬¶øºó½«ÆäÏÎ½Ó £¬Çë°´Start->Execute->cmd.exe £¬¶øºó°´Enter¡£ÔÚ´ò¿ªµÄ´°¿ÚÖмüÈëÒÔϺÅÁî £¬¶øºó°´Enter£ºcd c:\decrypt\&&crypto.exeÆäÖÐ £¬ÊÇÄúÏνӵÄÉ豸µÄ¸ùĿ¼£¨ÀýÈçS:£©¡£±È¼°½âÃܹý³ÌʵÏÖ¡£ÈôÊÇÄúÔÚ´øÓнâÃÜÆ÷µÄÎļþ¼ÐÖÐÕÒµ½Ãû³ÆÎªRENAME.txtµÄÎļþ £¬ÔòÏÂÔØ/bin/rename.exe £¬½«Æä·ÅÈë´ËÎļþ¼ÐÖÐ £¬ÔËÐÐËü²¢ÆÚ´ýʵÏÖ¡£


0x04 ²Î¿¼Á´½Ó


https://github.com/shade-team/keys

https://securityaffairs.co/wordpress/102384/cyber-crime/shade-ransomware-shut-down.html


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾