Shade(Troldesh)ÀÕË÷°ä·¢Í£Ô˲¢·Å³ö75Íò¸ö½âÃÜÃÜÔ¿
°ä²¼¹¦·ò 2020-04-300x00 ÊÂÎñ²¼¾°
ÀÕË÷Èí¼þShade±³ºó×éÖ¯ÓÚÖÜÄ©°ä·¢ÊÕÊÖ£¬²¢ÔÚGitHubÉϰ䲼Á˳¬¹ý75Íò¸ö½âÃÜÃÜÔ¿¡£
¿¨°Í˹»ù³¢ÊÔÊҵݲȫ×êÑÐÈËÔ±ÒѾ֤ʵÏàʼûÜÃÜÔ¿µÄÓÐЧÐÔ£¬²¢ÇÒÔÚÖÂÁ¦ÓÚ´´½¨Ãâ·ÑµÄ½âÃܹ¤¾ß¡£
ÔÚGitHub´æ´¢¿âÖа䲼µÄ¶ÌÐÂÎÅÖУ¨https://github.com/shade-team/keys£©£¬ShadeÍŶÓÚ¹ÊÏç˵¼ÖÂËûÃÇ×ö³ö¾ö¶¨µÄÔÒò¡£
¡°ÎÒÃÇÊÇÒ»¸öÍŶӣ¬¿ª·¢ÁËÒ»¸öľÂí¼ÓÃÜ·¨Ê½£¬Í¨³£±»³ÆÎªShade£¬Troldesh»òEncoder.858¡£ÏÖʵÉÏ£¬ÎÒÃÇÒÑÔÚ2019Äêµ×ÖÕ³¡·Ö·¢¡£´Ë¿Ì£¬ÎÒÃǾö¶¨Îª´ËÊ»ÉϾäºÅ£¬²¢°ä²¼ÎÒÃÇÕ¼ÓеÄËùÓнâÃÜÃÜÔ¿£¨×ܹ²³¬¹ý750,000¸ö£©¡£ÎÒÃÇ»¹½«°ä²¼½âÃÜÈí¼þ¡£ÎÒÃÇ»¹µ«Ô¸£¬ÓÐÁËÃÜÔ¿£¬·À²¡¶¾¹«Ë¾½«ÄÜ¿ª·¢²¢°ä²¼Ô½·¢Óû§¶ØÄÀµÄ½âÃܹ¤¾ß¡£ÓëGA»Æ½ð¼×»î¶¯ÓйصÄËùÓÐÆäËûÊý¾Ý£¨Ô̺¬ÌØÂåÒÁľÂíµÄÔ´´úÂ룩¾ù±»²»³É²Ã³·µØÏú»Ù¡£ÎÒÃÇÏòËùÓÐÌØÂåÒÁľÂíÊܺ¦ÕßÖÂǸ£¬²¢µ«Ô¸ÎÒÃǰ䲼µÄÃÜÔ¿¿ÉÄÜÔ®ÊÖËûÃǸ´ÔÊý¾Ý¡£¡±
¾ÑéÖ¤£¬Õâ´Î°ä²¼µÄ½âÃÜÃÜÔ¿¿ÉÒÔΪËùÓб»ÀÕË÷Èí¼þShade¼ÓÃܵÄÎļþ½âÃÜ¡£
0x01 Shade¼ò½é
Shade×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ÆäʱÔÚ¶íÂÞ˹·¢ÏÖÁË´ó¹æÄ£µÄϰȾ¡£ShadeϰȾÔÚ2018Äê10ÔÂÆÚ¼äÓÐËùÔö³¤£¬Ò»Ïò³ÖÐøµ½2018Äê12ÔÂϰëÔ£¬ÔÚÊ¥µ®½ÚÆÚ¼äÐÝÏ¢£¬¶øºóÔÚ2019Äê1ÔÂÖÐÑ®¸´ÔÔö³¤Ò»±¶¡£2019Äê5ÔÂ×êÑÐÈËÔ±ÓÖ·¢ÏÖÁËÐÂÒ»²¨ShadeÀÕË÷Èí¼þ¹¥»÷£¬Ô̺¬ÃÀ¹úºÍÈÕ±¾¡£ÊÜShadeÀÕË÷Èí¼þÓ°ÏìµÄǰÎå¸ö¹ú¶ÈÊÇÃÀ¹ú£¬ÈÕ±¾£¬Ó¡¶È£¬Ì©¹úºÍ¼ÓÄôó£¬ÖØÒªÕë¶Ô¸ß¿Æ¼¼¡¢Åú·¢ºÍ½ÌÓýÐÐÒµ¡£
ShadeϰȾָ±êÊÇÔËÐÐ Microsoft Windows µÄÖ÷»ú¡£Í¨³£Í¨¹ýÀ¬»øÓʼþ£¨³ö¸ñÊǶñÒâµç×ÓÓʼþ¸½¼þ£©´«²¼¡£¸½¼þͨ³£ÊÇzipÎļþ£¬ÊÕ¼þÈ˽âѹËõ¸½¼þ²¢Ë«»÷¸ÃÎļþ£¬ÀÕË÷Èí¼þÆðÍ·ÔËÐС£ÆäÖÐÌáÈ¡µÄzipÄÚÈÝÊÇÒ»¸öJavascript¾ç±¾£¬ÓÃÀ´ÏÂÔØ¶ñÒâpayload£¨ÀÕË÷Èí¼þ£©£¬¸Ãpayloadͨ³£ÍйÜÔÚCMSÕ¾µãÉÏ¡£
Ò»µ©ÏµÍ³Êܵ½Ï°È¾£¬¶ñÒâ´úÂë¾Í»áÉèÖÃ×ÀÃæ²¼¾°À´°ä·¢Ï°È¾£¬²¢ÇÒ½«ÃûΪREADME1.txtµ½README10.txtµÄDesktop 10¸öÎı¾Îļþ·ÅÔÚ×ÀÃæÉÏ£¬ÔÚREADME.txtÎļþÖоÍÔ̺¬ÓйØÍ¨¹ýµç×ÓÓʼþµØÖ·ÓëºÚ¿ÍÁªÏµµÄÅúʾ£¬ÒԱ㹵ͨÊê½ðÊÂÒË¡£
Shade¼ÓÃÜ·½Ê½Êǽ«ÎļþÔÚCBCģʽÏÂʹÓÃAES 256¼ÓÃÜ¡£¶ÔÓÚÿ¸ö¼ÓÃÜÎļþ£¬½«ÌìÉúÁ½¸öËæ»úµÄ256λAESÃÜÔ¿£ºÒ»¸öÓÃÓÚ¼ÓÃÜÎļþµÄÄÚÈÝ£¬ÁíÒ»¸öÓÃÓÚ¼ÓÃÜÎļþÃû¡£
0x02 ½âÃÜÃØÔ¿
½âÃÜÃØÔ¿ÏÂÔØ£ºhttps://github.com/shade-team/keys
ÏÂÔØ¾µÏñ£º
? https://yadi.sk/d/36uVFJ6bUBrdpQ £¨ËùÓÐÃÜÔ¿·Ö¸ô£»zipÖеÄËùÓÐÃÜÔ¿£»Èí¼þ£©
? https://cloud.mail.ru/public/5gy6/4UMfYqAp4 £¨ËùÓÐÃÜÔ¿·Ö¸ô£»zipÖеÄËùÓÐÃÜÔ¿£»Èí¼þ£©
? https://drive.google.com/open?id=1iA2KquslytIE83mwzlXPcL3u8Z0yoqat£¨zipÖÐµÄ ËùÓÐÃÜÔ¿£»Èí¼þ£©
? https://github.com/shade-team/keys £¨ËùÓÐÃÜÔ¿·Ö¸ô£©
? https://github.com/shade-binary/bin £¨Èí¼þ£©
0x03 ½âÃÜ×¢Ã÷
°ÑÎÈ£ºÄ³Ð©·À²¡¶¾Èí¼þ»á¼ì²âµ½Ä³Ð©ÒѰ䲼µÄÈí¼þ£¬ÓÉÓÚËüÓë¼ÓÃÜÆ÷һ·ʹÓÃÁ˳£¼ûµÄ´úÂë¿é¡£ÎªÔ¤·Àɾ³ýËüÃÇ£¬ËùÓÐexeÎļþ¾ùʹÓÃÒ»ÑùµÄÃÜÂëѹËõ£º123454321
ÈôÊÇÄúµÄ¼ÓÃÜÎļþÓµÓÐÒÔÏÂÀ©´óÃûÖ®Ò»£¬ÔòÔÚºóÐø²½ÖèÖУ¬Äú½«±ØÒª¡°keys¡±Îļþ¼ÐÖеġ°main¡±×ÓÎļþ¼Ð£º
? xtbl
? ytbl
? breaking_bad
? Heisenberg
? better_call_saul
? los_pollos
? da_vinci_code
? magic_software_syndicate
? windows10
? windows8
? no_more_ransom
? Tyson
? crypted000007
? crypted000078
? rsa3072
? decrypt_it
ÈôÊÇÄúµÄ¼ÓÃÜÎļþÓµÓÐÒÔÏÂÀ©´óÃûÖ®Ò»£¬ÔòÔÚºóÐø²½ÖèÖУ¬Äú½«±ØÒª¡°keys¡±Îļþ¼ÐÖеġ°alt¡±×ÓÎļþ¼Ð£º
? dexter
? miami_california
ËùÐèµÄ×ÓÎļþ¼Ð±ÉÈËÃæ°µÊ¾Îª¡£¡°master¡±×ÓÎļþ¼ÐºÏÓÃÓÚijЩ·À²¡¶¾¹«Ë¾£¬ËûÃÇÒѾ±»·î¸æÒªÊ¹ÓøÃÎļþ¼Ð¡£
1. Ç¿ÁÒ½¨Ò鹨¹ØÍÆËã»úÉϵÄËùÓз¨Ê½£¨Ô̺¬É±¶¾Èí¼þ£©£¬²¢Ô¤·ÀÔÚ½âÃܹý³ÌÖÐÖ´ÐÐÈÎºÎÆäËû²Ù×÷¡£ÈôÊÇÄúÕ¼ÓÐÍÆËã»úµÄID£¬Çëתµ½µÚ2¶Î¡£²»È»£¬Çëתµ½µÚ3¶Î¡£´ËIDÊÇÒ»¸ö20¸ö·ûºÅµÄ×Ö·û´®£¬Ô̺¬´óд×ÖĸºÍÊý×Ö£¨ÀýÈçAABBCCDDEEFF00112233£©£¬²¢±£ÁôÔŲ́ʽ»úºÍREADME.txtÎļþÖС£ËùÓдÅÅ̵ĸùÎļþ¼Ð¡£ÔÚ¸ü¸ß°æ±¾µÄ¼ÓÃÜÈí¼þÖУ¬ÎļþÃûÖ®ºóÒ²Ôö³¤ÁËID¡£
2. ÈôÊÇREADME.txtÎļþÖеĴúÂëÔÚÊúÏߺóÔ̺¬Á㣨ÀýÈçAABBCCDDEEFF00112233|0£©£¬Çë³ÖÐøÖ´ÐеÚ2.1¶Î¡£ÈôÊÇREADME.txtÎļþÖеĴúÂëÔ̺¬Èý¸öÊúÏߣ¨ÀýÈçAABBCCDDEEFF00112233|765|8|1£©£¬Çë³ÖÐøÖ´ÐеÚ2.2¶Î¡£
2.1 ½øÈë/keys//dynamic/
2.2 ½øÈë/keys//static/Îļþ¼Ð£¬¶øºóÕÒµ½Ãû³ÆÎª´úÂëµÚÒ»¸öÊúÏߺóµÄÊý×ÖµÄÎļþ£¨ÔÚGA»Æ½ð¼×ʾÀýÖÐΪ765£©¡£ÏÂÔØËü²¢³ÖÐøÖ´ÐеÚ4¶Î¡£
3. ÏÂÔØ²¢Ö´ÐÐ/bin/getid.exe·¨Ê½¡£Ëü»áÏÔʾÄúµÄID£¬¶øºóÄúÓ¦¸Ãתµ½ËüµÄµÚ2¶Î¡£ÈôÊÇÕâÑù×öûÓÐÔ®ÊÖ£¬Çë³¢ÊÔÖ´ÐÐ3.1¶ÎÂäÖеÄ×¢Ã÷¡£
3.1 ÔÚÍÆËã»úÉÏ´´½¨Ò»¸öÎļþ¼Ð£¬Æäõè¾¶½öÔ̺¬Ó¢ÎÄ×Öĸ»òÊý×Ö¡£ÏÂÔØÎļþ/bin/decrypt_bruteforce.exe£¬½«Æä±£Áôµ½´ËÎļþ¼Ð²¢ÔÚÆäÖд´½¨Îļþ¼Ó×°keys¡±¡£¶øºó´Ó/keys//static/Îļþ¼ÐÏÂÔØËùÓÐÎļþ£¬²¢½«ËüÃÇ·ÅÔÚ¡°keys¡±Îļþ¼ÐÖС£È¡³öÈκμÓÃÜÎļþ£¬²¢½«Æä·ÅÈëc:\1\Îļþ¼Ð¡£ÔËÐÐcrypto_bruteforce.exe²¢ÆÚ´ýʵÏÖ¡£ÈôÊÇÕÒµ½ÃÜÔ¿£¬ÔòÆäÎļþÃû½«ÏÔʾÔÚ´°¿ÚÖС£»ñµÃÃÜÔ¿Îļþ²¢³ÖÐøÖ´ÐеÚ4¶Î¡£
4. ÔÚÍÆËã»úÉÏ´´½¨Ò»¸öÎļþ¼Ð£¬¸ÃÎļþ¼ÐµÄõè¾¶½öÔ̺¬Ó¢ÎÄ×Öĸ»òÊý×Ö¡£ÏÂÔØ/bin/decrypt.exeÎļþ²¢½«Æä±£Áôµ½´ËÎļþ¼Ð¡£ÄúÒ²Äܹ»¸ÄÓÃ/bin/decrypt_nolog.exe·¨Ê½¡£¶øºóʹÓÃÉÏÒ»²½ÖлñµÃµÄÃÜÔ¿»ñÈ¡Îļþ£¬²¢½«Æä¸éÖÃÔÚ¸ÃĿ¼ÖУ¬²¢´øÓÓ×°key.txt¡±Ãû³Æ£¨»òÕߣ¬ÈôÊÇϵͳ²»ÏÔʾÎļþÀ©´óÃû£¬ÔòÖ»ÊÇ¡°key¡±£©¡£ÈôÊǼÓÃÜÎļþλÓÚÄúµÄÍÆËã»úÉÏ£¬ÔòÖ»ÐèÔËÐÐcrypto.exe¡£ÈôÊǼÓÃÜÎļþλÓÚ±í²¿Çý¶¯Æ÷ÉÏ£¬¶øºó½«ÆäÏνӣ¬Çë°´Start->Execute->cmd.exe£¬¶øºó°´Enter¡£ÔÚ´ò¿ªµÄ´°¿ÚÖмüÈëÒÔϺÅÁ¶øºó°´Enter£ºcd c:\decrypt\&&crypto.exe
0x04 ²Î¿¼Á´½Ó
https://github.com/shade-team/keys
https://securityaffairs.co/wordpress/102384/cyber-crime/shade-ransomware-shut-down.html


¾©¹«Íø°²±¸11010802024551ºÅ