¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«Ãæ·Ö½â
°ä²¼¹¦·ò 2019-04-251¡¢¸Å Êö
½üÈÕ£¬GA»Æ½ð¼×ADLab²¶»ñµ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬±àÒ빦·òΪ4ÔÂ14ÈÕ£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁŰ½ö½öÒ»¸ö¶àÔ¡£¡°ÏÀµÁ¡±V5.2ÆðÍ·ËÁŰÖйúµÄ¹¦·òΪ3ÔÂ11ÈÕ£¬²¢ÒÑϰȾÁËÎÒ¹úÉÏǧ̨µ±¾Ö¡¢ÆóÒµºÍÓйؿÆÑлú¹¹µÄÍÆËã»ú¡£ºþ±±Ê¡Ò˲ýÊÐÒÄÁêÇøµ±¾Ö¡¢Öйú¿ÆÑ§Ôº½ðÊô×êÑÐËù¡¢ÔÆÄÏʦ·¶´óѧÒÔ¼°´óÁ¬Êй«°²¾ÖµÈ»ú¹¹¾ùÔÚÆä¹ÙÍø°ä²¼ÁË·À±¸²¡¶¾¹¥»÷µÄ²¼¸æ¡£
¡°ÏÀµÁ¡±²¡¶¾µÄµÚÒ»¸ö°æ±¾µ®ÉúÓÚ2018Äê1Ô£¬Ä¿Ç°ÎªÖ¹£¬ÒѾ¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öÓ×°æ±¾¡£ÆäÖØÒªÖ÷ÕÅÊÇͨ¹ý¼ÓÃÜÊܺ¦Óû§µÄÍÆËã»úÎļþÀ´¶ÔÊܺ¦Óû§½øÐÐÀÕË÷¡£¡°GandCrab¡±ÀÕË÷²¡¶¾Ö®ËùÒÔ±»È˳ÆÎª¡°ÏÀµÁ¡±£¬ÊÇÓÉÓÚÆäÒѾ¡°ÈË·µØ¡±ÎªÎÞÁ¦Ö§¸¶¡°Êê½ð¡±µÄÐðÀûÑǸ¸Ç×½âÃÜÁËÆäÔÚÕ½ÕùÖÐÉ¥ÉúµÄ¶ù×ÓµÄÕÕÆ¬£¬²¢·Å³öÁ˲¿ÃÅÐðÀûÑǵØÓò֮ǰ°æ±¾µÄ½âÃÜÃÜÔ¿£¬»¹½«ÐðÀûÑÇÒÔ¼°ÆäËûÕ½ÂÒµØÓò¼Ó½øÏ°È¾ÇøÓò¡°°×Ãûµ¥¡±¡£
¡°ÏÀµÁ¡±»á½«Óû§Îļþ¼ÓÃܺóÔö³¤ÉÏÀÕË÷ºó׺Ãû£¬¶øºóÔÙ¸ü»»Ï°È¾ÏµÍ³µÄ×ÀÃæÎªÀÕË÷ͼƬ£¬ÀÕË÷ͼƬÉϵÄÎÄ×ÖÌáÐÑÊܺ¦Óû§ÔĶÁÆäÀÕË÷ÊÖ²áÎı¾Îļþ,ÔÚÀÕË÷ÊÖ²áÎı¾ÎļþÖнøÒ»²½Êèµ¼Êܺ¦Óû§Êê»ØÓû§Îļþ¡£ÔÚ5.2֮ǰµÄ°æ±¾ÖУ¬ÀÕË÷ÊÖ²áÎļþÊèµ¼Êܺ¦Óû§Í¨¹ýTorÍøÂçÊê»ØÎļþ£¬Êê½ðÖ§³Ö´ïÊÀ±ÒºÍ±ÈÌØ±ÒÖ§¸¶£»¶øÔÚ×îеÄ5.3°æ±¾ÖУ¬ÀÕË÷ÊÖ²áÖÐÖ»¸ø³öÁ˺ڿ͵ÄÓÊÏ䣬ҪÇóÊܺ¦ÕßÓʼþÁªÏµËûÃÇ£¬³ýÁËÕâÒ»µã±ä¶¯£¬¡°ÏÀµÁ¡±5.3»¹¸üÐÂÁ˺ڿ͹«Ô¿¡£Ä¿Ç°Éв»Ã÷ÏÔGandcrab5.3ÀÕË÷²¡¶¾¿ÉÄÜ»áÒªÇó½âÃÜÕßÖ§¸¶¼¸¶àÇ®£¬µ«Ö®Ç°µÄ°æ±¾ÒªÇóÔÚ±ÈÌØ±Ò»ò´ïÊÀ±ÒÉÏÖ§¸¶500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£
2¡¢²¡¶¾´«²¼
¡°ÏÀµÁ¡±²¡¶¾´«²¼õè¾¶ÖØÒªÓÐRDP¡¢VNCõè¾¶½øÐб©Á¦ÆÆ½âºÍÈëÇÖ¡¢¶¨ÏòÓã²æ´¹µöÓʼþͶ·Å¡¢°ó¸¿¶ñÒâÈí¼þºÍÍøÒ³¹ÒÂí¹¥»÷¡¢½©Ê¬ÍøÂçÒÔ¼°·ì϶ÀûÓô«²¼µÈ¡£
ĿǰÔÚ°µÍøÖУ¬¡°ÏÀµÁ¡±Ä»ºóÍŶÓѡȡ¡°ÀÕË÷¼´·þÎñ¡±£¨¡°ransomware as-a-service¡± £©µÄ·½Ê½£¬ÏòºÚ¿Í´ó¾ÙÊÛÂôV5.3°æ±¾²¡¶¾£¬¼´ÓÉ¡°ÏÀµÁ¡±ÍŶÓÌṩ²¡¶¾£¬ºÚ¿ÍÔÚÈ«ÇòÑ¡ÔñÖ¸±ê½øÐй¥»÷ÀÕË÷£¬¹¥»÷³É¹¦ºó ¡°ÏÀµÁ¡±ÍŶÓÔÙ´ÓÖгéÈ¡30%-40%µÄÀûÈ󡣡°À¬»øÓʼþÔì×÷ÕßÃÇ£¬ÄãÃÇ´Ë¿ÌÄܹ»ÓëÍøÂçר¼Ò½øÐкÏ×÷£¬²»Òª´íʧ»ñÈ¡ÃÀºÃÉúÑĵÄÃÅÆ±£¬ÎÒÃÇÔÚµÈÄã¡£¡±ÊÇ¡°ÏÀµÁ¡±ÍŶÓÔÚ°µÍøÖдò³öµÄ¡°ÕÐÉ̸æ°×¡±¡£
¡°ÏÀµÁ¡±ÊÇĿǰµÚÒ»¸öÀÕË÷´ïÊÀ±ÒµÄÀÕË÷²¡¶¾£¬ºóÀ´²Å¼ÓÁ˱ÈÌØ±Ò£¬Òª¼Û500ÃÀÔªÖÁ4000ÃÀÔª²»µÈ¡£¾Ý¡°ÏÀµÁ¡±ÍŶÓ2018Äê12Ô°䲼µÄÊý¾Ý£¬Æä×ܼÆÊÕÈë±ÈÌØ±ÒÒÔ¼°´ïÊÀ±Ò¼ÆËãÒѸߴï285ÍòÃÀÔª¡£
3¡¢ÆÆ½âº¹Çà
Ïñ´ó²¿ÃÅÀÕË÷ÎļþÒ»Ñù£¬¡°ÏÀµÁ¡±Ê¹ÓÃÁËRSA¼ÓÃÜËã·¨£¬³ý·ÇÄõ½ºÚ¿Í³ÖÓеÄRSA-2048˽Կ£¬²Å¿ÉÄܶÔϰȾÎļþ½øÐнâÃÜ£¬²»È»ÎÞ·¨½âÃÜ¡£
ÓÉÓÚ¡°ÏÀµÁ¡±ÊÂÎñ£¬¹¥»÷Õ߷ųöÁËÀÕË÷²¡¶¾²¿ÃÅÔçÆÚ°æ±¾µÄ½âÃÜÃÜÔ¿£¬¶à¸ö°²È«³§ÉÌËæ±í̬¼Ì°ä²¼Ïàʼûܹ¤¾ß¡£´Ó18Äê10Ôµ½½ñÄê2Ô£¬BitdefenderÏȺó°ä²¼ÁË¡°ÏÀµÁ¡±¶à¸ö°æ±¾µÄ½âÃܹ¤¾ß£¬×îеĽâÃܹ¤¾ßÏÂÔØµØÖ·Îª£ºhttps://labs.bitdefender.com/wp-content/uploads/downloads/gandcrab-removal-tool-v1-v4-v5/£¬¸Ã¹¤¾ßÄܹ»½âÃܵİ汾Èç±í1Ëùʾ¡£Æä½âÃܵÀÀíÊÇͨ¹ýÔÚÏßÏòBitdefender·þÎñÆ÷Ìá½»¼ÓÃÜID£¬À´»ñÈ¡¿ÉÓõĽâÃÜ˽Կ£¨ RSA-2048£©À´½øÐнâÃÜ¡£Óû§Äܹ»Æ¾¾Ý±íÖеļÓÃÜÎļþºó׺»òÀÕË÷×¢Ã÷Îı¾ÎļþµÄÆðÍ·À´²é¶Ô²¡¶¾°æ±¾¡£
ÇøÓò±êÖ¾·û | ˵»°£¨¹ú¶È£© |
0x419 | ¶íÓ¶íÂÞ˹£© |
0x422 | ÎÚ¿ËÀ¼ÓÎÚ¿ËÀ¼£© |
0x423 | °×¶íÂÞ˹Ó°×¶íÂÞ˹£© |
0x428 | Ëþ¼ª¿Ë |
0x42B | ÑÇÃÀÄáÑÇÓÑÇÃÀÄáÑÇ£© |
0x42C | °¢ÔóÀïÓ°¢Èû°Ý½®£¬À¶¡Ó |
0x437 | ¸ñ³¼ªÑÇÓ¸ñ³¼ªÑÇ£© |
0x43F | ¹þÈø¿ËÓ¹þÈø¿Ë˹̹£© |
0x440 | ¼ª¶û¼ªË¹Ó¼ª¶û¼ªË¹Ì¹£© |
0x442 | ÍÁ¿âÂü |
0x443 | ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹£¬À¶¡Ó |
0x444 | ÷²÷°Ó¶íÂÞ˹£© |
0x818 | ÂÞÂíÄáÑÇÓĦ¶û¶àÍßµØÓò£© |
0x819 | ¶íÓĦ¶û¶àÍßµØÓò£© |
0x82C | °¢ÔóÀïÓ°¢Èû°Ý½®£¬Î÷Àï¶ûÓ |
0x843 | ÎÚ×ȱð¿ËÓÎÚ×ȱð¿Ë˹̹£¬Î÷Àï¶ûÓ |
0x45A | ÐðÀûÑÇÓÐðÀûÑÇ£© |
0x2801 | °¢À²®ÓÐðÀûÑÇ£© |
±í2 ÅųýµÄ˵»°£¨¹ú¶È£©
5.2 ÖÕÖ¹°²È«Èí¼þ
¡°ÏÀµÁ¡±±éÀúϰȾÉ豸ϵͳ¹ý³Ì£¬ÈôÊÇ·¢ÏÖϰȾÉ豸ÓÐÔËÐп¨°Í˹»ù¡¢Åµ¶ÙµÈ°²È«Èí¼þ£¬¾ÍÇ¿ÔìʵÏÖµôÖ¸±ê¹ý³Ì£¬Ô¤·À×Ô¼º±»É±¶¾Èí¼þ²éɱ¡£ÓйصݲȫÈí¼þÈçÏÂͼ4Ëùʾ¡£

ͼ4 Óйذ²È«Èí¼þ¹ý³Ì
5.3 ÖÕÖ¹ÌØ¶¨·¨Ê½
¡°ÏÀµÁ¡±»á±éÀúϰȾÉ豸ϵͳµ±Ç°¹ý³ÌÁÐ±í£¬ÈôÊÇÆ¥Åäµ½Ö¸¶¨µÄ¹ý³ÌÔòʵÏָùý³Ì£¬ÒÔÔ¤·ÀÒÅ©µôÒòÓû§Îļþ±»Õ¼Óöø²»Äܱ»¼ÓÃܵÄÓû§Îļþ¡£ÈçWord¡¢Excel¡¢PowerPoint¡¢Onenote¡¢Visio¡¢Oracle¡¢SQLserver¡¢MySQLµÈ³£¼ûÀûÓùý³Ì£¬¾ßÌåÖ¸±ê¹ý³ÌÈçͼ5Ëùʾ£º

ͼ5 ÖÕÖ¹µÄÖ¸±ê¹ý³Ì
5.4 È·¶¨¼ÓÃÜÎļþÀàÐÍ
5.4.1 Îļþºó׺°×Ãûµ¥
ΪÁËÅųýµôûÓмÛÖµµÄÀÕË÷Êý¾ÝÎļþ£¬¡°ÏÀµÁ¡±ÄÚÖÃÁËÒ»·ÝÎļþºó׺°×Ãûµ¥£¬Èçͼ6Ëùʾ¡£ÎÒÃǽ«ÆäÁе½±í3ÖУ¬ÆäÖÐÔ̺¬µÄÎļþÓпÉÖ´ÐÐÎļþ¡¢ÏµÍ³¶¯Ì¬Å²ÓÿâÎļþ¡¢ÏµÍ³Çý¶¯ÎļþºÍ¡°ÏÀµÁ¡±ÓйصÄÎļþµÈ¡£

ͼ6 ²»¼ÓÃܵÄÎļþÀàÐÍ
°×Ãûµ¥õè¾¶ |
"\\ProgramData\\" |
"\\IETldCache\\" |
"\\Boot\\" |
"\\Program Files\\" |
"\\Tor Browser\\" |
"\\All Users\\" |
"\\Local Settings\\" |
"\\Windows\\" |
±í4 ϵͳĿ¼°×Ãûµ¥
±í5ÖеÄϵͳÎļþÒ²²»ÔÚ¼ÓÃÜÖ¸±êÖ®ÁУº
¼ÓÃܵÄÎļþºó׺ |
.1st .602 .docb .xlm .xlsx .xlsm .xltx .xltm .xlsb .xla .xlam .xll .xlw .ppt .pot .pps .pptx .pptm .potx .potm .ppam .ppsx .ppsm .sldx .sldm .xps .xls .xlt ._doc .dotm ._docx .abw .act .adoc .aim .ans .apkg .apt .asc .asc .ascii .ase .aty .awp .awt .aww .bad .bbs .bdp .bdr .bean .bib .bib .bibtex .bml .bna .boc .brx .btd .bzabw .calca .charset .chart .chord .cnm .cod .crwl .cws .cyi .dca .dfti .dgs .diz .dne .dot .doc .docm .dotx .docx .docxml .docz .dox .dropbox .dsc .dvi .dwd .dx .dxb .dxp .eio .eit .emf .eml .emlx .emulecollection .epp .err .err .etf .etx .euc .fadein.template .faq .fbl .fcf .fdf .fdr .fds .fdt .fdx .fdxt .fft .fgs .flr .fodt .fountain .fpt .frt .fwd .fwdn .gmd .gpd .gpn .gsd .gthr .gv .hbk .hht .hs .hwp .hwp .hz .idx .iil .ipf .ipspot .jarvis .jis .jnp .joe .jp1 .jrtf .jtd .kes .klg .klg .knt .kon .kwd .latex .lbt .lis .lnt .log .lp2 .lst .lst .ltr .ltx .lue .luf .lwp .lxfml .lyt .lyx .man .mbox .mcw .md5 .me .mell .mellel .min .mnt .msg .mw .mwd .mwp .nb .ndoc .nfo .ngloss .njx .note .notes .now .nwctxt .nwm .nwp .ocr .odif .odm .odo .odt .ofl .opeico .openbsd .ort .ott .p7s .pages .pages-tef .pdpcmd .pfx .pjt .plain .plantuml .pmo .prt .prt .psw .pu .pvj .pvm .pwd .pwdp .pwdpl .pwi .pwr .qdl .qpf .rad .readme .rft .ris .rpt .rst .rtd .rtf .rtfd .rtx .run .rvf .rzk .rzn .saf .safetext .sam .sam .save .scc .scm .scriv .scrivx .sct .scw .sdm .sdoc .sdw .se .session .sgm .sig .skcard .sla .sla.gz .smf .sms .ssa .story .strings .stw .sty .sublime-project .sublime-workspace .sxg .sxw .tab .tab .tdf .tdf .template .tex .text .textclipping .thp .tlb .tm .tmd .tmdx .tmv .tmvx .tpc .trelby .tvj .txt .u3i .unauth .unx .uof .uot .upd .utf8 .utxt .vct .vnt .vw .wbk .webdoc .wn .wp .wp4 .wp5 .wp6 .wp7 .wpa .wpd .wpd .wpd .wpl .wps .wps .wpt .wpt .wpw .wri .wsd .wtt .wtx .xbdoc .xbplate .xdl .xdl .xwp .xwp .xwp .xy .xy3 .xyp .xyw .zabw .zrtf .zw.rar .zip .cab .arj .lzh .tar .7z .gzip .iso .z .7-zip .lzma .vmx .vmdk .vmem .vdi .vbo |
5.5 ¼ÓÃÜÓû§Îļþ
¡°ÏÀµÁ¡±»á±éÀúϰȾÉ豸¹²ÏíĿ¼ºÍ±¾µØ´ÅÅÌ¡£Ñ¡È¡RSA-2048+Salsa20Ëã·¨¼ÓÃÜϰȾÉ豸Îļþ¡£
¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþÈçͼ8Ëùʾ£º

ͼ8 ¼ÓÃܹ²ÏíĿ¼ÏµÄÎļþ
¼ÓÃܱ¾µØ´ÅÅÌĿ¼ÏÂÎļþÈçͼ9Ëùʾ£º

ͼ9 ¼ÓÃܱ¾µØ´ÅÅÌĿ¼ÏÂÎļþ
5.6 ÌìÉúMANUALÎļþ
¡°ÏÀµÁ¡±ÏȽ«ÀÕË÷ÐÅÏ¢½âÃܵ½ÄÚ´æÖУ¬ÔÚ½øÐа汾ºÍºó׺ÐÅϢƴ½Óºó£¬½«Õû¸öÀÕË÷ÐÅϢдÈëMANUALÎļþÖУ¬Èçͼ10ºÍͼ11Ëùʾ£º


ͼ11 ½âÃܵ½ÄÚ´æÖеÄÀÕË÷ÐÅÏ¢
×îÖÕµÄMANUALÎļþÓÉÀÕË÷ÐÅÏ¢¡¢¼ÓÃܺóµÄ˽ԿÐÅÏ¢ºÍ¼ÓÃܺóµÄϰȾÉ豸ÐÅÏ¢×é³É¡£ÆäÖкڿÍרÃÅÇ¿µ÷Êܺ¦Óû§²»ÒªÅú¸Ä˽ԿÐÅÏ¢ÄÚÈÝ£¬ÓÉÓÚÒ»µ©Ë½Ô¿ÐÅÏ¢Ò»µ©±»Å¤×ª£¬¾ÍÎÞ·¨¶ÔÎļþ½øÐнâÃÜ¡£
5.7 ´úÌæÏ°È¾É豸×ÀÃæ
´´½¨ÀÕË÷×ÀÃæ±ÚÖ½µ½¡°C:\Documents and Settings\[username]\LocalSettings\Temp\bxmeoengtf.bmp¡±,Èçͼ12Ëùʾ£º

ͼ12 ´´½¨ÀÕË÷ͼƬ£¬ÉèÖÃÀÕË÷×ÀÃæ
ͼ13ÖУ¬ÀÕË÷ͼƬÉÏдÓÓ×°YOURFILES ARE UNDER STRONG PROTECTION BY OUR SOFTWARE. IN ORDER TO RESTORE IT YOUMUST BUY DECRYPTOR£¬For further stepsread %s-DECRYPT.%s that is located in every encrypted folder¡±£¬ÌáÐÑϰȾÓû§ÔĶÁManualÎļþÖ§¸¶Êê½ð¡£

ͼ13 ÀÕË÷±ÚÖ½
5.8 ɾ³ý¾íÓ°¿½±´
¡°ÏÀµÁ¡±»áɾ³ýÏ°È¾ÍÆËã»ú¾íÓ°¸±±¾£¬ÕâÊÇÀÕË÷²¡¶¾µÄͨÀý²Ù×÷£¬ÕâÑù×öµÄÖ÷ÕÅÊÇÔ¤·ÀÊܺ¦Óû§Í¨¹ýWindows Recovery¶ÔÎļþ½øÐи´Ô£¬Èçͼ14¡£

ͼ14 ɾ³ý¾íÓ°¸±±¾
Èçͼ15£¬¡°ÏÀµÁ¡±Å²Óá°shell32.ShellExecuteW¡±Ö´ÐкÅÁî¡°/c vssadmin delete shadows /all /quiet¡±

ͼ15 Ö´ÐÐɾ³ýºÅÁî
5.9 ÏνÓC&C
¡°ÏÀµÁ¡±»á½Ó¼ûÖ¸¶¨ÓòÃûµÄ80ºÍ443¶Ë¿Ú£¬¡°ÏÀµÁ¡±ÔÚÏνӺڿͽÚÔìµÄÔ¶³Ì·þÎñÆ÷£¨Èçhttp://www.kakaocorp.link£©³É¹¦ºó£¬ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍϰȾÉ豸ÐÅÏ¢£¬Èçͼ16¡£

ͼ16 ÏòÔ¶³Ì·þÎñÆ÷·¢ËÍϰȾÉ豸ÐÅÏ¢
ÆäÖУ¬rc4keyΪ".oj=294~!z3)9n-1,8^)o((q22)lb$"
strPCdata±£ÁôÔÚ¡±*-MANUAL.txt¡±ÎļþÖУ¨*°µÊ¾´óдµÄ¼ÓÃÜÎļþºó׺Ãû£©£¬¼ûͼ18£º

ͼ18 Base64´æ´¢µÄPCÓйØÃÜÎÄÐÅÏ¢
ÓÉÓÚC&CʧЧ£¬ËùÓÐÎÒÃÇûÓÐ×¥µ½·¢ËÍ·¢ËÍstrPCdataµÄÊý¾Ý°ü¡£
6.2 ½âÃÜpubkey
¡°ÏÀµÁ¡±ÏÈÌìÉú64×Ö½ÚÁ÷input3£¨ÓÉSalsakey3£¨¹Ì¶¨×Ö½Ú£©ºÍIV3£¨¹Ì¶¨×Ö½Ú£©ºÍ³£Á¿×é³É£©£¬Èçͼ19:

ͼ19 ÌìÉúµÄinput3
¡°ÏÀµÁ¡±ÔÚʹÓÃSalsa20Ëã·¨½âÃܺڿ͵ÄRSA2048¹«Ô¿£¬ÎÒÃǽ«¹«Ô¿ÃÜÎļÇΪpubkeyEncrypted£¬½«½âÃܺóµÄ¹«Ô¿¼ÇΪhackerPubkey£¬Ëã·¨ÈçÏ£º
hackerPubkey= Salse20(input3, pubkeyEncrypted)
hackerPubkeyEncrypted¼ûͼ20£º

ͼ20 ½âÃÜǰµÄhackerPubkey
½âÃܵõ½hackerPubkey¼ûͼ21£¬¶Ô±È¡°ÏÀµÁ¡±5.2µÄºÚ¿Í¹«Ô¿£¨Í¼22£©£¬ÎÒÃÇ·¢´Ë¿Ì5.3°æ±¾Öкڿ͸üÐÂÁËÆä³ÖÓеĹ«Ô¿¡£


ͼ22 GandCrab5.2 ºÚ¿Í¹«Ô¿
6.3 ±¾µØÌìÉúRSA¹«Ë½«h¶Ô
ºÚ¿ÍÀûÓÃ΢Èí¡°advapi32¡±¿âº¯Êý±¾µØÌìÉúRSA-2048¹«Ë½«h¶Ô£¬ÎÒÃDZðÀë¼ÇΪlocPubkeyºÍlocPrikey£¬Õë¶Ôÿ¸öϰȾÕß±¾µØ¹«Ë½«h¶ÔÖ»ÌìÉúÒ»´Î¡£ÆäÖУ¬locPubkeyÓÃÓÚ¼ÓÃÜSalsaFileKeyºÍIV2£¬¶ølocPrikeyʹÓÃSalsa20Ëã·¨¼ÓÃܺó×îÖÕ±£Áôµ½±¾µØ¡£
locPubkey£¨0x114×Ö½Ú£©¼ûͼ23:

ͼ23 ÄÚ´æÖеÄlocPubkey
locPrikey£¨0x494×Ö½Ú£©¼ûÏÂͼ24£º

ͼ24 ÄÚ´æÖеÄlocPrikey
6.4 ¼ÓÃܱ¾µØË½Ô¿
¡°ÏÀµÁ¡±Ê×ÏÈÌìÉúSalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©£¬Ôٺͳ£Á¿Ò»Â·ÌìÉú64×Ö½ÚÊäÈëÁ÷£¬ÎÒÃǼÇΪinput1£¬¶øºó£¬¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜlocPrikey£¬Ëã·¨ÈçÏ£º
data3 = Salsa20(input1,locPrikey)
SalsaKey(32×Ö½ÚËæ»úÊý)ºÍIV1£¨8×Ö½ÚËæ»úÊý£©±ðÀë±»ºÚ¿ÍµÄ¹«Ô¿¼ÓÃÜ£¬ÈçÏÂ:
data2 = RSA2048(hackerPubkey, IV1)
×îºó£¬¡°ÏÀµÁ¡±½«¡°data1¡±¡¢¡°data2¡±¡¢¡°data3¡±base64¼ÓÃܺó±£ÁôÔÚ±¾µØ£¬ÈçÏÂ(ÆäÖÐ0x00000494ΪlocPrikey³¤¶È)£º
gandcrabKey=base64encode(0x00000494+ data1+ data2+ data3)
±£ÁôÔÚ¡°****-MANUAL.txt¡±ÎļþÖУ¬Èçͼ25£º

ͼ25 Base64´æ´¢µÄ±¾µØRSA-2048˽ԿÃÜÎÄÐÅÏ¢
6.5 ¼ÓÃÜϰȾÕßÎļþ
¡°ÏÀµÁ¡±µÚÒ»²½ÌìÉúSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©¡¢IV2£¨8×Ö½ÚËæ»úÊý£©ÒÔ¼°³£Á¿ÌìÉúµÄ64×Ö½ÚÊäÈëÁ÷£¬ÎÒÃǼÇΪinput2£¬input2Õë¶Ôÿһ¸öÓû§Îļþ¶¼¶À±ÏÌìÉú£¬¶øºó¡°ÏÀµÁ¡±Ê¹ÓÃSalsa20Ëã·¨¼ÓÃÜÓû§Îļþ£¬Ëã·¨ÈçÏ£º
data4 = Salsa20(input2,userFile)
µÚ¶þ²½Óñ¾µØ¹«Ô¿locPubkey¼ÓÃÜSalsaFileKey£¨32×Ö½ÚËæ»úÊý£©ºÍIV2£¨8×Ö½ÚËæ»úÊý£©£¬Ëã·¨ÈçÏ£º
data6 = RSA2048(locPubkey, IV2)
×îºó£¬¡°ÏÀµÁ¡±½«¡°data4¡±¡¢¡°data5¡±¡¢¡°data6¡±ºÍ¹Ì¶¨µÄ×Ö½ÚÆ´½Ó³É¼ÓÃÜÎļþ£¬ÈçÏÂ(ÆäÖÐlenUserFileΪÓû§ÔʼÎļþ´óÓ×)£º
finalFile=data4 +data5+data6+lenUserFile+¹Ì¶¨×Ö½Ú
¼ÓÃܺóµÄÎļþ½á¹¹Èçͼ26£º

7.×ܽáÓ뽨Òé
ÓÉÓÚ´ó²¿ÃÅÀÕË÷²¡¶¾¼ÓÃܺóµÄÎļþ¶¼ÎÞ·¨½âÃÜ£¬ËùÒÔÓ¦¶ÔÀÕË÷²¡¶¾ÒÔÔ¤·ÀºÍ±¸·ÝΪÖ÷¡£½¨ÒéÓû§×öºÃÈÕ³£µÄ·À±¸´ëÊ©£º
- ʵʱ¸üвÙ×÷ϵͳ£¬ÊµÊ±¸øÍÆËã»ú´ò²¹¶¡¡£
- ¶Ô³ÁÒªµÄÊý¾ÝÎļþÒª½øÐÐÒìµØ±¸·Ý¡£
- ¾¡Á¿¹Ø¹Ø²»ÓÃÒªµÄÎļþ¹²Ïí£¬»ò°Ñ¹²Ïí´ÅÅÌÉèÖÃΪֻ¶ÁÊôÐÔ£¬²»ÔÊÐí¾ÖÓòÍøÓû§¸ÄдÎļþ¡£
- ¾¡Á¿¹Ø¹Ø²»ÓÃÒªµÄ·þÎñºÍ¶Ë¿Ú¡£È磺135£¬139£¬445¶Ë¿Ú£¬¶ÔÓÚÔ¶³Ì×ÀÃæ·þÎñ£¨3389£©£¬VNC·þÎñ±ØÒª½øÐа×Ãûµ¥ÉèÖ㬽öÔÊÐí°×Ãûµ¥ÄÚµÄIPµÇ½¡£
- ѡȡ²»ÉÙÓÚ10λµÄ¸ßÇ¿¶ÈÃÜÂ룬²¢¶¨ÆÚ¸ü»»ÃÜÂ룬ͨ¹ýwindows×éÕ½ÊõÅäÖÃÕË»§Ëø¶¨Õ½Êõ£¬¶Ô¶Ì¹¦·òÄÚÂ½ÐøµÇ½ʧ°ÜµÄÕË»§½øÐÐËø¶¨¡£
- ×°Öþ߱¸×Ô±£»¤Ö°ÄܵķÀ²¡¶¾Èí¼þ£¬²¢ÊµÊ±¸üв¡¶¾¿â»òÈí¼þ°æ±¾¡£
- ¼ÓǿԱ¹¤°²È«ÒâʶÅàѵ£¬²»µÈÏдò¿ªÄ°ÉúÓʼþ»òÔËÐÐÆðÔ´²»Ã÷µÄ·¨Ê½£¬¶Â½ØÀÕË÷²¡¶¾µÄÓʼþ´«²¼·½Ê½¡£


¾©¹«Íø°²±¸11010802024551ºÅ