Shade(Troldesh)ÀÕË÷Ðû²¼Í£Ô˲¢·Å³ö75Íò¸ö½âÃÜÃÜÔ¿
Ðû²¼Ê±¼ä 2020-04-300x00 ÊÂÎñÅä¾°
ÀÕË÷Èí¼þShade±³ºó×éÖ¯ÓÚÖÜÄ©Ðû²¼ÊÕÊÖ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚGitHubÉÏÐû²¼ÁËÁè¼Ý75Íò¸ö½âÃÜÃÜÔ¿¡£¡£¡£
¿¨°Í˹»ùʵÑéÊÒµÄÇå¾²Ñо¿Ö°Ô±ÒѾ֤ʵÏàʶÃÜÃÜÔ¿µÄÓÐÓÃÐÔ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÕýÔÚÖÂÁ¦ÓÚ½¨ÉèÃâ·ÑµÄ½âÃܹ¤¾ß¡£¡£¡£
ÔÚGitHub´æ´¢¿âÖÐÐû²¼µÄ¶ÌÐÂÎÅÖУ¨https://github.com/shade-team/keys£©£¬£¬£¬£¬£¬£¬£¬ShadeÍŶÓÚ¹ÊÍÁ˵¼ÖÂËûÃÇ×ö³ö¾öÒéµÄÔµ¹ÊÔÓÉ¡£¡£¡£
¡°ÎÒÃÇÊÇÒ»¸öÍŶӣ¬£¬£¬£¬£¬£¬£¬¿ª·¢ÁËÒ»¸öľÂí¼ÓÃܳÌÐò£¬£¬£¬£¬£¬£¬£¬Í¨³£±»³ÆÎªShade£¬£¬£¬£¬£¬£¬£¬Troldesh»òEncoder.858¡£¡£¡£ÏÖʵÉÏ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÒÑÔÚ2019Äêµ××èÖ¹·Ö·¢¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ÎÒÃǾöÒéΪ´ËÊ»ÉϾäºÅ£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÎÒÃÇÓµÓеÄËùÓнâÃÜÃÜÔ¿£¨×ܹ²Áè¼Ý750,000¸ö£©¡£¡£¡£ÎÒÃÇ»¹½«Ðû²¼½âÃÜÈí¼þ¡£¡£¡£ÎÒÃÇ»¹Ï£Íû£¬£¬£¬£¬£¬£¬£¬ÓÐÁËÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬·À²¡¶¾¹«Ë¾½«ÄÜ¿ª·¢²¢Ðû²¼Ô½·¢Óû§ÓѺõĽâÃܹ¤¾ß¡£¡£¡£Óë¼øºÚµ£±£Íø»î¶¯ÓйصÄËùÓÐÆäËûÊý¾Ý£¨°üÀ¨ÌØÂåÒÁľÂíµÄÔ´´úÂ룩¾ù±»²»¿ÉµõÏúµØÏú»Ù¡£¡£¡£ÎÒÃÇÏòËùÓÐÌØÂåÒÁľÂíÊܺ¦ÕßÖÂǸ£¬£¬£¬£¬£¬£¬£¬²¢Ï£ÍûÎÒÃÇÐû²¼µÄÃÜÔ¿Äܹ»×ÊÖúËûÃǻָ´Êý¾Ý¡£¡£¡£¡±
ÂÄÀúÖ¤£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÐû²¼µÄ½âÃÜÃÜÔ¿¿ÉÒÔΪËùÓб»ÀÕË÷Èí¼þShade¼ÓÃܵÄÎļþ½âÃÜ¡£¡£¡£
0x01 Shade¼ò½é
Shade×Ô2014ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÆäʱÔÚ¶íÂÞ˹·¢Ã÷ÁË´ó¹æÄ£µÄѬȾ¡£¡£¡£ShadeѬȾÔÚ2018Äê10ÔÂʱ´úÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬£¬Ò»Ö±Ò»Á¬µ½2018Äê12ÔÂϰëÔ£¬£¬£¬£¬£¬£¬£¬ÔÚÊ¥µ®½Úʱ´úÐÝÏ¢£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚ2019Äê1ÔÂÖÐÑ®»Ö¸´ÔöÌíÒ»±¶¡£¡£¡£2019Äê5ÔÂÑо¿Ö°Ô±ÓÖ·¢Ã÷ÁËÐÂÒ»²¨ShadeÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÃÀ¹úºÍÈÕ±¾¡£¡£¡£ÊÜShadeÀÕË÷Èí¼þÓ°ÏìµÄǰÎå¸ö¹ú¼ÒÊÇÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬ÈÕ±¾£¬£¬£¬£¬£¬£¬£¬Ó¡¶È£¬£¬£¬£¬£¬£¬£¬Ì©¹úºÍ¼ÓÄô󣬣¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¸ß¿Æ¼¼¡¢Åú·¢ºÍ½ÌÓýÐÐÒµ¡£¡£¡£
ShadeѬȾĿµÄÊÇÔËÐÐ Microsoft Windows µÄÖ÷»ú¡£¡£¡£Í¨³£Í¨¹ýÀ¬»øÓʼþ£¨ÌØÊâÊǶñÒâµç×ÓÓʼþ¸½¼þ£©Èö²¥¡£¡£¡£¸½¼þͨ³£ÊÇzipÎļþ£¬£¬£¬£¬£¬£¬£¬ÊÕ¼þÈ˽âѹËõ¸½¼þ²¢Ë«»÷¸ÃÎļþ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ×îÏÈÔËÐС£¡£¡£ÆäÖÐÌáÈ¡µÄzipÄÚÈÝÊÇÒ»¸öJavascript¾ç±¾£¬£¬£¬£¬£¬£¬£¬ÓÃÀ´ÏÂÔØ¶ñÒâpayload£¨ÀÕË÷Èí¼þ£©£¬£¬£¬£¬£¬£¬£¬¸Ãpayloadͨ³£ÍйÜÔÚCMSÕ¾µãÉÏ¡£¡£¡£
Ò»µ©ÏµÍ³Êܵ½Ñ¬È¾£¬£¬£¬£¬£¬£¬£¬¶ñÒâ´úÂë¾Í»áÉèÖÃ×ÀÃæÅä¾°À´Ðû²¼Ñ¬È¾£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½«ÃûΪREADME1.txtµ½README10.txtµÄDesktop 10¸öÎı¾Îļþ·ÅÔÚ×ÀÃæÉÏ£¬£¬£¬£¬£¬£¬£¬ÔÚREADME.txtÎļþÖоͰüÀ¨ÓйØÍ¨¹ýµç×ÓÓʼþµØµãÓëºÚ¿ÍÁªÏµµÄָʾ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÏàͬÊê½ðÊÂÒË¡£¡£¡£
Shade¼ÓÃÜ·½·¨Êǽ«ÎļþÔÚCBCģʽÏÂʹÓÃAES 256¼ÓÃÜ¡£¡£¡£¹ØÓÚÿ¸ö¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬½«ÌìÉúÁ½¸öËæ»úµÄ256λAESÃÜÔ¿£ºÒ»¸öÓÃÓÚ¼ÓÃÜÎļþµÄÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÓÃÓÚ¼ÓÃÜÎļþÃû¡£¡£¡£
0x02 ½âÃÜÃØÔ¿
½âÃÜÃØÔ¿ÏÂÔØ£ºhttps://github.com/shade-team/keys
ÏÂÔØ¾µÏñ£º
? https://yadi.sk/d/36uVFJ6bUBrdpQ £¨ËùÓÐÃÜÔ¿ÍÑÀ룻£»£»£»£»zipÖеÄËùÓÐÃÜÔ¿£»£»£»£»£»Èí¼þ£©
? https://cloud.mail.ru/public/5gy6/4UMfYqAp4 £¨ËùÓÐÃÜÔ¿ÍÑÀ룻£»£»£»£»zipÖеÄËùÓÐÃÜÔ¿£»£»£»£»£»Èí¼þ£©
? https://drive.google.com/open?id=1iA2KquslytIE83mwzlXPcL3u8Z0yoqat£¨zipÖÐµÄ ËùÓÐÃÜÔ¿£»£»£»£»£»Èí¼þ£©
? https://github.com/shade-team/keys £¨ËùÓÐÃÜÔ¿ÍÑÀ룩
? https://github.com/shade-binary/bin £¨Èí¼þ£©
0x03 ½âÃÜ˵Ã÷
×¢ÖØ£ºÄ³Ð©·À²¡¶¾Èí¼þ»á¼ì²âµ½Ä³Ð©ÒÑÐû²¼µÄÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÓë¼ÓÃÜÆ÷Ò»ÆðʹÓÃÁ˳£¼ûµÄ´úÂë¿é¡£¡£¡£Îª×èֹɾ³ýËüÃÇ£¬£¬£¬£¬£¬£¬£¬ËùÓÐexeÎļþ¾ùʹÓÃÏàͬµÄÃÜÂëѹËõ£º123454321
ÈôÊÇÄúµÄ¼ÓÃÜÎļþ¾ßÓÐÒÔÏÂÀ©Õ¹ÃûÖ®Ò»£¬£¬£¬£¬£¬£¬£¬ÔòÔÚºóÐø°ì·¨ÖУ¬£¬£¬£¬£¬£¬£¬Äú½«ÐèÒª¡°keys¡±Îļþ¼ÐÖеġ°main¡±×ÓÎļþ¼Ð£º
? xtbl
? ytbl
? breaking_bad
? Heisenberg
? better_call_saul
? los_pollos
? da_vinci_code
? magic_software_syndicate
? windows10
? windows8
? no_more_ransom
? Tyson
? crypted000007
? crypted000078
? rsa3072
? decrypt_it
ÈôÊÇÄúµÄ¼ÓÃÜÎļþ¾ßÓÐÒÔÏÂÀ©Õ¹ÃûÖ®Ò»£¬£¬£¬£¬£¬£¬£¬ÔòÔÚºóÐø°ì·¨ÖУ¬£¬£¬£¬£¬£¬£¬Äú½«ÐèÒª¡°keys¡±Îļþ¼ÐÖеġ°alt¡±×ÓÎļþ¼Ð£º
? dexter
? miami_california
ËùÐèµÄ×ÓÎļþ¼ÐÔÚÏÂÃæÌåÏÖΪ¡£¡£¡£¡°master¡±×ÓÎļþ¼ÐÊÊÓÃÓÚijЩ·À²¡¶¾¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒѾ±»¼û¸æÒªÊ¹ÓøÃÎļþ¼Ð¡£¡£¡£
1. Ç¿ÁÒ½¨Ò鹨±ÕÅÌËã»úÉϵÄËùÓгÌÐò£¨°üÀ¨É±¶¾Èí¼þ£©£¬£¬£¬£¬£¬£¬£¬²¢×èÖ¹ÔÚ½âÃÜÀú³ÌÖÐÖ´ÐÐÈÎºÎÆäËû²Ù×÷¡£¡£¡£ÈôÊÇÄúÓµÓÐÅÌËã»úµÄID£¬£¬£¬£¬£¬£¬£¬Çëתµ½µÚ2¶Î¡£¡£¡£²»È»£¬£¬£¬£¬£¬£¬£¬Çëתµ½µÚ3¶Î¡£¡£¡£´ËIDÊÇÒ»¸ö20¸ö·ûºÅµÄ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬°üÀ¨´óд×ÖĸºÍÊý×Ö£¨ÀýÈçAABBCCDDEEFF00112233£©£¬£¬£¬£¬£¬£¬£¬²¢ÉúÑÄÔŲ́ʽ»úºÍREADME.txtÎļþÖС£¡£¡£ËùÓдÅÅ̵ĸùÎļþ¼Ð¡£¡£¡£ÔÚ¸ü¸ß°æ±¾µÄ¼ÓÃÜÈí¼þÖУ¬£¬£¬£¬£¬£¬£¬ÎļþÃûÖ®ºóÒ²Ìí¼ÓÁËID¡£¡£¡£
2. ÈôÊÇREADME.txtÎļþÖеĴúÂëÔÚÊúÏߺó°üÀ¨Á㣨ÀýÈçAABBCCDDEEFF00112233|0£©£¬£¬£¬£¬£¬£¬£¬Çë¼ÌÐøÖ´ÐеÚ2.1¶Î¡£¡£¡£ÈôÊÇREADME.txtÎļþÖеĴúÂë°üÀ¨Èý¸öÊúÏߣ¨ÀýÈçAABBCCDDEEFF00112233|765|8|1£©£¬£¬£¬£¬£¬£¬£¬Çë¼ÌÐøÖ´ÐеÚ2.2¶Î¡£¡£¡£
2.1 ½øÈë/keys//dynamic/
2.2 ½øÈë/keys//static/Îļþ¼Ð£¬£¬£¬£¬£¬£¬£¬È»ºóÕÒµ½Ãû³ÆÎª´úÂëµÚÒ»¸öÊúÏߺóµÄÊý×ÖµÄÎļþ£¨ÔÚ¼øºÚµ£±£ÍøÊ¾ÀýÖÐΪ765£©¡£¡£¡£ÏÂÔØËü²¢¼ÌÐøÖ´ÐеÚ4¶Î¡£¡£¡£
3. ÏÂÔØ²¢Ö´ÐÐ/bin/getid.exe³ÌÐò¡£¡£¡£Ëü»áÏÔʾÄúµÄID£¬£¬£¬£¬£¬£¬£¬È»ºóÄúÓ¦¸Ãתµ½ËüµÄµÚ2¶Î¡£¡£¡£ÈôÊÇÕâÑù×öûÓÐ×ÊÖú£¬£¬£¬£¬£¬£¬£¬ÇëʵÑéÖ´ÐÐ3.1¶ÎÂäÖеÄ˵Ã÷¡£¡£¡£
3.1 ÔÚÅÌËã»úÉϽ¨ÉèÒ»¸öÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬Æä·¾¶½ö°üÀ¨Ó¢ÎÄ×Öĸ»òÊý×Ö¡£¡£¡£ÏÂÔØÎļþ/bin/decrypt_bruteforce.exe£¬£¬£¬£¬£¬£¬£¬½«ÆäÉúÑĵ½´ËÎļþ¼Ð²¢ÔÚÆäÖн¨ÉèÎļþ¼Ð¡°keys¡±¡£¡£¡£È»ºó´Ó/keys//static/Îļþ¼ÐÏÂÔØËùÓÐÎļþ£¬£¬£¬£¬£¬£¬£¬²¢½«ËüÃÇ·ÅÔÚ¡°keys¡±Îļþ¼ÐÖС£¡£¡£È¡³öÈκμÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬²¢½«Æä·ÅÈëc:\1\Îļþ¼Ð¡£¡£¡£ÔËÐÐcrypto_bruteforce.exe²¢ÆÚ´ý¿¢Ê¡£¡£¡£ÈôÊÇÕÒµ½ÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬ÔòÆäÎļþÃû½«ÏÔʾÔÚ´°¿ÚÖС£¡£¡£È¡µÃÃÜÔ¿Îļþ²¢¼ÌÐøÖ´ÐеÚ4¶Î¡£¡£¡£
4. ÔÚÅÌËã»úÉϽ¨ÉèÒ»¸öÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ¼ÐµÄ·¾¶½ö°üÀ¨Ó¢ÎÄ×Öĸ»òÊý×Ö¡£¡£¡£ÏÂÔØ/bin/decrypt.exeÎļþ²¢½«ÆäÉúÑĵ½´ËÎļþ¼Ð¡£¡£¡£ÄúÒ²¿ÉÒÔ¸ÄÓÃ/bin/decrypt_nolog.exe³ÌÐò¡£¡£¡£È»ºóʹÓÃÉÏÒ»²½ÖлñµÃµÄÃÜÔ¿»ñÈ¡Îļþ£¬£¬£¬£¬£¬£¬£¬²¢½«Æä°²ÅÅÔÚ¸ÃĿ¼ÖУ¬£¬£¬£¬£¬£¬£¬²¢´øÓС°key.txt¡±Ãû³Æ£¨»òÕߣ¬£¬£¬£¬£¬£¬£¬ÈôÊÇϵͳ²»ÏÔʾÎļþÀ©Õ¹Ãû£¬£¬£¬£¬£¬£¬£¬ÔòÖ»ÊÇ¡°key¡±£©¡£¡£¡£ÈôÊǼÓÃÜÎļþλÓÚÄúµÄÅÌËã»úÉÏ£¬£¬£¬£¬£¬£¬£¬ÔòÖ»ÐèÔËÐÐcrypto.exe¡£¡£¡£ÈôÊǼÓÃÜÎļþλÓÚÍⲿÇý¶¯Æ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬È»ºó½«ÆäÅþÁ¬£¬£¬£¬£¬£¬£¬£¬Çë°´Start->Execute->cmd.exe£¬£¬£¬£¬£¬£¬£¬È»ºó°´Enter¡£¡£¡£ÔÚ·¿ªµÄ´°¿ÚÖмüÈëÒÔÏÂÏÂÁ£¬£¬£¬£¬£¬£¬È»ºó°´Enter£ºcd c:\decrypt\&&crypto.exe
0x04 ²Î¿¼Á´½Ó
https://github.com/shade-team/keys
https://securityaffairs.co/wordpress/102384/cyber-crime/shade-ransomware-shut-down.html


¾©¹«Íø°²±¸11010802024551ºÅ