查看: 1025|回复: 3
收起左侧

[病毒样本] 新型勒索病毒Phobos勒索信源码

[复制链接]
python无名氏
发表于 2022-12-19 14:01:04 | 显示全部楼层 |阅读模式
经过分析,发现ID似乎是固定的某个值...
里面还含有很多js脚本,麻烦各位大佬分析分析这份“勒索信”有没有害处
  1. <!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01//EN' 'http://www.w3.org/TR/html4/strict.dtd'>
  2. <html>
  3.   <head>
  4.     <meta charset='windows-1251'>
  5.     <title>encrypted</title>

  6.     <HTA:APPLICATION
  7.       ICON='msiexec.exe'
  8.       SINGLEINSTANCE='yes'
  9.       SysMenu="no">

  10.     <script language='JScript'>
  11.       window.moveTo(50, 50);
  12.       window.resizeTo(screen.width - 100, screen.height - 100);
  13.     </script>

  14.     <style type='text/css'>

  15.       body {
  16.         font: 15px Tahoma, sans-serif;
  17.         margin: 10px;
  18.         line-height: 25px;
  19.         background: #EDEDED;
  20.       }
  21.           img {
  22.                 display:inline-block;
  23.           }
  24.       .bold {
  25.         font-weight: bold;
  26.       }
  27.       .mark {
  28.         background: #D0D0E8;
  29.         padding: 2px 5px;
  30.       }
  31.       .header {
  32.                 text-align: center;
  33.         font-size: 30px;
  34.         line-height: 50px;
  35.         font-weight: bold;
  36.                 margin-bottom:20px;
  37.       }
  38.           
  39.       .info {
  40.         background: #D0D0E8;
  41.         border-left: 10px solid #00008B;
  42.       }
  43.       .alert {
  44.         background: #FFE4E4;
  45.         border-left: 10px solid #FF0000;
  46.       }
  47.       .private {
  48.         border: 1px dashed #000;
  49.         background: #FFFFEF;
  50.       }

  51.       .note {
  52.         height: auto;
  53.         padding-bottom: 1px;
  54.         margin: 15px 0;
  55.       }
  56.       .note .title {
  57.         font-weight: bold;
  58.         text-indent: 10px;
  59.         height: 30px;
  60.         line-height: 30px;
  61.         padding-top: 10px;
  62.       }
  63.       .note .mark {
  64.         background: #A2A2B5;
  65.       }
  66.       .note ul {
  67.         margin-top: 0;
  68.       }
  69.       .note pre {
  70.         margin-left: 15px;
  71.         line-height: 13px;
  72.         font-size: 13px;
  73.       }
  74.           .footer {
  75.                 position:fixed;
  76.                 bottom:0;
  77.                 right:0;
  78.             text-align: right;
  79.           }
  80.     </style>
  81.   </head>

  82.   <body>
  83.     <div class='header'>
  84.                 <img src='data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAQAAAAAYLlVAAAABGdBTUEAALGPC/xhBQAAACBjSFJNAAB6JQAAgIMAAPn/AACA6QAAdTAAAOpgAAA6mAAAF2+SX8VGAAAAAmJLR0QA/4ePzL8AAAAJcEhZcwAACxMAAAsTAQCanBgAAAAHdElNRQfjAwwMJwSFwIn8AAADNklEQVRo3u2ZTUhUURTHfzozmprmZ1pYEmkfJNEmiwwkSEyFECIQpEUboYhqFYHQXlcti9rUKldWBEUiuQpbtDDNzD5G8qM0HRXLRtO5LdJx3puPd++8+xyIztm88zgf/3veufeee18SdimDI1RxnL0U4gbAzxhDdPGCfpZs+49JWTTyFB8iAq8wTju1pDgXvopOliIGX+d57rHPieBuLvLNIvgaD1KvP/x1FiTDCwQTNOkFcJVfCuEFgq+c0he+minF8AJBH2WRnCUph8/nIZVhb2d5w1smEbjYSTn7SQ/TucsFlnWkPxBW6Xc4RkbIoHKooSNshsxRbT98Eb0mtyM04oqgmR6hUNvtrwrnWDa4nOVMVF0XLfw2aPuosBfezQPTmNpiVtFmnpj0W+wBKMFrcPeJ3RYWNfwwWHSSZgdAHX6Du5uWFpl0myqm1KiQrASgnNQQaZFOS4t5nhvkAnbZAbDHIE0wIGHzmsUQKdXkQwlACtsN8ijfJay8zBjkovgBbCLPlAG/hNUcswa5IH4Ayasdzxr5pBbWRRYMstGHYg04QAkH4FbQFSwTCKbdI7mzWVipbMceKtiCCFqO0OeY1caRbAaKOcgOCpQ+WWTyM8EwvfjkTfJoYZDFONqwaPyTHs7LbktlPNMYep2XuE22dfhsHjkS/i+3Wn/SK2EdoE72UeuyGH8rxbbLLjqlkRlb4TAzDo5fIJiOvRTnR+ju9VJuwveC/wASDsD+2h5KUyyQTVZiALzjFt3MsY16mtmqx2mt9BbUw4EQuzpGpVcCLQB8nDBZXmJFDoCeInzFS9ObxwzLmeoBMGA4/QBM4t1IAOHXDi7Zqwg9ACrCWotS8xnQWQCHOGsafzOFOhzLT8NxmoI3RZncULjG1ARA8DHYupxUucbUtxd4ghnw4JI30wdARHneMABx0j8FYD3xCkdefQByKFl9KsOjy6nKNBR0cZRCTjOk1JhrBCCY5r3pZtSS9bZkueSqmljVgPoPDa0Algk4HD8QG8AXph0G8Dk2AC89DgPosFKodvR83G/dtiRzTevtUChP0SCTpBQuM+bI6Bvk51gl96X/FFvzCh9oW0v+H2zO2tYtz/EgAAAAJXRFWHRkYXRlOmNyZWF0ZQAyMDE5LTAzLTEyVDEyOjM5OjA0KzAwOjAwG6lIYwAAACV0RVh0ZGF0ZTptb2RpZnkAMjAxOS0wMy0xMlQxMjozOTowNCswMDowMGr08N8AAAAASUVORK5CYII='>
  85.                 <div>All your files have been encrypted!</div>
  86.         </div>
  87.     <div class='bold'>All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail <span class='mark'>2300957600@qq.com</span></div>         <div class='bold'>Write this ID in the title of your message <span class='mark'>CC5D85EE-3435</span></div>
  88.         <div class='bold'>In case of no answer in 24 hours write us to this e-mail:<span class='mark'>pythonhavenoname@163.com</span></div>

  89.     <div>
  90.                 You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.
  91.         </div>
  92.        
  93.         <div class='note info'>
  94.       <div class='title'>Free decryption as guarantee</div>
  95.                 <ul>Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)            </ul>
  96.     </div>

  97.     <div class='note info'>
  98.       <div class='title'>How to obtain Bitcoins</div>
  99.       <ul>
  100.         The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
  101.           <br><a href='https://localbitcoins.com/buy_bitcoins'>https://localbitcoins.com/buy_bitcoins</a>
  102.                   <br> Also you can find other places to buy Bitcoins and beginners guide here:
  103.           <br><a href='http://www.coindesk.com/information/how-can-i-buy-bitcoins/'>http://www.coindesk.com/information/how-can-i-buy-bitcoins/</a>
  104.       </ul>
  105.     </div>

  106.     <div class='note alert'>
  107.       <div class='title'>Attention!</div>
  108.       <ul>
  109.         <li>Do not rename encrypted files.</li>
  110.         <li>Do not try to decrypt your data using third party software, it may cause permanent data loss.</li>
  111.         <li>Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.</li>
  112.       </ul>
  113.         </div>
  114.   </body>
  115. </html>
复制代码
这里把邮箱换成了我的
以下是勒索信效果:
All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail 2300957600@qq.com
Write this ID in the title of your message CC5D85EE-3435
In case of no answer in 24 hours write us to this e-mail:pythonhavenoname@163.com
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.
Free decryption as guarantee

    Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins

    The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
    [url=]https://localbitcoins.com/buy_bitcoins[/url]
    Also you can find other places to buy Bitcoins and beginners guide here:
    [url=]http://www.coindesk.com/information/how-can-i-buy-bitcoins/[/url]

Attention!
  • Do not rename encrypted files.
  • Do not try to decrypt your data using third party software, it may cause permanent data loss.
  • Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.


勒索信翻译版:

您的所有文件都已加密!

由于您的 PC 存在安全问题,您的所有文件都已加密。如果您想恢复它们,请写信给我们的电子邮件2300957600@qq.com
将此 ID 写在您的消息标题中CC5D85EE-3435
如果 24 小时内无人接听,请写信给我们:pythonhavenoname@163.com
您必须用比特币支付解密费用。价格取决于您给我们写信的速度。付款后,我们将向您发送解密所有文件的工具。
免费解密为保证

    在付款之前,您最多可以向我们发送 5 个文件以供免费解密。文件总大小必须小于 4Mb(非存档),并且文件不应包含有价值的信息。(数据库、备份、大型 Excel 工作表等)

如何获得比特币

    购买比特币最简单的方法是 LocalBitcoins 网站。您必须注册,点击“购买比特币”,然后通过付款方式和价格选择卖家。
    [url=]https://localbitcoins.com/buy_bitcoins[/url]
    您还可以在这里找到其他购买比特币的地方和初学者指南:http:
    [url=]//www.coindesk.com/information/how-can-i-buy-bitcoins/[/url]

注意力!
  • 不要重命名加密文件。
  • 不要尝试使用第三方软件解密您的数据,这可能会导致永久性数据丢失。
  • 在第三方的帮助下解密您的文件可能会导致价格上涨(他们向我们收取费用)或者您可能成为骗局的受害者。


python无名氏
头像被屏蔽
 楼主| 发表于 2022-12-19 14:05:12 | 显示全部楼层
提示: 该帖被管理员或版主屏蔽
Jirehlov1234
发表于 2022-12-19 14:17:42 | 显示全部楼层
勒索信是无害的
anthonyqian
发表于 2022-12-19 14:18:51 | 显示全部楼层
就是html代码,没有什么危害。勒索信可以做为ioc
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-2 18:30 , Processed in 0.123132 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表