Ransom.Win64.CONTI.AA
Gen:Variant.Lazy.326686 (BITDEFENDER)
Windows

恶意软件类型:
Ransomware
有(yǒu)破坏性?:
没有(yǒu)
加密?:
没有(yǒu)
In the Wild:
是的
概要
它以文(wén)件的形式出现在系统中(zhōng),可(kě)能(néng)是其他(tā)恶意软件投放的,或者是用(yòng)户在访问恶意网站时无意中(zhōng)下载的。
技(jì )术详细信息
???????
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
??
???????:
- %System Root%\CONTI_LOG.txt ? If -log enabled is used
(??: %System Root% ?????,???? C:\??????????????)
???????:
- cmd.exe /c %System%\wbem\WMIC\wbem\WMIC.exe shadowcopy where \"ID=’{Shadowcopy ID}’\"delete ? Deletes shadow copies
(??: %System% ? Windows ? system ???,???? C:\Windows\System (Windows 98 ? ME)?C:\WINNT\System32 (Windows NT ? 2000) ? C:\WINDOWS\system32 (Windows 2000(32-bit)?XP?Server 2003(32-bit)?Vista?7?8?8.1?2008(64-bit),2012(64bit) ? 10(64-bit))?)
?????????,????????????:
- hsfjuukloqu280ajh727190
??????
?????????:
- It encrypts database storage files by looking for the following strings in their file path:
- .4dd
- .4dl
- .abcddb
- .abs
- .abx
- .accdb
- .accdc
- .accde
- .accdr
- .accdt
- .accdw
- .accft
- .adb
- .ade
- .adf
- .adn
- .adp
- .alf
- .arc
- .ask
- .bdf
- .btr
- .cat
- .cdb
- .ckp
- .cma
- .cpd
- .dacpac
- .dad
- .dadiagrams
- .daschema
- .db
- .db2
- .db3
- .dbc
- .dbf
- .dbs
- .db-shm
- .dbt
- .dbv
- .db-wal
- .dbx
- .dcb
- .dct
- .dcx
- .ddl
- .dlis
- .dp1
- .dqy
- .dsk
- .dsn
- .dtsx
- .dxl
- .eco
- .ecx
- .edb
- .epim
- .exb
- .fcd
- .fdb
- .fic
- .fm5
- .fmp
- .fmp12
- .fmpsl
- .fol
- .fp3
- .fp4
- .fp5
- .fp7
- .fpt
- .frm
- .gdb
- .grdb
- .gwi
- .hdb
- .his
- .hjt
- .ib
- .icg
- .icr
- .idb
- .ihx
- .itdb
- .itw
- .jet
- .jtx
- .kdb
- .kdb
- .kexi
- .kexic
- .kexis
- .lgc
- .lut
- .lwx
- .maf
- .maq
- .mar
- .mas
- .mav
- .maw
- .mdb
- .mdf
- .mdn
- .mdt
- .mpd
- .mrg
- .mud
- .mwb
- .myd
- .ndf
- .nnt
- .nrmlib
- .ns2
- .ns3
- .ns4
- .nsf
- .nv
- .nv2
- .nwdb
- .nyf
- .odb
- .oqy
- .ora
- .orx
- .owc
- .p96
- .p97
- .pan
- .pdb
- .pdm
- .pnz
- .qry
- .qvd
- .rbf
- .rctd
- .rod
- .rodx
- .rpd
- .rsd
- .sas7bdat
- .sbf
- .scx
- .sdb
- .sdc
- .sdf
- .sis
- .spg
- .sql
- .sqlite
- .sqlite3
- .sqlitedb
- .te
- .temx
- .tmd
- .tps
- .trc
- .trm
- .udb
- .udl
- .usr
- .v12
- .vis
- .vpd
- .vvv
- .wdb
- .wdmb
- .wrk
- .xdb
- .xld
- .xmlff
- Encrypts network drive
- It encrypts disk image files by looking for the following file extensions in their file path:
- .avdx
- .avhd
- .bin
- .iso
- .nvram
- .pvm
- .qcow2
- .raw
- .subvol
- .vdi
- .vhd
- .vhdx
- .vmcx
- .vmdk
- .vmem
- .vmrs
- .vmsd
- .vmsn
- .vmx
- .vsv
- When encrypting network shares it will check if the IP address starts with the following to ensure that it is encrypting local and non-internet systems:
- 172.
- 192.168.
- 10.
- 169.
解决方案
Step 2
??Windows ME?XP??,????,????????????,??????????
Step 3
注意:在此恶意软件/间谍软件/灰色软件执行期间,并非所有(yǒu)文(wén)件、文(wén)件夹和注册表键值和项都会安(ān)装(zhuāng)到您的计算机上。这可(kě)能(néng)是由于不完整的安(ān)装(zhuāng)或其他(tā)操作(zuò)系统条件所致。如果您没有(yǒu)找到相同的文(wén)件/文(wén)件夹/注册表信息,请继续进行下一步操作(zuò)。
Step 4
????????
- {Encrypted Directory}\readme.txt
- %System Root%\CONTI_LOG.txt
Step 5
?????????????,???????Ransom.Win64.CONTI.AA?? ????????????????????????,????????????????????????????????????????
Step 6
从备份中(zhōng)恢复加密文(wén)件。