LockBit²¡¶¾Ò»Á¬Éý¼¶£¬£¬£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿Ú¶à¿î²úÆ·¾«×¼³ö»÷£¡
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿ÚÚÐÌýʵÑéÊÒ¹Ø×¢µ½LockBitÀÕË÷Èí¼þÍÅ»ïÐû²¼ÁË×îа汾ÀÕË÷Èí¼þLockBit 3.0£¬£¬£¬£¬£¬£¬£¬£¬ÆäÒýÈëÁËZcash¼ÓÃÜÇ®±ÒÖ§¸¶Ñ¡ÏеÄÀÕË÷Õ½ÂÔ¼°Ê׸öÀÕË÷Èí¼þÎó²îÉͽðÍýÏë¡£¡£¡£¡£¡£¡£¡£×Ô2019ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÌṩµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©²Ù×÷Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬¾ÓÉÁ½¸öÔµÄbeta²âÊÔ£¬£¬£¬£¬£¬£¬£¬£¬LockBitˢкóµÄа汾ÒÑÓÃÓÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾Ýй¶Êý¾ÝÕ¾µãµÄͳ¼ÆÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2022ÄêµÚÒ»¼¾¶ÈËùÓÐÓëÀÕË÷Èí¼þÏà¹ØµÄй¶ÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬LockBitÕ¼±È46%¡£¡£¡£¡£¡£¡£¡£½öÔÚ½ñÄê6ÔÂÖУ¬£¬£¬£¬£¬£¬£¬£¬¾ÍÓÐ44ÆðÍøÂç¹¥»÷Óë¸Ã×éÖ¯Óйأ¬£¬£¬£¬£¬£¬£¬£¬LockBitÏÔÈ»ÒѳÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þÍŻ¡£¡£¡£¡£¡£¡£
½üÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷¸ßËÙÔöÌí£¬£¬£¬£¬£¬£¬£¬£¬ÒѳÉÎªÍøÂçÌìϵÄÒ»ÖÖÊ¢Ðв¡£¬£¬£¬£¬£¬£¬£¬£¬³ý½»Êê½ðÍ⣬£¬£¬£¬£¬£¬£¬£¬ÏÕЩÎ޽⡣¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDR¡¢×Ô˳Ӧ·ÀÓùϵͳµÈ²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸ÃÀÕË÷²¡¶¾£¬£¬£¬£¬£¬£¬£¬£¬ÓÐÓñÜÃâÀÕË÷ÊÂÎñ±¬·¢£¬£¬£¬£¬£¬£¬£¬£¬Ç¿»¯ÖÕ¶ËÍøÂçÇå¾²£¬£¬£¬£¬£¬£¬£¬£¬Æð¾¢ÓªÔìÇåÀʵÄÍøÂç¿Õ¼äÇéÐΡ£¡£¡£¡£¡£¡£¡£
ÑùÌìÖ°Îö
LockBit3.0°æ±¾ÀÕË÷Èí¼þµÄÊê½ð¼Í¼²»ÔÙ³ÆÎª¡°Restore-My-Files.txt¡±£¬£¬£¬£¬£¬£¬£¬£¬¶øÊǸÄΪÃüÃûÃûÌÃ[id].README.txt£¬£¬£¬£¬£¬£¬£¬£¬ÈçͼËùʾÒÔÏ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÏîÄ¿ÒÑÖØÃüÃûΪ LockBit Black¡£¡£¡£¡£¡£¡£¡£

LockBit 3.0°æ±¾µÄÔËÐÐÔöÌíÁ˲ÎÊýУÑ飬£¬£¬£¬£¬£¬£¬£¬ÐèÒªÊäÈëÈçÏÂ׼ȷµÄ²ÎÊý²Å»ªÀÖ³ÉÖ´ÐС£¡£¡£¡£¡£¡£¡£

ÔËÐкó»áÁ¬Ã¦½âÃܳöPEÎļþÖи÷Çø¶ÎµÄÕæÊµ´úÂëÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ö®ºóÌø×ªµ½½âÃܺóµÄ´úÂëÖÐÖ´ÐС£¡£¡£¡£¡£¡£¡£

ÔÚ»ñÈ¡µ½ÏµÍ³º¯ÊýµÄµØÖ·ºó£¬£¬£¬£¬£¬£¬£¬£¬ÌìÉú½âÃÜAPIº¯ÊýµÄÖ¸Õë±í£¬£¬£¬£¬£¬£¬£¬£¬Ï൱ÓÚ¸øÏµÍ³APIŲÓüÓÁËÒ»¸ö¼òÆÓµÄÖ´ÐнâÃܿǡ£¡£¡£¡£¡£¡£¡£

Ö®ÒÔÊÇ˵LockBitÓëBlackMatter¼«ÆäÏàËÆ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚÆäÉèÖÃÎļþµÄ½âÃÜÓëBlackMatterÏÕЩÈç³öÒ»ÕÞ£¬£¬£¬£¬£¬£¬£¬£¬Ðí¶àÉèÖÃÊý¾ÝÐèÒªµ¥×Ö½ÚÒì»ò¡¢APLIB½âѹËõ¡¢Base64±àÂëµÈ¶àÖÖ½âÂëºó·½ÄÜ¿´µ½ÔʼÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÏêÇé½âÃÜÒªÁì¼°¾ç±¾¿ÉÒԲο¼https://research.openanalysis.net/lockbit/lockbit3/yara/triage/ransomware/2022/07/07/lockbit3.html¡£¡£¡£¡£¡£¡£¡£

¼ì²éϵͳʹÓõÄÓïÑÔ¡£¡£¡£¡£¡£¡£¡£Ä¿½ñϵͳÖ÷»úÖеÄÓïÑÔÈôÊÇÊôÓÚÏÂÁÐÓïÑÔÀàÐÍÀÕË÷Èí¼þ»áÖ±½ÓÍ˳ö¡£¡£¡£¡£¡£¡£¡£°üÀ¨°¢Èû°Ý½®ÎÄ£¨Î÷Àï¶ûÎÄ¡¢°¢Èû°Ý½®£©¡¢°¢Èû°Ý½®ÎÄ£¨À¶¡ÎÄ¡¢°¢Èû°Ý½®£©¡¢ÑÇÃÀÄáÑÇÎÄ£¨ÑÇÃÀÄáÑÇ£©¡¢°×¶íÂÞ˹ÎÄ£¨°×¶íÂÞ˹£©¡¢¸ñ³¼ªÑÇÎÄ£¨¸ñ³¼ªÑÇ£©¡¢¹þÈø¿ËÎÄ£¨¹þÈø¿Ë˹̹£©¡¢¼ª¶û¼ªË¹ÎÄ£¨¼ª¶û¼ªË¹Ë¹Ì¹£©¡¢¶íÎÄ£¨Ä¦¶û¶àÍߣ©¡¢¶íÎÄ£¨¶íÂÞ˹£©¡¢Ëþ¼ª¿ËÎÄ£¨Î÷Àï¶ûÎÄ¡¢Ëþ¼ª¿Ë˹̹£©¡¢ÍÁ¿âÂüÎÄ£¨ÍÁ¿âÂü˹̹£©¡¢ÎÚ×ȱð¿ËÎÄ£¨Î÷Àï¶ûÎÄ¡¢ÎÚ×ȱð¿Ë˹̹£©¡¢ÎÚ×ȱð¿ËÎÄ£¨À¶¡ÎÄ¡¢ÎÚ×ȱð¿Ë˹̹£©¡¢ÎÚ¿ËÀ¼ÎÄ£¨ÎÚ¿ËÀ¼£©¡£¡£¡£¡£¡£¡£¡£

LockBitµÄËùÓвÎÊý¡¢·þÎñÃû³Æ¡¢Àú³ÌÃû³Æ¡¢ºó׺Ãû³Æ¡¢ÎļþÃû³Æ¶¼Ê¹ÓÃÒ»¸öËã·¨º¯Êý¾ÙÐв»¿ÉÄæ±ä»»ºó¾ÙÐÐУÑ飬£¬£¬£¬£¬£¬£¬£¬ÕâÑùµÄÀûÒæÊÇ×èÖ¹ÔÚÄÚ´æÖÐÖ±½Ó̻¶º¬Óдó×ÚÃô¸ÐµÄ×Ö·û´®ÁÐ±í¡£¡£¡£¡£¡£¡£¡£×Ö·û´®Ð£ÑéµÄËã·¨ÈçÏÂͼËùʾ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃËã·¨¶Ô×Ö·û´®µÄÿһ¸ö×Ö·û¾ÙÐÐRORÑ»·ÓÒÒÆ0xDh´Î£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇ×Ö·ûΪ´óд×Öĸ¼ÓÉÏÔ×Ö·ûHEXÊýÖµÒì»ò0x20h£¬£¬£¬£¬£¬£¬£¬£¬²»È»Ö±½Ó¼ÓÉÏ×Ö·ûµÄHEXÊýÖµ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ»ñµÃµÄ×Ö·û´®ÊÇÒ»¸ö²»¿ÉÄæµÄ32λHEXÊýÖµ¡£¡£¡£¡£¡£¡£¡£Èç¡°txt¡±¶ÔÓ¦HEXÊýÖµ0xEBA01E00h¡£¡£¡£¡£¡£¡£¡£

ÀÕË÷Èí¼þÔËÐÐÖбØÐèʹÓõÄ×Ö·û´®Ôòͨ¹ýÔÚÕ»ÖÐÒì»ò0x4506DFCAhÔÙÈ¡·´ØÊºó½âÃÜ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬×Ö·û´®½âÃܵÄIDApython¾ç±¾¿ÉÒԲο¼Ô´ÏîÄ¿
https://github.com/StupidBird-Code/Malware_Analysize-Tools/blob/main/lockbit3.0_decrypt.py¡£¡£¡£¡£¡£¡£¡£

Ö®ºóÑ»·ÌáȨ£¬£¬£¬£¬£¬£¬£¬£¬»®·Ö»ñÈ¡SeBackupPrivilege¡¢SeManageVolumePrivilege¡¢SeTakeOwnershipPrivilege¡¢SeDebugPrivilegeµÈȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ҪĿµÄÊÇ¿ÉÒÔ¿¢Êµô×ÌÈżÓÃÜÀú³ÌµÄÀú³ÌºÍ·þÎñ²¢¾ß±¸×ã¹»¸ßµÄȨÏÞ¾ÙÐмÓÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£

½¨É軥³âÁ¿
Global\2cae82bd1366f4e0fdc7a9a7c12e2a6b

LockBitÔÚ¼ÓÃÜËùÓÐÎļþǰµÄ×¼±¸ÊÂÇé»ù±¾ÔÚн¨µÄ¶à¸öÏß³ÌÖÐÍê³É¡£¡£¡£¡£¡£¡£¡£ÆäÖеÚÒ»¸öÏß³ÌÆôÓÃWindowsϵͳ×Ô´øµÄTrustedInstaller·þÎñ¡£¡£¡£¡£¡£¡£¡£

²¢Ã¶¾ÙϵͳËùÓзþÎñ״̬£¬£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤·þÎñÃû³Æ×Ö·û´®µÄУÑéËã·¨¿¢ÊµôÌØ¶¨·þÎñÀú³Ì¡£¡£¡£¡£¡£¡£¡£¿¢ÊµķþÎñÀú³Ì°üÀ¨ÒÔÏ·þÎñÃû³Æ£º


µÚ¶þ¸öÏß³ÌŲÓÃCoCreateInstanceµÈϵͳAPIÖ´ÐÐWMIÓï¾äɾ³ý¾íÓ°¸±±¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ҪĿµÄÊDZÜÃâÊý¾Ý±»»Ö¸´¡£¡£¡£¡£¡£¡£¡£

µÚÈý¸öÏß³ÌÔÚ¼ÓÃÜÀú³ÌÖлáö¾ÙϵͳÖÐÔËÐеÄËùÓÐÀú³Ì£¬£¬£¬£¬£¬£¬£¬£¬²¢¿¢ÊÂÒÔÏÂÃû³ÆµÄÀú³Ì£º


µÚËĸöÏß³ÌÖ´ÐÐIOCP¶àÏ̴߳¦Öóͷ£µÄ³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬ºóÐøÓÃÓÚ¼ÓÃܲ¢Ð´ÈëÎļþÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£±ðµÄLockBitÔÚ»ñÈ¡´ÅÅÌÐÅϢʱ£¬£¬£¬£¬£¬£¬£¬£¬½¨ÉèÐÂÏß³ÌŲÓÃGetLogicalDriveStringsWºÍGetDriveTypeWÁ½¸öÒªº¦API£¬£¬£¬£¬£¬£¬£¬£¬´ËÖÖ´úÂëÐÐΪӦ¸ÃÊÇΪÁ˹æ±ÜÇå¾²Èí¼þÔÚ¶¯Ì¬Ö´ÐÐÖеÄAPIÐòÁÐÐÐΪ¼à²â¡£¡£¡£¡£¡£¡£¡£
ÀÕË÷Èí¼þÔÚ¼ÓÃÜÀú³ÌÖлáɨ³ýÒÔϺó׺µÄÎļþ£º


ÔÚ¼ÓÃÜÀú³ÌÖлáɨ³ýÒÔÏÂÃû³ÆµÄÎļþ£º

ɨ³ý°üÀ¨ÒÔÏÂÃû³ÆµÄÎļþ¼Ð·¾¶£º

¼ÓÃÜÀú³ÌÖÐLockBit»áΪÿһ¸öÎļþÌìÉúÐÂµÄÆß¸ö×ÖĸÃû³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ".HLJkNskOq"ΪÀο¿ºó׺£¬£¬£¬£¬£¬£¬£¬£¬Ö®ºóŲÓÃMoveFileExº¯Êý¸Ä±ä±»¼ÓÃÜÎļþµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£

Ö®ºóÔÚ¸ßÓÅÏȼ¶µÄ¶à¸öIOCP´¦Öóͷ£Ïß³ÌÖмÓÃܲ¢Ð´ÈëÎļþÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖ¸ßÐÔÄܵļÓÃÜËÙÂÊ¡£¡£¡£¡£¡£¡£¡£ÀÕË÷ǰºó½ÓÄÉÁËRSAËã·¨ºÍ×Ô½ç˵µÄËã·¨¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÊµÖÊÉÏÎÞ·¨½âÃܱ»¼ÓÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£

±»LockBit 3.0¼ÓÃܺóµÄÎļþͼ±ê»á±»ÐÞ¸ÄΪÐþÉ«µÄ¡°B¡±×ÖÑù¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þ½«Éè¼ÆºÃµÄͼ±êÎļþÊÍ·ÅÔÚC:\ProgramData\HLJkNskOq.ico·¾¶Ï£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ×¢²á±íÖн¨ÉèHKCR\HLJkNskOq\DefaultIcon\(Default)ÏîÄ¿£¬£¬£¬£¬£¬£¬£¬£¬ÉèÖÃ.HLJKNskOqºó׺µÄĬÈÏͼ±ê·¾¶Îª´Ëico¡£¡£¡£¡£¡£¡£¡£

×îÖÕÔÚicoͼ±êÎļþµÄͬĿ¼ÏÂÊÍ·ÅbmpÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÐÞ¸Ä×¢²á±í½«ÆäÉèÖÃΪ×ÀÃæÅä¾°¡£¡£¡£¡£¡£¡£¡£

ÔÚÿ¸öĿ¼ÏÂÊͷŵÄÀÕË÷µÄÌáÐÑÐÅÏ¢ÈçÏ£º

Ñù±¾IOCsÁбí

·À»¤½¨Òé
1¡¢ÊµÊ±ÐÞ¸´ÏµÍ³Îó²î£¬£¬£¬£¬£¬£¬£¬£¬½µµÍ±»LockBitÀÕË÷²¡¶¾Í¨¹ýÎó²îÈëÇÖµÄΣº¦£»£»£»£»£»
2¡¢ÔöÇ¿»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ²»ÐëÒªµÄ¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬½ûÓò»ÐëÒªµÄÅþÁ¬£¬£¬£¬£¬£¬£¬£¬£¬½µµÍ×ʲúΣº¦Ì»Â¶Ã棻£»£»£»£»
3¡¢¸ü¸Äϵͳ¼°Ó¦ÓÃʹÓõÄĬÈÏÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÉèÖøßÇ¿¶ÈÃÜÂëÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬£¬²¢°´ÆÚ¸üÐÂÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬±ÜÃâÈõ¿ÚÁî¹¥»÷£»£»£»£»£»
4¡¢¿É×°ÖÃ3377ÌåÓýÍø¹ÙÍøÈë¿ÚÇå¾²²úÆ·ÔöÇ¿·À»¤£¬£¬£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳ¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÐÓ÷ÀÓù¸ÃÀÕË÷²¡¶¾¡£¡£¡£¡£¡£¡£¡£



²úÆ·ÏÈÈÝ
¡ö3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳ·ÀÓùÉèÖÃ
1¡¢¿ªÆôÀÕË÷²¡¶¾ÓÕ²¶£¬£¬£¬£¬£¬£¬£¬£¬×è¶Ï¼ÓÃÜÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬·À»¤ÀÕË÷²¡¶¾Íþв£»£»£»£»£»
2¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬½µµÍºáÏòѬȾΣº¦£»£»£»£»£»
3¡¢¿ªÆôÎļþʵʱ¼à¿Ø¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾¡£¡£¡£¡£¡£¡£¡£
¡ö3377ÌåÓýÍø¹ÙÍøÈë¿Ú×Ô˳ӦÇå¾²·ÀÓùϵͳ·ÀÓùÉèÖÃ
1¡¢¿ªÆô²¡¶¾ÊµÊ±¼à²â¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸ÃÀÕË÷²¡¶¾£»£»£»£»£»
2¡¢Í¨¹ý΢¸ôÀëÕ½ÂÔÔöÇ¿»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬½µµÍºáÏòѬȾΣº¦£»£»£»£»£»
3¡¢Í¨¹ýΣº¦·¢Ã÷¹¦Ð§É¨ÃèϵͳÊÇ·ñ±£´æÏà¹ØÎó²îºÍÈõ¿ÚÁ£¬£¬£¬£¬£¬£¬£¬½µµÍΣº¦¡¢ïÔÌ×ʲú̻¶£»£»£»£»£»
¡ª¡ª?²úÆ·»ñÈ¡·½·¨?¡ª¡ª
3377ÌåÓýÍø¹ÙÍøÈë¿Ú×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳÆóÒµ°æÊÔÓ㨿Éͨ¹ý3377ÌåÓýÍø¹ÙÍøÈë¿ÚÌìÏ·ÖÖ§»ú¹¹»ñÈ¡£¡£¡£¡£¡£¡£¡£©£º
http://www.topsec.com.cn/contact/
3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳµ¥»ú°æÏÂÔØµØÖ·£º
http://edr.topsec.com.cn
TOPSEC
ÀÕË÷²¡¶¾×÷ÎªÍøÂçÌìÏÂÊ¢Ðв¡£¬£¬£¬£¬£¬£¬£¬£¬½üÄêÀ´Ò»ÔÙ¶ÔÖÖÖÖ×éÖ¯»ú¹¹µÄÓªÒµÇå¾²ÒÔÖÂÉç»áÖÈÐòÔì³ÉÖØ´óÍþв¡£¡£¡£¡£¡£¡£¡£3377ÌåÓýÍø¹ÙÍøÈë¿ÚʼÖÕÉî¸û²úÆ·¡¢ÊÖÒÕÓë·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÍøÂçÇå¾²°ü¹Üϵͳ½¨É裬£¬£¬£¬£¬£¬£¬£¬Ò»Ö±Îª¿Í»§ÌṩÍêÕûµÄ²úÆ··þÎñ»¯ÌåÑ飬£¬£¬£¬£¬£¬£¬£¬ÖúÁ¦¹ú¼ÒÍøÂçÇå¾²¹¤Òµ¿µ½¡Óë¿ÉÒ»Á¬Éú³¤¡£¡£¡£¡£¡£¡£¡£
- Òªº¦´Ê±êÇ©£º
- 3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDR LockBit²¡¶¾ ×Ô˳Ӧ·ÀÓùϵͳ ÖÕ¶ËÍøÂçÇå¾²

¾©¹«Íø°²±¸ 11010802026257ºÅ