{"id":41163,"date":"2020-02-06T10:06:32","date_gmt":"2020-02-06T07:06:32","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/wulfric-ransomware-shifrovalshhik-kotorogo-net"},"modified":"2020-02-06T10:06:32","modified_gmt":"2020-02-06T07:06:32","slug":"wulfric-ransomware-shifrovalshhik-kotorogo-net","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/wulfric-ransomware-shifrovalshhik-kotorogo-net","title":{"rendered":"Wulfric Ransomware \u2013 the encryptor that doesn't exist","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Sometimes you just want to look into the eyes of a virus writer and ask: why and how? We can handle the question of \"how\" ourselves, but it would be fascinating to know what that particular creator of malware was thinking. Especially when we come across such \"gems.\"<\/p>\n<p>The hero of today's article is an interesting specimen of ransomware. It appears to have been conceived as yet another \"extortionist,\" but its technical implementation resembles some kind of cruel joke. We will talk about this implementation today. <\/p>\n<p>Unfortunately, tracking the lifecycle of this encoder is virtually impossible \u2013 there is very little statistics on it, as fortunately, it has not gained widespread distribution. So, we will leave aside its origin, infection methods, and other mentions. We will only share our case of encountering <b>Wulfric Ransomware<\/b> and how we helped the user recover their files. <br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>I. How It All Started<\/h3>\n<p>\nOur antivirus lab often receives inquiries from people who have been affected by ransomware. We provide assistance regardless of the antivirus products they have installed. This time, a person reached out to us whose files were infected by an unknown encoder.<\/p>\n<blockquote><p>Good afternoon! Files were encrypted on a file storage (samba4) with passwordless login. I suspect the infection came from my daughter\u2019s computer (Windows 10 with the built-in Windows Defender protection). The daughter\u2019s computer has not been turned on since then. Files encrypted mainly include .jpg and .cr2 formats. The file extension after encryption is: .aef.<\/p><\/blockquote>\n<p>We received samples of the encrypted files from the user, a ransom note, and a file that is likely the key required by the ransomware author to decrypt the files.<\/p>\n<p>Here are all our clues:<\/p>\n<ul>\n<li>01c.aef (4481K) <\/li>\n<li>hacked.jpg (254K) <\/li>\n<li>hacked.txt (0K) <\/li>\n<li>04c.aef (6540K) <\/li>\n<li>pass.key (0K) <\/li>\n<\/ul>\n<p>\nLet's take a look at the note. How many bitcoins this time? <\/p>\n<p><b>Translation:<\/b><\/p>\n<blockquote><p>Attention, your files are encrypted!<br \/>\nthe password is unique to your PC.<\/p>\n<p>Pay the amount of 0.05 BTC to the bitcoin address: 1ERtRjWAKyG2Edm9nKLLCzd8p1CjjdTiF<br \/>\nAfter payment, send me an email attaching the pass.key file to Wulfric@gmx.com with a payment notification.<\/p>\n<p>Upon confirmation, I will send you the decryptor for your files.<\/p>\n<p>You can pay bitcoins online in various ways:<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/buy.blockexplorer.com\/\">buy.blockexplorer.com<\/a><\/noindex> \u2014 credit card payment<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.buybitcoinworldwide.com\/\">www.buybitcoinworldwide.com<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/localbitcoins.net\">localbitcoins.net<\/a><\/noindex><\/p>\n<p>About bitcoins:<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Bitcoin\">en.wikipedia.org\/wiki\/Bitcoin<\/a><\/noindex><br \/>\nIf you have any questions, feel free to email me at Wulfric@gmx.com<br \/>\nAs a bonus, I will explain how your computer was hacked and how to protect it in the future.<\/p><\/blockquote>\n<p>\nA dramatic wolf, summoned to show the victim the seriousness of the situation. Still, it could have been worse.<\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/83546fd6abaf84c07c4471f75320a99d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 1. -As a bonus, I will tell you how to protect your computer in the future. \u2013Seems legit.<\/b><\/p>\n<h3>II. Let's get to work<\/h3>\n<p>\nFirst, we looked at the structure of the sample sent. Strangely enough, it did not resemble a file affected by ransomware. We opened a hex editor to take a look. The first 4 bytes contain the original file size, the following 60 bytes are filled with zeros. But the most interesting part is at the end:<\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/47e1039822100885ec4c400a6d85f705.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 2. Analyzing the corrupted file. What stands out immediately?<\/b><\/p>\n<p>It turned out to be infuriatingly simple: 0x40 bytes from the header were moved to the end of the file. To recover the data, it is enough to just return them to the beginning. Access to the file has been restored, but the name remains encrypted, which is more complicated. <\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/82e22bd3820247d72be8452620970e5f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 3. The encrypted name in Base64 looks like a random string of characters. <\/b><\/p>\n<p>Let\u2019s try to decode it <b>pass.key<\/b>, sent by the user. In it, we see a 162-byte sequence of characters in ASCII.<\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/cf932ca88de8ebf419f06a70f6dc2cb3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 4. 162 characters left on the victim's PC. <\/b><\/p>\n<p>If you look closely, you can see that the characters repeat with a certain periodicity. This may indicate the use of XOR, where repetitions are characteristic, and the frequency depends on the key length. Splitting the string into 6-character segments and XORing with some variations of XOR sequences did not yield any meaningful results.<\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/378d6be895bf9d9b4fd163afe38b6589.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 5. Do you see the repeating constants in the middle?<\/b> <\/p>\n<p>We decided to Google the constants, because yes, that\u2019s also an option! And they all eventually led to one algorithm \u2212 Batch Encryption. After studying the script, it became clear that our string is nothing more than the result of its work. It should be noted that this is not ransomware at all, but simply an encoder that replaces characters with 6-byte sequences. No keys or other secrets \ud83d\ude41<\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/20f26580ab8f5bf4d301e7212fefbf35.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 6. A piece of the original algorithm of unknown authorship. <\/b><\/p>\n<p>The algorithm would not have worked as intended if it weren't for one detail:<\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/c4cb297f51ba110f9c21866a9db29e34.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 7. Morpheus approved.<\/b><\/p>\n<p>Using reverse substitution, we convert the string from <b>pass.key<\/b> in the text of 27 characters. Special attention deserves the human (most likely) text \u2018asmodat\u2019. <\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/6e5ab19d688f9a085a327a883900d298.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 8. USGFDG=7.<\/b><\/p>\n<p>Google will help us again. After a brief search, we find an interesting project on GitHub \u2013 Folder Locker, written in .Net and using the \u2018asmodat\u2019 library from another account on Git. <\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/39de88fc343cabce3d8209e749ac6341.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 9. The Folder Locker interface. We definitely checked for malware. <\/b><\/p>\n<p>The utility is an encryptor for Windows 7 and later, distributed as open source. It uses a password for encryption, which is required for subsequent decryption. It can work with both individual files and entire directories.<\/p>\n<p>Its library uses the Rijndael symmetric encryption algorithm in CBC mode. Notably, the block size has been chosen to be 256 bits \u2013 unlike the 128-bit limit specified in the AES standard. <\/p>\n<p>Our key is formed according to the PBKDF2 standard. The password used is the SHA-256 of the string entered in the utility. We just need to find this string to form the decryption key. <\/p>\n<p>Well, let\u2019s return to our already decoded <b>pass.key<\/b>. Remember that line with a set of digits and the text \u2018asmodat\u2019? Let's try using the first 20 bytes of the string as a password for Folder Locker. <\/p>\n<p>Look at that, it works! The passphrase was correct, and everything decrypted perfectly. Judging by the password characters, it is a HEX representation of a specific word in ASCII. Let's try to display the passphrase in text form. We get \u2018<b>shadowwolf<\/b>\u2019. Already feeling symptoms of lycanthropy?<\/p>\n<p>Let's take another look at the structure of the affected file, now that we know how the locker works:<\/p>\n<ul>\n<li>02 00 00 00 \u2013 name encryption mode;<\/li>\n<li>58 00 00 00 \u2013 length of the encrypted and base64 encoded file name;<\/li>\n<li>40 00 00 00 \u2013 size of the transferred header.<\/li>\n<\/ul>\n<p>\nHighlighted in red and yellow are the encrypted name and the transferred header, respectively. <\/p>\n<p><img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/b96cb599127e3d4af198dd2065fd51e4.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 10. The encrypted name is highlighted in red, and the transferred header is highlighted in yellow. <\/b><\/p>\n<p>Now let's compare the encrypted and decrypted names in hexadecimal representation. <\/p>\n<p>Structure of the decrypted data:<\/p>\n<ul>\n<li>78 B9 B8 2E \u2013 garbage created by the utility (4 bytes);<\/li>\n<li>0C 00 00 00 \u2013 length of the decrypted name (12 bytes);<\/li>\n<li>then comes the actual file name and padding with zeros to the required block length.<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"Wulfric Ransomware \u2013 the encryptor that doesn&#039;t exist\" src=\"\/wp-content\/uploads\/2020\/02\/1e2a6e57f9a7f594a7394c03d2f52c5a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Fig. 11. IMG_4114 looks much better. <\/b><\/p>\n<h3>III. Conclusions and Summary<\/h3>\n<p>\nReturning to the beginning. We do not know what motivated the author of Wulfric.Ransomware or what goal he pursued. Undoubtedly, for the average user, the result of even such a ransomware's work will seem like a major disaster. Files cannot be opened. All names are gone. Instead of the familiar image, there is a wolf on the screen. They force users to read about bitcoins. <\/p>\n<p>However, this time, behind the guise of a 'fearsome encoder' was such a ridiculous and senseless attempt at extortion, where the perpetrator uses ready-made programs and leaves the keys right at the crime scene. <\/p>\n<p>By the way, about the keys. We did not have a malicious script or trojan that would allow us to understand how this <b>pass.key<\/b> \u2013 the mechanism of file appearance on the infected PC remains unknown. However, I remember that in his note, the author mentioned the uniqueness of the password. So, the code word for decryption is as unique as the username shadow wolf \ud83d\ude42<\/p>\n<p>And still, shadow wolf, why and for what purpose?<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/drweb\/blog\/486908\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0440\u043e\u0439 \u0442\u0430\u043a \u0445\u043e\u0447\u0435\u0442\u0441\u044f \u0437\u0430\u0433\u043b\u044f\u043d\u0443\u0442\u044c \u043a\u0430\u043a\u043e\u043c\u0443-\u043d\u0438\u0431\u0443\u0434\u044c \u0432\u0438\u0440\u0443\u0441\u043e\u043f\u0438\u0441\u0430\u0442\u0435\u043b\u044e \u0432 \u0433\u043b\u0430\u0437\u0430 \u0438 \u0441\u043f\u0440\u043e\u0441\u0438\u0442\u044c: \u0437\u0430\u0447\u0435\u043c \u0438 \u043f\u043e\u0447\u0435\u043c\u0443? \u0421 \u043e\u0442\u0432\u0435\u0442\u043e\u043c \u043d\u0430 \u0432\u043e\u043f\u0440\u043e\u0441 \u00ab\u043a\u0430\u043a\u00bb \u043c\u044b \u0441\u043f\u0440\u0430\u0432\u0438\u043c\u0441\u044f \u0441\u0430\u043c\u0438, \u0430 \u0432\u043e\u0442 \u0443\u0437\u043d\u0430\u0442\u044c, \u0447\u0435\u043c \u0434\u0443\u043c\u0430\u043b \u0440\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0441\u044f \u0442\u043e\u0442 \u0438\u043b\u0438 \u0438\u043d\u043e\u0439 \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e, \u0431\u044b\u043b\u043e \u0431\u044b \u043e\u0447\u0435\u043d\u044c \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e. \u0422\u0435\u043c \u0431\u043e\u043b\u0435\u0435, \u043a\u043e\u0433\u0434\u0430 \u043d\u0430\u043c \u043f\u043e\u043f\u0430\u0434\u0430\u044e\u0442\u0441\u044f \u0442\u0430\u043a\u0438\u0435 \u00ab\u0436\u0435\u043c\u0447\u0443\u0436\u0438\u043d\u044b\u00bb. \u0413\u0435\u0440\u043e\u0439 \u0441\u0435\u0433\u043e\u0434\u043d\u044f\u0448\u043d\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u2013 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u0439 \u044d\u043a\u0437\u0435\u043c\u043f\u043b\u044f\u0440 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a\u0430. \u0417\u0430\u0434\u0443\u043c\u044b\u0432\u0430\u043b\u0441\u044f \u043e\u043d, \u043f\u043e \u0432\u0441\u0435\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":41164,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41163","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0440\u043e\u0439 \u0442\u0430\u043a \u0445\u043e\u0447\u0435\u0442\u0441\u044f \u0437\u0430\u0433\u043b\u044f\u043d\u0443\u0442\u044c \u043a\u0430\u043a\u043e\u043c\u0443-\u043d\u0438\u0431\u0443\u0434\u044c \u0432\u0438\u0440\u0443\u0441\u043e\u043f\u0438\u0441\u0430\u0442\u0435\u043b\u044e \u0432 \u0433\u043b\u0430\u0437\u0430 \u0438 \u0441\u043f\u0440\u043e\u0441\u0438\u0442\u044c: \u0437\u0430\u0447\u0435\u043c \u0438 \u043f\u043e\u0447\u0435\u043c\u0443?\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/wulfric-ransomware-shifrovalshhik-kotorogo-net\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Wulfric Ransomware \u2013 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a, \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043d\u0435\u0442 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0440\u043e\u0439 \u0442\u0430\u043a \u0445\u043e\u0447\u0435\u0442\u0441\u044f \u0437\u0430\u0433\u043b\u044f\u043d\u0443\u0442\u044c \u043a\u0430\u043a\u043e\u043c\u0443-\u043d\u0438\u0431\u0443\u0434\u044c \u0432\u0438\u0440\u0443\u0441\u043e\u043f\u0438\u0441\u0430\u0442\u0435\u043b\u044e \u0432 \u0433\u043b\u0430\u0437\u0430 \u0438 \u0441\u043f\u0440\u043e\u0441\u0438\u0442\u044c: \u0437\u0430\u0447\u0435\u043c \u0438 \u043f\u043e\u0447\u0435\u043c\u0443?\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/wulfric-ransomware-shifrovalshhik-kotorogo-net\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-06T07:06:32+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-06T07:06:32+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Wulfric Ransomware \u2013 the ransomware that does not exist | ProHoster","description":"Sometimes, you just want to look a virus writer in the eye and ask: why and for what?","canonical_url":"https:\/\/prohoster.info\/en\/blog\/wulfric-ransomware-shifrovalshhik-kotorogo-net","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Wulfric Ransomware \u2013 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a, \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043d\u0435\u0442 | ProHoster","og:description":"\u041f\u043e\u0440\u043e\u0439 \u0442\u0430\u043a \u0445\u043e\u0447\u0435\u0442\u0441\u044f \u0437\u0430\u0433\u043b\u044f\u043d\u0443\u0442\u044c \u043a\u0430\u043a\u043e\u043c\u0443-\u043d\u0438\u0431\u0443\u0434\u044c \u0432\u0438\u0440\u0443\u0441\u043e\u043f\u0438\u0441\u0430\u0442\u0435\u043b\u044e \u0432 \u0433\u043b\u0430\u0437\u0430 \u0438 \u0441\u043f\u0440\u043e\u0441\u0438\u0442\u044c: \u0437\u0430\u0447\u0435\u043c \u0438 \u043f\u043e\u0447\u0435\u043c\u0443?","og:url":"https:\/\/prohoster.info\/en\/blog\/wulfric-ransomware-shifrovalshhik-kotorogo-net","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-06T07:06:32+00:00","article:modified_time":"2020-02-06T07:06:32+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"41163","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 22:24:47","updated":"2022-09-28 11:39:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/41163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=41163"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/41163\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/41164"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=41163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=41163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=41163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}