Decryption method and device based on ransomware

By obtaining ransomware samples and suspicious seed keys, and using known plaintext files and resulted ciphertext files to determine ransomware samples, the problem of lack of universality in the decryption scheme in the prior art is solved, and the generalized automatic decryption of different ransomware samples is achieved.

CN119995842APending Publication Date: 2025-05-13QI AN XIN TECHNOLOGY GROUP INC
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411918401.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing decryption scheme based on ransomware samples lacks universality and cannot effectively decrypt the encryption methods used by different ransomware samples.

Method used

By obtaining ransomware samples and suspicious seed keys, the encryption algorithm for the ransomware samples is determined using known plaintext files and resulted ciphertext files, corresponding decryption algorithms are generated, and the ransomware samples are controlled to use the decryption algorithm to decrypt the target file in the original environment.

Benefits of technology

It realizes generalized automatic decryption of different ransomware samples, avoiding the limitations of understanding the key generation method and encryption sharding method of ransomware samples.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995842A_ABST
    Figure CN119995842A_ABST
Patent Text Reader

Abstract

The invention provides a decryption method and device based on a ransomware, and the method comprises the steps: obtaining the ransomware and obtaining a suspicious seed key when a target file after the ransomware is encrypted needs to be decrypted, and enabling the suspicious seed key to be recorded in the target file encryption process of the ransomware; processing a known plaintext file through the ransomware sample to obtain a result ciphertext file; based on the known plaintext file and the result ciphertext file, determining an encryption algorithm of the ransomware sample; generating a decryption algorithm corresponding to the encryption algorithm; and controlling the ransomware to generate a key based on the suspicious seed key, and controlling the ransomware to decrypt the target file by adopting the key and the decryption algorithm to obtain an original file corresponding to the target file. And for different ransomware samples, the mode can be adopted for decryption, so that generalization automatic decryption based on the ransomware samples is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal device security protection technology, and in particular to a decryption method based on a ransomware sample, a decryption device based on a ransomware sample, an electronic device, and a terminal device readable storage medium. Background Art

[0002] Ransomware samples refer to software programs that encrypt files on user terminal devices and require users to pay a ransom before decrypting and restoring the files on the user terminal devices. Ransomware samples invade user terminal devices and cause data or economic losses to users.

[0003] After the ransomware sample invades the user's terminal device and encrypts the files in the user's terminal device, the user can obtain the ransomware sample from the terminal device without paying the ransom, as well as the relevant information when the ransomware sample encrypted the file, and conduct manual analysis based on the ransomware sample and related information to determine the possible encryption method of the ransomware sample, and then infer the decryption method based on the encryption method, so as to use the inferred decryption method to decrypt the files encrypted by the ransomware sample in the terminal device.

[0004] However, different ransomware samples use different encryption methods. For example, for most ransomware samples, the encryption key is first dynamically generated, and then the file is encrypted in pieces using the encryption key. Then, asymmetric information is appended to the end of the encrypted file to produce the final encrypted file. However, for different ransomware samples, the method of generating encryption keys, the file segments selected for the encrypted file, and the asymmetric information appended to the end are all different. Therefore, the encryption method of the ransomware sample is analyzed through the ransomware sample and the related information when the ransomware sample encrypts the file. It is aimed at a ransomware sample and adopts an analysis method based on the actual situation. It can be seen that the current decryption scheme based on the ransomware sample is not universal. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide a decryption method based on a ransom sample, a decryption device based on a ransom sample, an electronic device, and a terminal device readable storage medium, so as to provide a universal decryption solution based on a ransom sample.

[0006] In order to solve the above technical problems, the embodiments of the present application provide the following technical solutions:

[0007] A first aspect of the present application provides a decryption method based on a ransomware sample, the method comprising: when it is necessary to decrypt a target file encrypted by the ransomware sample, obtaining the ransomware sample, and obtaining a suspicious seed key, the suspicious seed key being recorded by the ransomware sample during the encryption process of the target file; processing a known plaintext file by the ransomware sample to obtain a result ciphertext file; determining an encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file; generating a decryption algorithm corresponding to the encryption algorithm; controlling the ransomware sample to generate a key based on the suspicious seed key, and controlling the ransomware sample to decrypt the target file using the key and the decryption algorithm to obtain an original file corresponding to the target file.

[0008] Compared with the prior art, the decryption method based on the ransom sample provided in the first aspect of the present application uses a known plaintext file to encrypt it using the ransom sample, so that the encryption algorithm used by the ransom sample can be known, and then the corresponding decryption algorithm can be inferred. Then, the environment when the ransom sample was previously encrypted is restored through the suspicious seed key recorded when the ransom sample was encrypted, and the ransom sample is controlled to use the decryption algorithm to process the encrypted target file. In this way, without knowing the key generation method and encryption fragmentation method of the ransom sample, the ransom sample is reused so that the ransom sample actually decrypts the target file in its original manner. After the decryption is completed, the ransom sample is no longer used to continue processing the file. Because the subsequent processing of the file is actually to append asymmetric information to the end of the file. The file obtained at this time is the original file corresponding to the target file. For different ransom samples, this method can be used for decryption, realizing universal automatic decryption based on the ransom sample.

[0009] In some modified implementations of the first aspect of the present application, the encryption algorithm of the ransomware sample is determined based on the known plaintext file and the result ciphertext file, including: performing automated reverse analysis on the known plaintext file and the result ciphertext file to obtain an initial encryption algorithm; extracting parameters in the initial encryption algorithm; and verifying the encryption algorithm of the ransomware sample based on the parameters, multiple known encryption algorithms, known plaintext files, and the result ciphertext file.

[0010] In general, ransomware samples use known encryption algorithms, with only minor adjustments to the parameters in the algorithm. By automatically reverse-engineering known plaintext files and resulting ciphertext files, we can obtain the parameters used by the ransomware sample encryption algorithm, and combine the obtained parameters with the known algorithm to achieve a simple and accurate cracking of the ransomware sample encryption method.

[0011] In some modified implementations of the first aspect of the present application, the encryption algorithm of the ransomware sample is verified based on parameters, multiple known encryption algorithms, known plaintext files and result ciphertext files, including: for each known encryption algorithm, using parameters to replace the parameters at the corresponding positions in the known encryption algorithm to obtain a pending encryption algorithm; using the pending encryption algorithm to process the known plaintext file to obtain a verification ciphertext file; determining whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to a first threshold; if so, determining the pending encryption algorithm as the encryption algorithm of the ransomware sample; the method also includes: if not, outputting a prompt message that decryption cannot be performed.

[0012] In a few cases, ransomware samples also use self-compiled encryption algorithms. In this case, it is impossible to restore the known encryption algorithms. By outputting prompt information, users can be prompted to change other methods to decrypt files, thereby improving the efficiency of file decryption.

[0013] In some modified implementations of the first aspect of the present application, before determining the encryption algorithm of the ransom sample based on the known plaintext file and the result ciphertext file, the method also includes: matching the ransom sample with multiple general encryption algorithms; if the match is successful, determining the successfully matched general encryption algorithm as the encryption algorithm of the ransom sample; if the match fails, executing the step of determining the encryption algorithm of the ransom sample based on the known plaintext file and the result ciphertext file.

[0014] In some cases, the ransomware sample may directly use a common encryption algorithm without making any changes to the common encryption algorithm. First, check whether there is a common encryption algorithm in the ransomware sample. If it exists, you can directly find the encryption algorithm used by the ransomware sample, which can more quickly determine the encryption algorithm used by the ransomware sample, improve the efficiency of determining the encryption algorithm used by the ransomware sample, and thus improve the efficiency of file decryption.

[0015] In some modified implementations of the first aspect of the present application, before determining the successfully matched general encryption algorithm as the encryption algorithm of the ransom sample, the method also includes: using the successfully matched general encryption algorithm to process a known plaintext file to obtain a verification ciphertext file; determining whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to a second threshold; if so, executing the step of determining the successfully matched general encryption algorithm as the encryption algorithm of the ransom sample; if not, executing the step of determining the encryption algorithm of the ransom sample based on the known plaintext file and the result ciphertext file.

[0016] After determining the common encryption algorithm in the ransomware sample, the determined common encryption algorithm is verified using a known plaintext file, and after the verification is passed, the determined common encryption algorithm is determined as the encryption algorithm of the ransomware sample. This can improve the accuracy of determining the encryption algorithm of the ransomware sample, and while improving the efficiency of file decryption, it can ensure the accuracy of file decryption.

[0017] In some modified implementations of the first aspect of the present application, controlling the ransomware sample to decrypt the target file using a key and a decryption algorithm to obtain the original file corresponding to the target file, including: controlling the ransomware sample to decrypt in sequence starting from the header of the target file using a key and a decryption algorithm; determining whether the ransomware sample has completed decryption based on the progress of the ransomware sample; if so, deleting the data after the decryption completion position to obtain the original file corresponding to the target file.

[0018] By monitoring the progress of the ransomware sample, we can accurately determine the location in the target file where the ransomware sample completes decryption, and delete the data after that location, thereby improving the accuracy of file decryption.

[0019] In some modified implementations of the first aspect of the present application, determining whether the ransom sample has completed decryption based on the process of the ransom sample includes: judging whether the process of the ransom sample calls the write function twice in a row, and if so, determining that the ransom sample has completed decryption when the write function is called for the second time of the two consecutive times; if not, determining that the ransom sample has not completed decryption; and / or, monitoring the task execution status of the process of the ransom sample, determining that the ransom sample has completed decryption when the task execution is monitored for the first time, and determining that the ransom sample has completed decryption when the task execution is not monitored to be completed, determining that the ransom sample has not completed decryption.

[0020] When the ransomware sample is encrypted and the tail information is appended, the corresponding function will be called in the process. By monitoring the function called by the process, the accuracy of the ransomware sample decryption completion can be improved, thereby improving the accuracy of file decryption. In addition, the ransomware sample encrypts and appends the tail information, which are two tasks. By monitoring whether the first task of the ransomware sample process is completed, it can be simply and accurately determined whether the ransomware sample has completed decryption, thereby improving the efficiency and accuracy of file decryption.

[0021] In some changed implementation modes of the first aspect of the present application, the suspicious seed key includes environmental parameters of the terminal device, and the environmental parameters include a timestamp; before controlling the ransomware sample to generate a key based on the suspicious seed key, the method also includes: pushing back the timestamp step by step according to a preset time interval to obtain multiple time points before the timestamp; using multiple time points to replace the timestamp in the environmental parameters respectively to obtain multiple new environmental parameters; controlling the ransomware sample to generate a key based on the suspicious seed key, and controlling the ransomware sample to decrypt the target file using the key and the decryption algorithm to obtain the original file corresponding to the target file, including: controlling the ransomware sample to generate a key under each new environmental parameter, and controlling the ransomware sample to decrypt the target file using each key and the decryption algorithm respectively, and correspondingly obtaining multiple candidate files; determining the candidate file with correct format and content as the original file corresponding to the target file.

[0022] Since the time when the ransomware sample was encrypted was recorded before, and the ransomware sample will generate a key before encryption, if the time is used when generating the key, then the key generation time will be earlier than the previously recorded ransomware sample encryption time. It is impossible to determine how much earlier it is. At this time, several times can be inferred based on the timestamp in the environmental parameters. One of the times may be the key generation time. Then, a new set of environmental parameters is generated based on each inferred time, so that the ransomware sample can decrypt the target file under different new environmental parameters. The ransomware sample can only correctly decrypt the target file with the key generated under the correct new environmental parameters. The file with the correct format and content among multiple decrypted files is the original file, thereby achieving correct decryption of the file.

[0023] In some changed implementation modes of the first aspect of the present application, before obtaining the suspicious seed key, the method also includes: in response to detecting the start of a suspicious process in the terminal device, obtaining the current environmental parameters of the terminal device; the obtaining of the suspicious seed key includes: when it is determined that the suspicious process is a ransomware process, determining the environmental parameters as the suspicious seed key.

[0024] Before encrypting the ransomware sample, the current environment parameters of the terminal device are obtained for suspicious processes. Compared with obtaining the environment parameters of all processes on the terminal device, the storage amount of the environment parameters can be reduced while ensuring that the environment parameters are available based on the ransomware sample, thus alleviating the storage burden on the terminal device.

[0025] The second aspect of the present application provides a decryption device based on a ransom sample, the device comprising: an acquisition module, used to acquire the ransom sample when it is necessary to decrypt the target file encrypted by the ransom sample, and to acquire a suspicious seed key, the suspicious seed key being recorded by the ransom sample during the target file encryption process; an encryption module, used to process a known plaintext file through the ransom sample to obtain a result ciphertext file; a determination module, used to determine the encryption algorithm of the ransom sample based on the known plaintext file and the result ciphertext file; a generation module, used to generate a decryption algorithm corresponding to the encryption algorithm; a decryption module, used to control the ransom sample to generate a key based on the suspicious seed key, and control the ransom sample to decrypt the target file using the key and the decryption algorithm to obtain the original file corresponding to the target file.

[0026] The third aspect of the present application provides an electronic device, which includes: a processor, a memory, and a bus; wherein the processor and the memory communicate with each other through the bus; and the processor is used to call program instructions in the memory to execute the method in the first aspect.

[0027] A fourth aspect of the present application provides a terminal device readable storage medium, the storage medium comprising: a stored program; wherein when the program is running, the device where the storage medium is located is controlled to execute the method in the first aspect.

[0028] The decryption device based on the ransomware sample provided in the second aspect of this application, the electronic device provided in the third aspect, and the terminal device readable storage medium provided in the fourth aspect have the same or similar beneficial effects as the decryption method based on the ransomware sample provided in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] By reading the detailed description below with reference to the accompanying drawings, the above and other purposes, features and advantages of the exemplary embodiments of the present application will become easy to understand. In the accompanying drawings, several embodiments of the present application are shown in an exemplary and non-limiting manner, and the same or corresponding reference numerals represent the same or corresponding parts, wherein:

[0030] Figure 1 This is a schematic diagram of the scenario architecture of the decryption method based on the ransomware sample in the embodiment of the present application;

[0031] Figure 2 The process diagram of the decryption method based on the ransomware sample in the embodiment of the present application is as follows Figure 1 ;

[0032] Figure 3 The process diagram of the decryption method based on the ransomware sample in the embodiment of the present application is as follows Figure 2 ;

[0033] Figure 4 The structure of the decryption device based on the ransomware sample in the embodiment of the present application is shown in FIG. Figure 1 ;

[0034] Figure 5 The structure of the decryption device based on the ransomware sample in the embodiment of the present application is shown in FIG. Figure 2 ;

[0035] Figure 6 Schematic diagram of the structure of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0036] The exemplary embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present application and to fully convey the scope of the present application to those skilled in the art.

[0037] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in this application should have the common meanings understood by technicians in the field to which this application belongs.

[0038] Currently, there is no universal way to decrypt files encrypted by ransomware samples.

[0039] In view of this, the embodiments of the present application provide a decryption method based on a ransom sample, a decryption device based on a ransom sample, an electronic device, and a terminal device readable storage medium. By reusing the ransom sample, a known plaintext file is encrypted, thereby obtaining the encryption algorithm of the ransom sample, and then obtaining the corresponding decryption algorithm. Then, the ransom sample is controlled to actually decrypt the target file using the decryption algorithm in the environment when it was previously encrypted. In the case where the generation method of the ransom sample encryption key, the encryption fragmentation method, and the tail information appending method are all unknown, the ransom sample is decrypted in the original manner, thereby realizing universal automatic decryption based on the ransom sample.

[0040] First, the application scenario of the decryption method based on the ransomware sample provided in the embodiment of the present application is described.

[0041] Figure 1 This is a schematic diagram of the scenario architecture of the decryption method based on the ransomware sample in the embodiment of the present application, see Figure 1 As shown, the architecture may include: a terminal device 11, a user 12 and a blackmailer 13.

[0042] The terminal device 11 may refer to any hardware device with data processing function, such as a server, a mobile phone, a laptop computer, etc.

[0043] The user 12 can process the corresponding data using the terminal device 11. In the terminal device 11, various data files 111 before and after the processing by the user 12 are stored.

[0044] The blackmailer 13 designs a blackmail sample 131 and implants the blackmail sample 131 into the terminal device 11 through various covert means, and then uses the blackmail sample 131 to encrypt the file 111 in the terminal device 11, and then requires the user 12 of the terminal device 11 to pay the ransom to achieve the purpose of blackmail.

[0045] In practical applications, the decryption method based on the ransom sample provided in the embodiment of the present application can be pre-installed in the terminal device 11 as a software program. When the ransom sample 131 encrypts the file 111 in the terminal device 11, the software program only observes and records. After the ransom sample 13 completes the file encryption and implements the ransom, the software program decrypts the file encrypted by the ransom sample 131 based on the ransom sample 131, the recorded data, the known plaintext file, etc., thereby realizing universal automatic decryption based on the ransom sample.

[0046] Alternatively, after the file 111 in the terminal device 11 has been encrypted by the ransom sample 131, the decryption method based on the ransom sample provided in the embodiment of the present application is used to obtain relevant data from the terminal device 11, and then the file encrypted by the ransom sample 131 is decrypted based on the ransom sample 131, the relevant data, known plaintext files, etc., thereby realizing universal automatic decryption based on the ransom sample.

[0047] Next, the decryption method based on the ransomware sample provided in the embodiment of the present application is described in detail.

[0048] Figure 2 The process diagram of the decryption method based on the ransomware sample in the embodiment of the present application is as follows Figure 1 , see Figure 2 As shown, the method may include:

[0049] S21: When it is necessary to decrypt the target file encrypted by the ransomware sample, the ransomware sample is obtained, and a suspicious seed key is obtained, where the suspicious seed key is recorded by the ransomware sample during the target file encryption process.

[0050] After the ransomware sample invades the terminal device, encrypts the files in the terminal device, and extorts the user of the terminal device, the ransomware sample is generally not deleted from the terminal device. Therefore, the ransomware sample can be directly extracted from the terminal device. Specifically, the storage location of the ransomware sample can be found in the terminal device through the relevant information of the ransomware process, thereby obtaining the ransomware sample.

[0051] In the case where the ransomware sample is automatically deleted after completing the ransomware, since the automatic deletion of the ransomware sample only deletes the data stored in the terminal device disk, and the ransomware sample has just completed the ransomware, the data of the ransomware sample in the terminal device memory has not been overwritten. At this time, the ransomware sample can be obtained from the terminal device's memory.

[0052] For terminal devices, relevant data will be recorded during the running of each process. For the process used by the ransomware sample to encrypt the target file, the relevant data during its running process will also be recorded. When the target file needs to be decrypted, the ransomware process can be locked through the ransomware sample, and the relevant data recorded when the ransomware process is running can be obtained and used as a suspicious seed key.

[0053] The relevant data here may refer to all parameters involved in the operation of the terminal device, such as: process identifier (PID), thread identifier (TID), various hardware information, timestamp, etc.

[0054] S22: Process the known plaintext file through the ransomware sample to obtain the resulting ciphertext file.

[0055] The target file has been encrypted by the ransomware sample. The user does not have the original file, and thus cannot determine the encryption algorithm of the ransomware sample based on the comparison between the original file and the encrypted target file. At this point, another plaintext data, namely the known plaintext file, can be used to control the ransomware sample to encrypt the known plaintext file, and obtain the encrypted known plaintext file, namely the result ciphertext file. In this way, a pair of files before and after encryption is obtained. The encryption algorithm of the ransomware sample can be obtained by using the files before and after encryption.

[0056] In the process of reusing ransomware samples or controlling the operation of ransomware samples, the ransomware samples can be controlled through the Hook function. Of course, other control methods can also be used to control the ransomware samples. For example: composable functions (Composables). The specific method of controlling the operation of ransomware samples is not limited here.

[0057] S23: Determine the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file.

[0058] During the encryption process, the ransomware sample will generally randomly generate a key, then use the key to encrypt the terminal device file in pieces using a certain encryption algorithm, and append arbitrary information to the end of the encrypted file. However, it is not easy to obtain the key and its generation method, the fragmentation method during encryption, and the specific information appended to the end through only a pair of known plaintext files and result ciphertext files. In this case, the encryption algorithm of the ransomware sample can be determined only through the known plaintext files and result ciphertext files.

[0059] In the specific process of determining the encryption algorithm, given that the ransomware party is more likely to use an existing encryption algorithm, and modify the algorithm's key generation method, fragment encryption method, tail appending method, etc., to perform encrypted ransomware on terminal device files, therefore, various publicly available encryption algorithms can be collected in advance, and then known plaintext files can be processed using each publicly available encryption algorithm. By comparing the processed files with the resulting ciphertext files, it is possible to determine which known encryption algorithm the ransomware sample uses, thereby determining the encryption algorithm of the ransomware sample.

[0060] Alternatively, the resulting ciphertext file may be compared with the known plaintext file to determine the encryption method used by the ransomware sample through content comparison, and then the encryption algorithm corresponding to the same encryption method may be found among the known encryption algorithms to be used as the encryption algorithm of the ransomware sample.

[0061] After determining the encryption algorithm of the ransomware sample, when the key generation method, encryption fragmentation method, tail appending method, etc. of the ransomware sample are unknown, since the ransomware sample itself knows its key generation method, encryption fragmentation method, tail appending method, etc., the ransomware sample can be reused, but the ransomware sample needs to be decrypted in reverse. That is, the ransomware sample is controlled not to use its encryption algorithm, but to use the decryption algorithm corresponding to the encryption algorithm to process the target file.

[0062] S24: Generate a decryption algorithm corresponding to the encryption algorithm.

[0063] The decryption algorithm can be generated based on the encryption algorithm by using a known tool with algorithm inversion function or by manual acquisition. As for the specific process of generating the decryption algorithm from the encryption algorithm, this is a well-known technology and will not be described here.

[0064] The ransomware sample, suspicious seed key, and decryption algorithm have all been prepared. Next, we can control the ransomware sample and use the key generation method and encryption fragmentation method known to the ransomware sample to reversely decrypt the target file.

[0065] S25: Control the ransomware sample to generate a key based on the suspicious seed key, and control the ransomware sample to decrypt the target file using the key and decryption algorithm to obtain the original file corresponding to the target file.

[0066] A space is divided in the terminal device, and a suspicious seed key is configured for the space, so that the space is the same as the terminal device environment when the ransomware sample was previously encrypted. The ransomware sample is controlled to run in the space, and the Hook function is used to control the ransomware sample to no longer use its encryption algorithm, but to use the decryption algorithm deduced this time to decrypt the target file. From the perspective of the ransomware sample, the target file is an ordinary file in the terminal device, which can be encrypted to achieve the purpose of ransom. However, from the perspective of this method, the key generation method and encryption sharding method known by the ransomware sample are used to run the decryption algorithm to achieve the decryption of the target file.

[0067] As can be seen from the above content, the decryption method based on the ransom sample provided in the embodiment of the present application uses a known plaintext file to encrypt it using the ransom sample, and the encryption algorithm used by the ransom sample can be known, and the corresponding decryption algorithm can be deduced. Next, the environmental parameters of the ransom sample previously implemented encryption are simulated, and the ransom sample is controlled to use the decryption algorithm to process the target file. In this way, without knowing the key generation method and encryption sharding method of the ransom sample, the ransom sample is reused so that the ransom sample actually decrypts the target file in its original manner. After the decryption is completed, the ransom sample is no longer used to continue processing the file. Because the subsequent processing of the file is actually to append asymmetric information to the end of the file. The file obtained at this time is the original file corresponding to the target file. For different ransom samples, this method can be used for decryption, realizing universal automatic decryption based on the ransom sample.

[0068] Furthermore, as a Figure 2 As a refinement and extension of the method shown, the embodiment of the present application also provides a decryption method based on a ransomware sample.

[0069] Figure 3 The process diagram of the decryption method based on the ransomware sample in the embodiment of the present application is as follows Figure 2 , see Figure 3 As shown, the method may include:

[0070] S31: In response to detecting the start of a suspicious process in the terminal device, obtaining current environment parameters of the terminal device.

[0071] When the terminal device is running, the security defense module in the terminal device will perform security detection on the processes started in the terminal device. For each process started in the terminal device, the security defense module performs security detection on it. The detection result is one of white process, black process, unknown process and suspicious process. If the currently started process is determined to be a white process, it means that the process is safe and not a ransomware process. At this time, there is no need to record the current environmental parameters of the terminal device. If the currently started process is determined to be a black process, the security defense module will immediately respond to the process, such as: disable, delete, etc., and the process will not have the next step, and will not perform encryption ransomware. At this time, there is no need to record the current environmental parameters of the terminal device. If the currently started process is determined to be an unknown process, since the process has no abnormal behavior before, the probability of implementing encryption ransomware is low, and there is no need to record the current environmental parameters of the terminal device at this time. If the currently started process is determined to be a suspicious process, it means that the process has been found to have some behaviors that are not enough to be determined as a black process, but are different from normal behaviors. There is a certain probability that encryption ransomware may be implemented in the future. At this time, it is necessary to record the current environmental parameters of the terminal device.

[0072] S32: When the suspicious process is determined to be a ransomware process, the environmental parameter is determined as a suspicious seed key.

[0073] When the terminal device files are encrypted and the terminal device user is blackmailed, it means that there is a blackmail process in the previously determined suspicious processes. At this time, the blackmail process is locked in the suspicious process based on the blackmail information, so as to obtain the environmental parameters recorded based on the blackmail process, and the environmental parameters are used as the suspicious seed key of the terminal device environment when the blackmail sample was previously encrypted.

[0074] S33: When it is necessary to decrypt the target file encrypted by the ransomware sample, the ransomware sample is obtained, and the suspicious seed key is obtained.

[0075] The specific implementation method of step S32 here is the same as that of step S21 in the aforementioned embodiment. Please refer to the relevant description in the aforementioned embodiment and will not be repeated here.

[0076] S34: Match the ransomware sample with multiple common encryption algorithms. If the match is successful, execute S35; if the match fails, execute S36.

[0077] For ransomware samples, the encryption algorithms used are rarely self-created. Most of them are obtained by slightly modifying the public common encryption algorithms, or even using them directly without any modification. Therefore, we can check whether there is a common encryption algorithm in the ransomware sample, and if we find that there is a common encryption algorithm, we can directly determine the encryption algorithm used by the ransomware sample.

[0078] The matching here may refer to calculating the similarity between the data in the ransomware sample and the data in the general encryption algorithm. When the similarity is greater than or equal to a certain threshold, the match is determined to be successful. When the similarity is less than a certain threshold, the match is determined to be unsuccessful. The threshold can be configured according to the actual situation and is not specifically limited here.

[0079] The match here can also refer to checking whether there is a keyword of a common encryption algorithm in the ransomware sample. If it exists, it is determined that the match is successful. If not, it is determined that the match fails. The keyword here can uniquely characterize the common encryption algorithm.

[0080] In some cases, multiple general encryption algorithms may successfully match the ransom sample. Considering that the functions of the multiple general encryption algorithms that successfully match the ransom sample are roughly the same, and the encryption method is the same as that of the ransom sample, a general encryption algorithm can be selected from the multiple general encryption algorithms that successfully match to determine the encryption algorithm of the ransom sample. Of course, in order to accurately determine the encryption algorithm of the ransom sample, the general encryption algorithm with the highest matching degree can also be selected from the multiple general encryption algorithms that match to determine the encryption algorithm of the ransom sample.

[0081] S35: Determine the successfully matched universal encryption algorithm as the encryption algorithm of the ransomware sample.

[0082] If the match is successful, it means that the corresponding universal encryption algorithm is used in the ransomware sample. At this time, the successfully matched universal encryption algorithm can be directly determined as the encryption algorithm of the ransomware sample. In this way, the step of processing known plaintext files can be omitted, and the efficiency of obtaining encryption algorithms can be improved.

[0083] In order to ensure the accuracy of the determined encryption algorithm, the successfully matched general encryption algorithm can also be verified first, and after the verification is passed, the successfully matched general encryption algorithm can be determined as the encryption algorithm of the ransomware sample. The verification process can use known plaintext files.

[0084] Control the ransomware sample to encrypt the known plaintext file and obtain the result ciphertext file. The result ciphertext file is encrypted according to the real encryption algorithm in the ransomware sample. If the successfully matched general encryption algorithm can also encrypt the known plaintext file into a file that is similar to the result ciphertext file, then it is determined that the successfully matched general encryption algorithm is the encryption algorithm used by the ransomware sample.

[0085] Specifically, before the above step S35, the method may include:

[0086] Step A1: Use the successfully matched universal encryption algorithm to process the known plaintext file to obtain a verification ciphertext file.

[0087] Step A2: Determine whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to a second threshold. If so, execute the above step S35; if not, execute the subsequent step S36.

[0088] Since the general encryption algorithm based on the verification ciphertext file is only an encryption process, and the processing of the ransomware sample based on the result ciphertext file includes not only an encryption process but also a tail information appending process, the second threshold used to verify whether the verification ciphertext file is similar to the result ciphertext file can be a percentage less than 100%.

[0089] If the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to the second threshold, it means that the verification ciphertext file and the result ciphertext file are relatively similar, and the only difference may be the appended data at the end. At this time, it can be determined that the universal encryption algorithm that successfully matches the ransomware sample is the encryption algorithm of the ransomware sample.

[0090] If the similarity between the verification ciphertext file and the result ciphertext file is less than the second threshold, it means that the verification ciphertext file and the result ciphertext file are not very similar. The ransomware may not directly use the existing general encryption algorithm for encryption, but may have improved the general encryption algorithm. At this time, the encryption algorithm of the ransomware sample can be determined by processing the known plaintext file through the ransomware sample.

[0091] S36: Process the known plaintext file through the ransomware sample to obtain the resulting ciphertext file.

[0092] The specific implementation method of step S36 here is the same as that of step S22 in the aforementioned embodiment. Please refer to the relevant description in the aforementioned embodiment and will not be repeated here.

[0093] S37: Perform automated reverse analysis on known plaintext files and result ciphertext files to obtain the initial encryption algorithm.

[0094] Through reverse analysis of the contents of the result ciphertext file and the known plaintext file, the encryption algorithm used by the ransomware sample, namely the initial encryption algorithm, can be roughly determined. The initial encryption algorithm can be obtained through known automated reverse analysis tools. Input the known plaintext file and the result ciphertext file into the automated reverse analysis tool. The output of the automated reverse analysis tool is the initial encryption algorithm. As for the specific type of automated reverse analysis tool, any tool that can analyze the encryption algorithm based on the files before and after encryption is acceptable, and there is no limitation here. Of course, the initial encryption algorithm can also be determined by manually analyzing the known plaintext file and the result ciphertext file.

[0095] It takes a long time to infer the decryption algorithm based on the initial encryption algorithm, and the accuracy cannot be guaranteed. Here, the decryption algorithm is inferred from the initial encryption algorithm only to use its corresponding encryption method and decryption method. If the parameters in the initial encryption algorithm are combined with the publicly available encryption algorithm, the encryption algorithm of the encryption method can also be obtained. Similarly, the decryption algorithm with the same decryption method can be obtained by combining the parameters in the initial encryption algorithm with the publicly available decryption algorithm corresponding to the publicly available encryption algorithm, thereby realizing the rapid determination of the ransomware sample encryption algorithm and its corresponding decryption algorithm.

[0096] S38: Extract parameters in the initial encryption algorithm.

[0097] Since the result ciphertext file is obtained by encrypting the known plaintext file by the ransomware sample, the result ciphertext file will contain various information about the encryption algorithm used by the ransomware sample. The initial encryption algorithm obtained by the automated reverse analysis of the result ciphertext file and the known plaintext file will contain various parameters in the actual encryption algorithm of the ransomware sample. Therefore, the parameters extracted from the initial encryption algorithm are the parameters contained in the actual encryption algorithm of the ransomware sample.

[0098] S39: Based on parameters, multiple known encryption algorithms, known plaintext files, and result ciphertext files, the encryption algorithm of the ransomware sample is verified.

[0099] The known encryption algorithms here, like the aforementioned general encryption algorithms, are all public encryption algorithms. We can collect as many public encryption algorithms as possible to ensure the accurate acquisition of the encryption algorithms of the ransomware samples.

[0100] Use the parameters extracted from the initial encryption algorithm to replace the corresponding parameters in the known encryption algorithm, and use the encryption algorithm after parameter replacement to encrypt the known plaintext file. Then, by comparing the resulting ciphertext file with the encrypted ransomware sample, the encryption algorithm used by the ransomware sample can be cracked.

[0101] Specifically, the above step S39 may include:

[0102] Step B1: For each known encryption algorithm, use parameters to replace the parameters at corresponding positions in the known encryption algorithm to obtain the pending encryption algorithm.

[0103] There are as many encryption algorithms as there are. After replacing the parameters, there are as many pending encryption algorithms as there are.

[0104] In the case where there are multiple parameters extracted from the initial encryption algorithm, the known encryption algorithm with the same encryption operation as the encryption algorithm of the ransomware sample should have the same parameter position as the parameter position in the initial encryption algorithm. The parameters in the initial encryption algorithm can be replaced with the corresponding positions in the known encryption algorithm. If the position of each parameter in the initial encryption algorithm does not correspond to the position of each parameter in a known encryption algorithm, it means that the specific encryption operation of the known encryption algorithm is quite different from that of the initial encryption algorithm, and it is highly likely that it is not the encryption algorithm used by the ransomware sample. Parameter replacement can be omitted to reduce the amount of data to be verified, improve verification efficiency, and thus improve file decryption efficiency.

[0105] Among these pending encryption algorithms, one may be the encryption algorithm of the ransom sample. Therefore, each pending encryption algorithm can be used to process the known plaintext file. If the ciphertext file obtained by the pending encryption algorithm is similar to the ciphertext file processed by the ransom sample, the pending encryption algorithm is the encryption algorithm of the ransom sample.

[0106] Step B2: Use the to-be-determined encryption algorithm to process the known plaintext file to obtain a verification ciphertext file.

[0107] That is, the known plaintext files are encrypted using various pending encryption algorithms to obtain the corresponding verification ciphertext files after being processed by each pending encryption algorithm.

[0108] Step B3: Determine whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to a first threshold. If yes, execute step B4; if no, execute step B5.

[0109] The result ciphertext file is obtained by processing the known plaintext file through the ransomware sample. Each verification ciphertext file is obtained by processing the known plaintext file through each pending encryption algorithm. Among the verification ciphertext files, the pending encryption algorithm corresponding to the verification ciphertext file whose similarity with the result ciphertext file is greater than the first threshold is the encryption algorithm consistent with the specific operation of the ransomware sample encryption, and can be regarded as the encryption algorithm used by the ransomware sample.

[0110] If the similarities between multiple verification ciphertext files and the result ciphertext file are all greater than or equal to the first threshold, the pending encryption algorithm corresponding to the verification ciphertext file with the greatest similarity may be selected as the only selected pending encryption algorithm.

[0111] Step B4: Determine the pending encryption algorithm as the encryption algorithm of the ransomware sample.

[0112] At this point, the encryption algorithm of the ransomware sample has been determined.

[0113] If the similarity between each verification ciphertext file and the result ciphertext file is less than the first threshold, it means that each verification ciphertext file is not similar to the result ciphertext file. Either the known algorithm used by the ransomware sample has not been obtained by this method, or the encryption algorithm used by the ransomware sample is designed by the ransomware party, and this method cannot crack it. At this time, a prompt message can be output to prompt the relevant personnel as soon as possible that the automatic decryption cannot be performed, so that the relevant personnel can take other methods to decrypt the file as soon as possible, avoiding the loss of relevant information required for decryption by other methods due to too long time, and improving the success rate of file decryption.

[0114] Step B5: Output a prompt message indicating that the decryption cannot be performed.

[0115] The prompt information here may include the known plaintext file and the result ciphertext file obtained previously, as well as the common encryption algorithm and the known encryption algorithm, so as to provide more information to assist in the rapid decryption of the file. The prompt information here may also only include information indicating that the decryption cannot be performed.

[0116] S310: Generate a decryption algorithm corresponding to the encryption algorithm.

[0117] The specific implementation method of step S310 here is the same as that of step S24 in the aforementioned embodiment. Please refer to the relevant description in the aforementioned embodiment and will not be repeated here.

[0118] After the decryption algorithm corresponding to the ransomware sample encryption is obtained, the ransomware sample can be reused in combination with the suspicious seed key to decrypt the target file.

[0119] If the ransom sample uses time when generating the key, this time is the time when the ransom sample generates the key. The time recorded in the suspicious seed key is the time when the ransom sample is actually encrypted. The key is generated first, and then encrypted using the key. The time actually used by the ransom sample and the time recorded in the suspicious seed key are two times one before and one after. The actual encryption time is provided to the ransom sample so that the ransom sample generates the key. Obviously, the key generated by the ransom sample in this case is wrong. Therefore, it is necessary to push forward the time recorded in the suspicious seed key. However, it is impossible to know how long to push forward, that is, the time difference between the ransom sample generating the key and the actual encryption. In view of this, multiple times can be pushed forward, and an environment can be simulated for the ransom sample at each time. Only at the correct time can the ransom sample generate the correct key and perform correct decryption.

[0120] The suspicious seed key includes environmental parameters of the terminal device, and the environmental parameters include a timestamp.

[0121] S311: Push back the timestamp step by step according to preset time intervals to obtain multiple time points before the timestamp.

[0122] Starting from the timestamp, push back at a certain time interval, push back a preset time interval, and get a time point. At this time point, push back a preset time interval again, and get another time point. Until you get the required multiple time points.

[0123] The number of pushbacks can be set according to actual needs or the total pushback duration. The total pushback duration can be determined based on the time it takes for historical ransomware samples to generate keys and encrypt. For example, the time it takes for ransomware samples to generate keys and encrypt generally does not exceed 60 seconds. Set 60 seconds as the total pushback duration and the preset time interval to 1 second. That is, starting from the timestamp in the environment parameters, move forward 1 second each time, and get a total of 60 time points.

[0124] The specific value of the preset time interval can be set according to actual conditions and is not limited here.

[0125] S312: Use multiple time points to replace the timestamps in the environment parameters respectively to obtain multiple new environment parameters.

[0126] The environmental parameters include not only the timestamp but also other parameters that characterize the terminal device environment. Other parameters that characterize the terminal device environment are not changed when the time point is replaced, but the original timestamp is replaced with each time point in the environmental parameters. In this way, multiple new environmental parameters are obtained. For example: the environmental parameters include time 1 and other parameters. Multiple time points include time points 2-9. Time 2 is used to replace time 1 to obtain a new environmental parameter 1 including time 2 and other parameters. Time 3 is used to replace time 1 to obtain a new environmental parameter 2 including time 3 and other parameters. ..., time 9 is used to replace time 1 to obtain a new environmental parameter 8 including time 11 and other parameters. A total of new environmental parameters 1-8 are obtained.

[0127] S313: Control the ransomware sample to generate a key under each new environmental parameter, and control the ransomware sample to use each key and decryption algorithm to decrypt the target file, thereby obtaining a plurality of candidate files.

[0128] The specific implementation method of step S313 here is the same as that of step S25 in the aforementioned embodiment. Please refer to the relevant description in the aforementioned embodiment and will not be repeated here.

[0129] However, the ransomware sample in step S313 needs to be run once under each new environment parameter, and multiple files are obtained, namely, files corresponding to each new environment parameter. Among these files, only the files whose time in the corresponding new environment parameter is consistent with the time when the ransomware sample previously generated the key are correct files. Therefore, these files can currently be called candidate files.

[0130] After encrypting the file, the ransomware sample will also append information to the end of the file. However, it is impossible to know the specific information appended and the specific amount of data of the appended information. However, the decryption process of the ransomware sample can be monitored. After the decryption is completed, the data after the decryption completion position in the file is the data appended to the end of the ransomware sample. This data can be deleted to achieve file tail removal.

[0131] Specifically, the above step S313 may include:

[0132] Step C1: Control the ransomware sample to use the key and decryption algorithm to decrypt the target file in sequence starting from the header.

[0133] Step C2: Determine whether the ransomware sample has been decrypted based on the progress of the ransomware sample. If yes, execute step C3; if no, execute step C2 again.

[0134] Step C3: Delete the data after the decryption completion position to obtain multiple candidate files corresponding to the target file.

[0135] The ransomware samples were run under multiple new environment parameters, generated multiple keys, performed multiple decryptions, and performed multiple tail removals, resulting in multiple candidate files.

[0136] When determining whether the ransomware sample has completed decryption based on the process of the ransomware sample, it is possible to accurately and efficiently determine whether the ransomware sample has completed the decryption operation based on the running status of the process or the function called by the process.

[0137] Specifically, the above step C2 may include:

[0138] C21: Determine whether the process of the ransomware sample calls the write function twice in succession. If so, it is determined that the ransomware sample has completed decryption when the write function is called the second time in the two consecutive times. If not, it is determined that the ransomware sample has not completed decryption.

[0139] Generally speaking, when a ransomware sample is encrypting, the process will first call the encryption function to encrypt the original file and obtain the encrypted data. Then, the process calls the write function to overwrite the original file with the encrypted data. At this point, the ransomware sample has completed the encryption of the original file. Next, the ransomware sample continues to append to the end. The process of the ransomware sample continues to call the write function to write the additional information to the end of the encrypted data. At this point, the target file encrypted by the ransomware sample is stored in the terminal device.

[0140] Therefore, when the process of the ransomware sample is monitored to call the write function for the second time, it can be determined that the ransomware sample has been decrypted.

[0141] Step C22: monitor the task execution status of the ransomware sample process. When the task execution is detected for the first time, determine that the ransomware sample has completed decryption. When the task execution is not detected for the first time, determine that the ransomware sample has not completed decryption.

[0142] For the ransomware sample, there are mainly two tasks. The first task is encryption, and the second task is to append the tail information. And the two tasks are executed one after the other. In other words, the process of the ransomware sample will first execute the encryption task, and then execute the tail information appending task. By monitoring the task execution status of the ransomware sample process, when the first task is monitored to be completed, it can be determined that the ransomware sample has completed decryption.

[0143] When conducting specific monitoring, you can use a professional process task execution status monitoring tool, or you can determine whether the ransomware sample has been decrypted based on whether you have obtained feedback information on the completion of a single task in the process, such as the task return value.

[0144] It should be noted here that the above steps C21 and C22 can be executed simultaneously or one at a time.

[0145] The ransomware sample decrypts the target file under different new environment parameters and removes the tail, thus obtaining multiple candidate files.

[0146] The ransomware sample can only generate the correct key and perform the correct decryption in the new environment parameters containing the correct time point. However, in the incorrect new environment parameters, the generated key is incorrect, and the decrypted file is also wrong. Therefore, by checking the format and content of the file, the original file corresponding to the target file can be determined from multiple candidate files.

[0147] S314: Determine the candidate file with correct format and content as the original file corresponding to the target file.

[0148] When selecting the original file from multiple candidate files, you can first select it by format. Generally speaking, if the wrong key is used for decryption, the format of the decrypted file is wrong. Therefore, you can directly select the candidate file with the correct format from multiple candidate files as the original file of the target file.

[0149] When selecting files by format, you can collect various file formats in advance, such as: .docx, .jpg, etc. Then, match the format of each file to be selected with the pre-collected format. If the format of a file to be selected is the same as a pre-collected format, it is determined that the format of the file to be selected is correct, which is the original file of the target file decrypted by the ransomware sample.

[0150] In rare cases, there may be two or more files to be selected that have the same format as the pre-collected format. At this point, the original file can be determined from the two or more files to be selected by file content.

[0151] Specifically, the candidate file with normal content can be determined as the original file of the target file by checking whether the content of the file is normal. For example, if the format of file 1 and file 2 are both .docx, part of the content of file 1 is garbled, and all the content of file 2 is normal, then file 2 can be determined to be the original file.

[0152] When the contents of two or more candidate files are normal, the original file can only be determined from the two or more candidate files by the terminal device user. Since the terminal device user knows the general or detailed content of the original file, the two or more candidate files can be displayed to the terminal device user, and the original file can be determined through the feedback of the terminal device user. For example: File 3 and File 4 are both in .jpg format, and both are color portraits. The hair in the portrait in File 3 is black, and the hair in the portrait in File 4 is white. In fact, the hair in the portrait in the original file is white, and the terminal device user knows this. After the terminal device user sees the portraits in File 3 and File 4, he can determine that File 4 is the original file.

[0153] At this point, the decryption method based on the ransomware sample provided in the embodiment of the present application has been fully described.

[0154] Based on the same inventive concept, as an implementation of the above method, the embodiment of the present application also provides a decryption device based on a ransomware sample.

[0155] Figure 4 The structure of the decryption device based on the ransomware sample in the embodiment of the present application is shown in FIG. Figure 1 , see Figure 4 As shown, the device may include: an acquisition module 41, an encryption module 42, a determination module 43, a generation module 44 and a decryption module 45.

[0156] The acquisition module 41 is used to acquire the ransom sample when it is necessary to decrypt the target file encrypted by the ransom sample, and to acquire the suspicious seed key, where the suspicious seed key is recorded by the ransom sample during the target file encryption process.

[0157] The encryption module 42 is used to process the known plaintext file through the ransomware sample to obtain a result ciphertext file.

[0158] The determination module 43 is used to determine the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file.

[0159] The generating module 44 is used to generate a decryption algorithm corresponding to the encryption algorithm.

[0160] The decryption module 45 is used to control the ransomware sample to generate a key based on the suspicious seed key, and control the ransomware sample to decrypt the target file using the key and the decryption algorithm to obtain the original file corresponding to the target file.

[0161] Furthermore, as a Figure 5 As a refinement and extension of the device shown, an embodiment of the present application also provides a decryption device based on a ransomware sample.

[0162] Figure 5 The structure of the decryption device based on the ransomware sample in the embodiment of the present application is shown in FIG. Figure 2 , see Figure 5 As shown, the device may include: a collection module 51, an acquisition module 52, a matching module 53, a verification module 54, a general module 55, an encryption module 56, a determination module 57, a generation module 58, an environment module 59, a decryption module 510 and a selection module 511.

[0163] The acquisition module 51 is used to obtain the current environment parameters of the terminal device in response to detecting the startup of a suspicious process in the terminal device.

[0164] The acquisition module 52 is used to determine the environmental parameter as a suspicious seed key when the suspicious process is determined to be a blackmail process.

[0165] The acquisition module 52 is also used to acquire the ransom sample when it is necessary to decrypt the target file encrypted by the ransom sample, and to acquire the suspicious seed key, where the suspicious seed key is recorded by the ransom sample during the target file encryption process.

[0166] The matching module 53 is used to match the ransomware sample with multiple common encryption algorithms. If the match is successful, the verification module 54 is entered; if the match fails, the encryption module 56 is entered.

[0167] The verification module 54 is used to process the known plaintext file with the successfully matched universal encryption algorithm to obtain the verification ciphertext file; and determine whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to the second threshold. If so, enter the universal module 55. If not, enter the encryption module 56.

[0168] The general module 55 is used to determine the successfully matched general encryption algorithm as the encryption algorithm of the ransomware sample.

[0169] The encryption module 56 is used to process the known plaintext file through the ransomware sample to obtain a result ciphertext file.

[0170] The determination module 57 is used to perform automatic reverse analysis on the known plaintext file and the result ciphertext file to obtain the initial encryption algorithm; extract the parameters in the initial encryption algorithm; and verify the encryption algorithm of the ransomware sample based on the parameters, multiple known encryption algorithms, the known plaintext file and the result ciphertext file.

[0171] The determination module 57 is specifically used to replace the parameters at the corresponding positions in the known encryption algorithm with the parameters for each known encryption algorithm to obtain the pending encryption algorithm; use the pending encryption algorithm to process the known plaintext file to obtain the verification ciphertext file; determine whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to the first threshold; if so, determine the pending encryption algorithm as the encryption algorithm of the ransomware sample; the method also includes: if not, output a prompt message that the decryption cannot be performed.

[0172] The generation module 58 is used to generate a decryption algorithm corresponding to the encryption algorithm.

[0173] When the suspicious seed key includes the environmental parameters of the terminal device, and the environmental parameters include a timestamp, the environmental module 59 is used to gradually push the timestamp back according to a preset time interval to obtain multiple time points before the timestamp; and use multiple time points to replace the timestamp in the environmental parameters respectively to obtain multiple new environmental parameters.

[0174] The decryption module 510 is used to control the ransomware sample to generate a key under each new environmental parameter, and control the ransomware sample to use each key and decryption algorithm to decrypt the target file, thereby obtaining a plurality of candidate files.

[0175] The decryption module 510 is also used to control the ransomware sample to use the key and decryption algorithm to decrypt the target file in sequence starting from the head of the target file; determine whether the ransomware sample has completed decryption based on the progress of the ransomware sample; if so, delete the data after the decryption completion position to obtain the original file corresponding to the target file.

[0176] The decryption module 510 is specifically used to determine whether the process of the ransomware sample calls the write function twice in succession. If so, it is determined that the ransomware sample has completed decryption when the write function is called for the second time of the two consecutive times. If not, it is determined that the ransomware sample has not completed decryption; and / or, monitor the task execution status of the process of the ransomware sample. When the task execution is monitored to be completed for the first time, it is determined that the ransomware sample has completed decryption. When the task execution is not monitored to be completed, it is determined that the ransomware sample has not completed decryption.

[0177] The selection module 511 is used to determine the candidate file with correct format and content as the original file corresponding to the target file.

[0178] It should be noted here that the description of the above device embodiment is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the device embodiment of the present application, please refer to the description of the method embodiment of the present application for understanding.

[0179] Based on the same inventive concept, an embodiment of the present application also provides an electronic device.

[0180] Figure 6 This is a schematic diagram of the structure of the electronic device in the embodiment of the present application, see Figure 6 As shown, the electronic device may include: a processor 61, a memory 62, and a bus 63; wherein the processor 61 and the memory 62 communicate with each other via the bus 63; the processor 61 is used to call program instructions in the memory 62 to execute the methods in one or more of the above embodiments.

[0181] It should be noted that the description of the above electronic device embodiment is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the electronic device embodiment of this application, please refer to the description of the method embodiment of this application for understanding.

[0182] Based on the same inventive concept, an embodiment of the present application also provides a terminal device readable storage medium, which may include: a stored program; wherein, when the program is running, the device where the storage medium is located is controlled to execute the method in one or more of the above embodiments.

[0183] It should be noted here that the description of the above storage medium embodiment is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the storage medium embodiment of the present application, please refer to the description of the method embodiment of the present application for understanding.

[0184] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A decryption method based on a ransomware sample, characterized in that: The method comprises: When it is necessary to decrypt the target file encrypted by the ransomware sample, the ransomware sample is obtained, and a suspicious seed key is obtained, where the suspicious seed key is recorded by the ransomware sample during the encryption process of the target file; Processing a known plaintext file through the ransomware sample to obtain a result ciphertext file; Determining an encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file; Generate a decryption algorithm corresponding to the encryption algorithm; The ransomware sample is controlled to generate a key based on the suspicious seed key, and the ransomware sample is controlled to decrypt the target file using the key and the decryption algorithm to obtain an original file corresponding to the target file.

2. The method according to claim 1, characterized in that The step of determining the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file includes: Performing automated reverse analysis on the known plaintext file and the result ciphertext file to obtain an initial encryption algorithm; Extracting parameters in the initial encryption algorithm; Based on the parameters, multiple known encryption algorithms, the known plaintext file and the result ciphertext file, the encryption algorithm of the ransomware sample is verified.

3. The method according to claim 2, characterized in that The step of verifying the encryption algorithm of the ransomware sample based on the parameters, multiple known encryption algorithms, the known plaintext file, and the result ciphertext file includes: For each known encryption algorithm, the parameters at corresponding positions in the known encryption algorithm are replaced by the parameters to obtain the pending encryption algorithm; Processing the known plaintext file using the pending encryption algorithm to obtain a verification ciphertext file; Determine whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to a first threshold; If yes, the pending encryption algorithm is determined as the encryption algorithm of the ransomware sample; The method further comprises: If not, a prompt message indicating that the decryption cannot be performed is output.

4. The method according to claim 1, characterized in that: Before determining the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file, the method further includes: Matching the ransomware sample with a plurality of common encryption algorithms; If the match is successful, the successfully matched universal encryption algorithm is determined as the encryption algorithm of the ransomware sample; If the match fails, the step of determining the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file is executed.

5. The method according to claim 4, characterized in that Before determining the successfully matched universal encryption algorithm as the encryption algorithm of the ransomware sample, the method further includes: The known plaintext file is processed by the successfully matched universal encryption algorithm to obtain a verification ciphertext file; Determine whether the similarity between the verification ciphertext file and the result ciphertext file is greater than or equal to a second threshold; If yes, then executing the step of determining the successfully matched universal encryption algorithm as the encryption algorithm of the ransomware sample; If not, the step of determining the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file is executed.

6. The method according to any one of claims 1 to 5, characterized in that The controlling the ransomware sample to decrypt the target file using the key and the decryption algorithm to obtain the original file corresponding to the target file includes: Controlling the ransomware sample to use the key and the decryption algorithm to decrypt in sequence starting from the head of the target file; Determining whether the ransomware sample has completed decryption based on the progress of the ransomware sample; If so, delete the data after the decryption completion position to obtain the original file corresponding to the target file.

7. The method according to claim 6, characterized in that The process based on the ransomware sample determines whether the ransomware sample has completed decryption, including: Determine whether the process of the ransomware sample calls the write function twice in succession, if so, determine that the ransomware sample completes decryption when the write function is called the second time of the two consecutive times, if not, determine that the ransomware sample does not complete decryption; and / or, The task execution status of the process of the ransomware sample is monitored. When the task execution is monitored to be completed for the first time, it is determined that the ransomware sample has completed decryption. When the task execution is not monitored to be completed, it is determined that the ransomware sample has not completed decryption.

8. The method according to any one of claims 1 to 5, characterized in that The suspicious seed key includes an environmental parameter of the terminal device, and the environmental parameter includes a timestamp; before controlling the ransomware sample to generate a key based on the suspicious seed key, the method further includes: Pushing the timestamp back step by step according to preset time intervals to obtain multiple time points before the timestamp; Replacing the timestamps in the environmental parameters respectively with the multiple time points to obtain multiple new environmental parameters; The step of controlling the ransomware sample to generate a key based on the suspicious seed key, and controlling the ransomware sample to decrypt the target file using the key and the decryption algorithm to obtain an original file corresponding to the target file includes: Control the ransomware sample to generate a key under each new environmental parameter, and control the ransomware sample to use each key and the decryption algorithm to decrypt the target file, thereby obtaining a plurality of candidate files; The candidate file with correct format and content is determined as the original file corresponding to the target file.

9. The method according to any one of claims 1 to 5, characterized in that Before obtaining the suspicious seed key, the method further includes: In response to detecting the start of a suspicious process in the terminal device, obtaining current environmental parameters of the terminal device; The obtaining of the suspicious seed key comprises: When the suspicious process is determined to be a blackmail process, the environmental parameter is determined as the suspicious seed key.

10. A decryption device based on a ransomware sample, characterized in that: The device comprises: An acquisition module, used for acquiring the ransom sample when it is necessary to decrypt the target file encrypted by the ransom sample, and acquiring a suspicious seed key, wherein the suspicious seed key is recorded by the ransom sample during the encryption process of the target file; An encryption module, used to process a known plaintext file through the ransomware sample to obtain a result ciphertext file; A determination module, used to determine the encryption algorithm of the ransomware sample based on the known plaintext file and the result ciphertext file; A generation module, used to generate a decryption algorithm corresponding to the encryption algorithm; A decryption module is used to control the ransomware sample to generate a key based on the suspicious seed key, and control the ransomware sample to use the key and the decryption algorithm to decrypt the target file to obtain the original file corresponding to the target file.

11. An electronic device, characterized in that: The electronic device comprises: a processor, a memory, and a bus; wherein the processor and the memory communicate with each other via the bus; and the processor is used to call program instructions in the memory to execute the method as claimed in any one of claims 1 to 9.

12. A storage medium readable by a terminal device, characterized in that: The storage medium comprises: a stored program; wherein, when the program is running, the device where the storage medium is located is controlled to execute the method as claimed in any one of claims 1 to 9.

Citation Information

Cited By

  • File decryption method and system, electronic equipment and readable storage medium

    CN122241740A