4 ms·
> “The challenge was that they delete the [public key] once the files are fully encrypted. Memory analysis gave us about a 5-minute window after files were encr
by rob-olmos 4y ago
> “The challenge was that they delete the [public key] once the files are fully encrypted. Memory analysis gave us about a 5-minute window after files were encrypted to retrieve this public key.”
> Unit 221B ultimately built a “Live CD” version of Linux that victims could run on infected systems to extract that RSA-512 key.
I'm guessing most didn't make it within the 5-min window, so the Live CD would recover the "deleted" record from the Windows Registry database?
- system2 4y agoI am puzzled by the statement too. Live CD means restarting the host and boot it with that CD then retrieve whatever. I doubt that CD is sitting next to people got encrypted when it happens.
- jsmith99 4y agoPresumably it means you need to turn the computer off within 5m of the encryption occuring and don't turn it on again till you boot the live cd?
- splonk 4y agoThe more technical writeup [0] linked at the bottom of the article doesn't specifically mention it, but it sounds like they probably booted off the Live CD to get access to the registry. > You can’t analyze the registry live on a windows machine because it locks the NTUSER.dat files by the process id (PID) 104 known as Registry.exe. Any useful registry information will be found in that process, and we recommend getting a memory and VAD dump of the Registry.exe process as soon as possible. You can do this quite easily with the REKALL tool, which can perform live and dead memory analysis on Windows machines. [0]: https://blog.unit221b.com/dont-read-this-blog/0xdead-zeppelin https://blog.unit221b.com/dont-read-this-blog/0xdead-zeppeli...
- Someone 4y agoReading between the lines, I get the impression the key is deleted from the registry, but not explicitly erased, allowing recovery if the disk space isn’t reused yet. “Since Zeppelin deletes the registry key store, we will have to extract unallocated cells from the registry to recover the Public Key section. […] We have had 100% success carving the public key from NTUser.dat for live Zeppelin samples in the field”
- yieldcrv 4y agoor maybe they could add a machine to the network to get encrypted and then get the key from that one
- rocqua 4y agoThis is covered by the write-up of unit 221 [1], also linked by splink it turns out the registry key that was deleted can be recovered. Much like you can recover deleted files from a file-system, you can recover deleted keys from a windows registry. In the words of the blog[1]: Since Zeppelin deletes the registry key store, we will have to extract unallocated cells from the registry to recover the Public Key section. We use a combination of code and existing tools such as yarp and regipy to carve registry information from the hard drive, memory, registry backup, and transaction files. We also need to recover the deleted data. The most successful process used yarp-carve and yarp-print with the -deleted flag against NTUSER.DAT files, which are compressed. [1] https://blog.unit221b.com/dont-read-this-blog/0xdead-zeppelin https://blog.unit221b.com/dont-read-this-blog/0xdead-zeppeli...