DeadBolt ransomware: nothing but NASty
Key conclusions:
Analysis of DeadBolt ransomware
DeadBolt ransom message embedded in the web interface of the NAS device
DeadBolt ransom message addressed to QNAP, the vendor of the NAS device
Description of the process of receiving the decryption key
The code of the function main of the DeadBolt ransomware
Encryption
Core structures of DeadBolt
Initial fragment of the DeadBolt encryption mode function
Final fragment of the DeadBolt encryption mode function
Fragment of the shell script template /home/httpd/index.html contained in the body of DeadBolt
Fragment of the shell script template /home/httpd/index.html contained in the body of DeadBolt
Extraction function /mnt/HDA_ROOT/update_pkg/SDDPd.bin
Shell script template /mnt/HDA_ROOT/update_pkg/SDDPd.bin contained in the body of DeadBolt
File encryption
Contents of !!!_IMPORTANT_README_WHERE_ARE_MY_FILES_!!!.txt
Fragment of the DeadBolt file's encryption function
End fragment of the file encryption function
Configuration
Decryption
Decryption mode function
Fragment of the file decryption function
Fragment of the file decryption function
DeadBolt's self-delete function
Additional information
Conclusion
Recommendations for companies
Recommendations for setting up an NAS device:
If you found this article helpful, share it with your friends!