13/10/2015
15:07

New variant Trojan.Win32.CryptoFF.B that encrypts document file.


This variant of ransomware encrypts all documents and rename their with extension ".33t", asking a ransom to unlock.
On October 9th, 2015, a new variant of ransomware crypto-malware Trojan.Win32.CryptoFF.A was discovered.
This new variant is called Trojan.Win32.CryptoFF.B  and is very similar to Trojan.Win32.CryptoFF.A.

The file analyzed "7C55.tmp" was found in the temporary folder of a computer hit by Trojan.Win32.CryptoFF.B
We don't have any more information as this malware spreads.


File name: 7C55.tmp
MD5: cee2402cdab199e8cf0614fa26fae2e4
Size: 198911 byte
Time Stamp (header): 08/10/2015 - 23.27.48

When running the Trojan.Win32.CryptoFF.B,  it creates a temporary file in: %temp%\83sa9Pd.txt
And then immediately starts to encrypt the files.

When it finds the first victim, it will do the following things:

1) open the document
2) encrypt the document
3) rename the original file with extension ".33t" (e.g.  mydocument.doc -> mydocument.doc.33t)

In each folder it will create 2 files:
secret.key (size: 1368 byte)
VIRUSHELLO!!!.txt (size: 537 byte)

The file "secret.key" contains a key in UUencode, after it's decoded, it will obtain a key of 1024 byte.
The file "VIRUSHELLO!!!.txt" contains instructions to recover the file encrypted:

hi. if you want to get your files back, email me:

fatvirginboy@inbox.lv

if that email gets blocked or you get no reply, contact me using this more reliable way:

go to http://bitmessage.org/, download and run Bitmessage.
Click ‘Your Identities’ tab, then click ‘New’, then click ‘OK’.
Then click ‘Send’ tab.

TO: BM-2cUKkir7WzC1WoZCtZJpzzHqNuQ9aW31Gk
SUBJECT: name of your PC.
MESSAGE:  Hi, I want my files back.

Click ‘Send’ button. It takes time to send and get messages though, so keep the program running.


The Trojan.Win32.CryptoFF.B removes the volume shadow copies with this command:
cmd.exe /Q /C vssadmin.exe delete shadows /all /quiet

And it uses low-level cryptographic primitives of library Opensource CRYPTOGAMS by <appro@openssl.org>.

The Trojan.Win32.CryptoFF.B encrypts the first 16 bytes of files with the following extensions:
.001 .3d .3ds .3dxml .3fr .3mf .4db .7z .abf .accdb .accde .ace .adp .aec .ai .apk .app .arc .arch00 .arj .arw .ase .asm .asp .aspx .asse .avi .bad  .bak .bar .bay .bc6 .bc7 .bfs .big .bik .bin .bkf .bkp .blob .bmp .box .bpw .bsa .bsc .bson .btq .bzip2 .c .c2d .cad .cals .cam .cap .cas .cbl .cc .ccs  .cdf .cdi .cdr .cer .cfg .cfr .cgi .cif .class .cls .cmd .cnf .com .conf .cpp .cpt .cr2 .crt .crw .cs .css .csv .ctl .cxx .d3dbsp .das .dat .data  .DayZProfile .dazip .db .db0 .db2 .dba .dbf .dbfv .dbk .dcr .ddi .der .desc .dff .dib .djvu .dmg .dmp .dms .dng .doc .docm .docx .dos .dsk .dts .dwf .dwg  .dxf .dxg .ear .efs .egg .el .emf .eml .epk .eps .erf .esm .exif .exp .fcp .fdb .fds .fdx .ff .file .fla .flp .flv .fm .fmb .fmt .fmx .for .forge .fos .fp  .fpk .frm .frm .frx .fs .fsdb .fsh .ftn .gdb .gho .ghs .gif .go .gpl .group .grp .gxk .gz .gzip .h5 .hdd .hkdb .hkx .hplg .hpp .hvpl .hxx .iam .ibank .ibd  .ibdata .icxs .idb .idw .ifc .image .img .inc .indd .ipa .iso .itdb .itl .itm .iwd .iwi .jag .jar .java .jfif .jng .jp2 .jpe .jpeg .jpg .js .jsfl .json  .jsonb .jst .kdb .kdc .kexi .key .kf .layout .lbf .ldb .ldf .lgt .lisp .litemod .log .lrf .lst .ltx .lua .lvl .lz .lzh .m2 .m3u .m4a .m4v .map .max .mcgame  .mcmeta .mcw .md .mdb .mdbackup .mddata .mde .mdf .mef .menu .mkv .ml .mlx .mov .mp2 .mp3 .mp4 .mpc .mpeg .mpg .mpp .mpqge .mrwref  .msg .mts .myd .myi .myo  .ncf .ndf .npc .nrg .nrw .nsf .ntl .nu3 .nv2 .nvram .odb .odc .odm .odp .ods .odt .ofx .ora .orf .ori .ost .p12 .p7b .p7c .pac .pak .pck .pct .pcxm .pdb .pdd  .pdf .pdi .pef .pem .pfx .php .php3 .php4 .php5 .phps .phtml .pict .pkb .pkpass .pks .pl .plb .pls .pm .png .pp .ppk .pps .ppt .pptm .pptx .pqb .psb .psd  .psk .pst .ptb .ptx .pub .py .pyc .pyo .qbb .qbw .qdb .qdf .qfx .qic .qif .r3d .raf .rar .raw .rb .rc .rdb .rdf .rdo .re4 .rec .rep .rex .rgss3a .rim .rofl  .rtf .rw2 .rwl .sap .sapdata .sav .sb .sc2save .sdb .sdf .sdi .sea .shf .shtml .sid .sidd .sidn .sie .sis .sit .sitx .skf .slm .sln .smd .snp .snx .sql  .sqlite .sr2 .srf .srw .ssh .ssi .sum .svg .syncdb .t12 .t13 .tab .tar .tax .tc .tcl .text .tgz .tib .tor .txt .u3d .uha .unity3d .upk .vb .vbg .vbk .vbm  .vbox .vbp .vbs .vbx .vcd .vdf .vdi .vfs0 .vhd .vip .vmc .vmdk .vmem .vmsd .vmsn .vmss .vmtm .vmx .vmxf .vpk .vpp_pc .vrb .vst .vsv .vtf .w3x .war .wb2  .wbcat .wma .wmo .wmv .wotreplay .wpd .wps .x3f .xdf .xf .xht .xlk .xls .xlsb .xlsm .xlsx .xml .xps .xxx .zip


Clean:
VirIT version 8.0.24 and later.


Analysis by eng. Gianfranco Tonello
C.R.A.M. (Anti-Malware Research Center)
by TG Soft


Any information published on our site may be used and published on other websites, blogs, forums, facebook and/or in any other form both in paper and electronic form as long as the source is always and in any case cited explicitly “Source: CRAM by TG Soft www.tgsoft.it” with a clickable link to the original information and / or web page from which textual content, ideas and / or images have been extrapolated.
It will be appreciated in case of use of the information of C.R.A.M. by TG Soft www.tgsoft.it in the report of summary articles the following acknowledgment/thanks “Thanks to Anti-Malware Research Center C.R.A.M. by TG Soft of which we point out the direct link to the original information: [direct clickable link]”

Vir.IT eXplorer PRO is certified by the biggest international organisation: