Cryptanalysis of VSCrypt Ransomware and the Control Sum Cript Algorithm v1.0
[html]Introduction
I was recently sent an email by someone who was hit with a new
species of ransomware. This one encrypted all of the documents on the
system, attached the extension .vscrypt to the end, and changed the
desktop wallpaper to a ransom note written in Russian. Here are my findings…
MD5 Sum | | scope="col">Filename Magic Number | Packer | | class="c09_td" scope="col">Build Time
|---|
href="http://www.threatexpert.com/report.aspx?md5=56e78abca7acad5165b7390eaa32ca67">56e78abca7acad5165b7390eaa32ca67 href="http://www.threatexpert.com/report.aspx?md5=56e78abca7acad5165b7390eaa32ca67">56e78abca7acad5165b7390eaa32ca67 | Possible trojan.scr class="c09_td_value is-hidden-mml">Possible trojan.scr | MS-DOS executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE), OS/2 or MS Windows | class="is-visible-mml"> not detected (because I haven’t kept my database up to date) class="c09_td_value is-hidden-mml">not detected
(because I haven’t kept my database up to date) |
Fri Jun 19 15:22:17 1992 class="c09_td_value is-hidden-mml">Fri Jun 19 15:22:17 1992 |
…when executed, drops the following files onto the system: [It
pretends to be an installer for Windows Media Player 9 (English).]
MD5 Sum | | scope="col">Filename Magic Number | Packer | | class="c09_td" scope="col">Build Time
|---|
7e5f5bea9600121a41dd4619abf70029 class="c09_td_value is-hidden-mml">7e5f5bea9600121a41dd4619abf70029 | /Program Files/Flash Media Arts,inc/SWF Video/23854356.avi class="c09_td_value is-hidden-mml">/Program Files/Flash Media Arts,inc/SWF Video/23854356.avi | | class="c09_td"> MS-DOS
executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
OS/2 or MS Windows class="is-visible-mml"> Microsoft Visual C++ v7.0 class="c09_td_value is-hidden-mml">Microsoft Visual C++ v7.0 | Tue Nov 20 16:59:32 2007 class="c09_td_value is-hidden-mml">Tue Nov 20 16:59:32 2007 |
href="http://www.threatexpert.com/report.aspx?md5=010d7b79d002d747f420a7880f89ee38">010d7b79d002d747f420a7880f89ee38 href="http://www.threatexpert.com/report.aspx?md5=010d7b79d002d747f420a7880f89ee38">010d7b79d002d747f420a7880f89ee38 | /Program Files/Flash Media Arts,inc/SWF Video/Free_update.exe class="c09_td_value is-hidden-mml">/Program Files/Flash Media Arts,inc/SWF Video/Free_update.exe | | class="c09_td"> MS-DOS
executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
OS/2 or MS Windows class="is-visible-mml"> Microsoft Visual Basic v5.0/v6. class="c09_td_value is-hidden-mml">Microsoft Visual Basic v5.0/v6. | class="is-visible-mml"> Tue May 12 04:03:40 2009 Tue May 12 04:03:40 2009 |
aa74d413fcc98fef29ba9bd75f894093 class="c09_td_value is-hidden-mml">aa74d413fcc98fef29ba9bd75f894093 | /Program Files/Flash Media Arts,inc/SWF Video/Uninstall.exe class="c09_td_value is-hidden-mml">/Program Files/Flash Media Arts,inc/SWF Video/Uninstall.exe | | class="c09_td"> MS-DOS
executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
OS/2 or MS Windows class="is-visible-mml"> not detected, but packed anyway class="c09_td_value is-hidden-mml">not detected, but packed anyway | class="is-visible-mml"> Fri Jun 19 15:22:17 1992 Fri Jun 19 15:22:17 1992 |
031fc32cd1b5bde5b1efa1d148815000 class="c09_td_value is-hidden-mml">031fc32cd1b5bde5b1efa1d148815000 | /Program Files/Flash Media Arts,inc/SWF Video/Uninstall.ini class="c09_td_value is-hidden-mml">/Program Files/Flash Media Arts,inc/SWF Video/Uninstall.ini | | class="c09_td"> ISO-8859
text, with CRLF line terminators class="c09_td_value is-hidden-mml">ISO-8859 text, with CRLF
line terminators class="is-visible-mml"> N/A class="c09_td_value is-hidden-mml">N/A | | class="c09_td">
N/A class="c09_td_value is-hidden-mml">N/A
href="http://www.threatexpert.com/report.aspx?md5=d3583ac12d068e231c0b1e62c2a7eb49">d3583ac12d068e231c0b1e62c2a7eb49 href="http://www.threatexpert.com/report.aspx?md5=d3583ac12d068e231c0b1e62c2a7eb49">d3583ac12d068e231c0b1e62c2a7eb49 | /Program Files/Flash Media Arts,inc/SWF Video/Video_codec.exe class="c09_td_value is-hidden-mml">/Program Files/Flash Media Arts,inc/SWF Video/Video_codec.exe | | class="c09_td"> MS-DOS
executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
OS/2 or MS Windows class="is-visible-mml"> Microsoft Visual Basic v5.0/v6.0 class="c09_td_value is-hidden-mml">Microsoft Visual Basic v5.0/v6.0 | class="is-visible-mml"> Tue May 12 04:03:40 2009 Tue May 12 04:03:40 2009 |
href="http://www.threatexpert.com/report.aspx?md5=5f9927ee59b4881a2ce8634332f63fa8">5f9927ee59b4881a2ce8634332f63fa8 href="http://www.threatexpert.com/report.aspx?md5=5f9927ee59b4881a2ce8634332f63fa8">5f9927ee59b4881a2ce8634332f63fa8 | /Program Files/Flash Media Arts,inc/SWF Video/svchost.exe class="c09_td_value is-hidden-mml">/Program Files/Flash Media Arts,inc/SWF Video/svchost.exe | | class="c09_td"> MS-DOS
executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
OS/2 or MS Windows class="is-visible-mml"> Microsoft Visual Basic v5.0/v6.0 class="c09_td_value is-hidden-mml">Microsoft Visual Basic v5.0/v6.0 | class="is-visible-mml"> Tue May 12 04:03:40 2009 Tue May 12 04:03:40 2009 |
It immediately executes Video_codec.exe and svchost.exe. svchost.exe
and CSCA1.DLL were written in Delphi. These files all use the same
packer written in Visual Basic 6 of all things. The packer uses
Blowfish, and has a giant blob of a Base64 encoded EXE file embedded
in it which it drops to disk, and then that
does something else, and blah blah blah, I got around it on the
first try. Whomever compiled this packer, appears to have a German
Locale, based upon paths like: C:\Programme\Microsoft Visual
Studio\VB98\VB6.OLB (Free_update.exe is a keylogger by the way.) The
VSCrypt ransomware is svchost.exe in this case. And these are the
files it drops when executed:
MD5 Sum | | scope="col">Filename Magic Number | Packer | | class="c09_td" scope="col">Build Time
|---|
b817a4c8ca2479be0ea7e5dab1cb4432 class="c09_td_value is-hidden-mml">b817a4c8ca2479be0ea7e5dab1cb4432 | /vsworkdir/CSCA1.DLL class="c09_td_value is-hidden-mml">/vsworkdir/CSCA1.DLL | MS-DOS executable (EXE), OS/2 or MS Windows class="c09_td_value is-hidden-mml">MS-DOS executable (EXE), OS/2 or MS Windows | class="is-visible-mml"> not detected (because I haven’t kept my database up to date) class="c09_td_value is-hidden-mml">not detected
(because I haven’t kept my database up to date) |
Fri Jun 19 15:22:17 1992 class="c09_td_value is-hidden-mml">Fri Jun 19 15:22:17 1992 |
80e1d714045a4402e3992a195f7e7a08 class="c09_td_value is-hidden-mml">80e1d714045a4402e3992a195f7e7a08 | /vsworkdir/shantazh.jpg class="c09_td_value is-hidden-mml">/vsworkdir/shantazh.jpg | JPEG image data, JFIF standard 1.00, comment: “LEAD Technologies Inc. V1.01″ class="c09_td_value is-hidden-mml">JPEG image data, JFIF standard 1.00, comment: “LEAD Technologies Inc. V1.01″ | N/A class="c09_td_value is-hidden-mml">N/A | | class="c09_td">
N/A class="c09_td_value is-hidden-mml">N/A
So what does it do?
VSCrypt (svchost.exe) searches each directory on the
system, for the following files:
*.pdf
*.jpg
*.rar
*.zip
*.txt
*.xls
*.rtf
*.jpeg
*.html
*.htm
*.php
*.eml
*.3gp
*.7z
For each file like this it finds, it encrypts it using the Control
Sum Cript Algorithm v1.0 (CSCA1.DLL) with the password
Fantazma1518061DgFgvFdvHyfvFdWwlm876Ql, more on this below. Adds a
.vscrypt to the end of the filename, and deletes the
original. At the end of this process, it drops
shantazh.jpg and sets [HKEY_CURRENT_USER\Control
Panel\Desktop] ConvertedWallpaper =
"C:\vsworkdir\shantazh.jpg" in the registry — setting
the desktop background to the «шантаж» or blackmail note.
All your files are belong to us.
I went through the effort of typing this in while translating, so
here is the text of the message in the shantazh.jpg file.
I don't speak Russian very well, so please forgive me if I made any typos.
Привет я Trojan encoder точнее одна из его разновидностей
::) мой автор человек с ником КО