Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le mai 15, 2019, 00:00:21

Titre: [FireEye]Cryptanalysis of VSCrypt Ransomware and the Control Sum Cript Algorithm v1.0
Posté par: igor51 le mai 15, 2019, 00:00:21
Cryptanalysis of VSCrypt Ransomware and the Control Sum Cript Algorithm v1.0

[html]

Introduction


 

I was recently sent an email by someone who was hit with a new
  species of ransomware. This one encrypted all of the documents on the
  system, attached the extension .vscrypt to the end, and changed the
  desktop wallpaper to a ransom note written in Russian. Here are my findings…


 
   
              class="c09_td" scope="col">Build Time
   
     
       
MD5 Sum       scope="col">Filename Magic
      Number
Packer

                    href="http://www.threatexpert.com/report.aspx?md5=56e78abca7acad5165b7390eaa32ca67">56e78abca7acad5165b7390eaa32ca67

         
                    href="http://www.threatexpert.com/report.aspx?md5=56e78abca7acad5165b7390eaa32ca67">56e78abca7acad5165b7390eaa32ca67
     

            Possible trojan.scr
          class="c09_td_value is-hidden-mml">Possible trojan.scr
     

            MS-DOS executable (EXE), OS/2 or MS
        Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows
          class="is-visible-mml"> not detected
  (because I
            haven’t kept my database up to date)
          class="c09_td_value is-hidden-mml">not detected

          (because I haven’t kept my database up to date)
Fri Jun
            19 15:22:17 1992
          class="c09_td_value is-hidden-mml">Fri Jun 19 15:22:17
      1992

 

…when executed, drops the following files onto the system: [It
  pretends to be an installer for Windows Media Player 9 (English).]


 
   
              class="c09_td" scope="col">Build Time
   
                class="c09_td"> MS-DOS
            executable (EXE), OS/2 or MS Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows

   
                class="c09_td"> MS-DOS
            executable (EXE), OS/2 or MS Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows

   
                class="c09_td"> MS-DOS
            executable (EXE), OS/2 or MS Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows

   
                class="c09_td"> ISO-8859
            text, with CRLF line terminators
          class="c09_td_value is-hidden-mml">ISO-8859 text, with CRLF
          line terminators
          class="c09_td">
        N/A
          class="c09_td_value is-hidden-mml">N/A

   
                class="c09_td"> MS-DOS
            executable (EXE), OS/2 or MS Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows

   
                class="c09_td"> MS-DOS
            executable (EXE), OS/2 or MS Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows
MD5 Sum       scope="col">Filename Magic
      Number
Packer

        7e5f5bea9600121a41dd4619abf70029
          class="c09_td_value is-hidden-mml">7e5f5bea9600121a41dd4619abf70029
     

            /Program Files/Flash Media Arts,inc/SWF
        Video/23854356.avi
          class="c09_td_value is-hidden-mml">/Program Files/Flash Media
          Arts,inc/SWF Video/23854356.avi
          class="is-visible-mml"> Microsoft Visual C++
        v7.0
          class="c09_td_value is-hidden-mml">Microsoft Visual C++ v7.0
     

            Tue Nov 20 16:59:32 2007
          class="c09_td_value is-hidden-mml">Tue Nov 20 16:59:32 2007
     

                    href="http://www.threatexpert.com/report.aspx?md5=010d7b79d002d747f420a7880f89ee38">010d7b79d002d747f420a7880f89ee38

         
                    href="http://www.threatexpert.com/report.aspx?md5=010d7b79d002d747f420a7880f89ee38">010d7b79d002d747f420a7880f89ee38
     

            /Program Files/Flash Media Arts,inc/SWF
        Video/Free_update.exe
          class="c09_td_value is-hidden-mml">/Program Files/Flash Media
          Arts,inc/SWF Video/Free_update.exe
          class="is-visible-mml"> Microsoft Visual Basic
        v5.0/v6.
          class="c09_td_value is-hidden-mml">Microsoft Visual Basic
          v5.0/v6.
          class="is-visible-mml"> Tue May 12 04:03:40
        2009
Tue
          May 12 04:03:40 2009

        aa74d413fcc98fef29ba9bd75f894093
          class="c09_td_value is-hidden-mml">aa74d413fcc98fef29ba9bd75f894093
     

            /Program Files/Flash Media Arts,inc/SWF
        Video/Uninstall.exe
          class="c09_td_value is-hidden-mml">/Program Files/Flash Media
          Arts,inc/SWF Video/Uninstall.exe
          class="is-visible-mml"> not detected, but packed
        anyway
          class="c09_td_value is-hidden-mml">not detected, but packed
          anyway
          class="is-visible-mml"> Fri Jun 19 15:22:17
        1992
Fri
          Jun 19 15:22:17 1992

        031fc32cd1b5bde5b1efa1d148815000
          class="c09_td_value is-hidden-mml">031fc32cd1b5bde5b1efa1d148815000
     

            /Program Files/Flash Media Arts,inc/SWF
        Video/Uninstall.ini
          class="c09_td_value is-hidden-mml">/Program Files/Flash Media
          Arts,inc/SWF Video/Uninstall.ini
          class="is-visible-mml"> N/A           class="c09_td_value is-hidden-mml">N/A

                    href="http://www.threatexpert.com/report.aspx?md5=d3583ac12d068e231c0b1e62c2a7eb49">d3583ac12d068e231c0b1e62c2a7eb49

         
                    href="http://www.threatexpert.com/report.aspx?md5=d3583ac12d068e231c0b1e62c2a7eb49">d3583ac12d068e231c0b1e62c2a7eb49
     

            /Program Files/Flash Media Arts,inc/SWF
        Video/Video_codec.exe
          class="c09_td_value is-hidden-mml">/Program Files/Flash Media
          Arts,inc/SWF Video/Video_codec.exe
          class="is-visible-mml"> Microsoft Visual Basic
        v5.0/v6.0
          class="c09_td_value is-hidden-mml">Microsoft Visual Basic
          v5.0/v6.0
          class="is-visible-mml"> Tue May 12 04:03:40
        2009
Tue
          May 12 04:03:40 2009

                    href="http://www.threatexpert.com/report.aspx?md5=5f9927ee59b4881a2ce8634332f63fa8">5f9927ee59b4881a2ce8634332f63fa8

         
                    href="http://www.threatexpert.com/report.aspx?md5=5f9927ee59b4881a2ce8634332f63fa8">5f9927ee59b4881a2ce8634332f63fa8
     

            /Program Files/Flash Media Arts,inc/SWF
        Video/svchost.exe
          class="c09_td_value is-hidden-mml">/Program Files/Flash Media
          Arts,inc/SWF Video/svchost.exe
          class="is-visible-mml"> Microsoft Visual Basic
        v5.0/v6.0
          class="c09_td_value is-hidden-mml">Microsoft Visual Basic
          v5.0/v6.0
          class="is-visible-mml"> Tue May 12 04:03:40
        2009
Tue
          May 12 04:03:40 2009

 

It immediately executes Video_codec.exe and svchost.exe. svchost.exe
  and CSCA1.DLL were written in Delphi. These files all use the same
  packer written in Visual Basic 6 of all things. The packer uses
  Blowfish, and has a giant blob of a Base64 encoded EXE file embedded
  in it which it drops to disk, and then that


 

does something else, and blah blah blah, I got around it on the
  first try. Whomever compiled this packer, appears to have a German
  Locale, based upon paths like: C:\Programme\Microsoft Visual
  Studio\VB98\VB6.OLB (Free_update.exe is a keylogger by the way.) The
  VSCrypt ransomware is svchost.exe in this case. And these are the
  files it drops when executed:


 
   
              class="c09_td" scope="col">Build Time
   
     
       
   
                class="c09_td">
        N/A
      class="c09_td_value is-hidden-mml">N/A
MD5 Sum       scope="col">Filename Magic
      Number
Packer

        b817a4c8ca2479be0ea7e5dab1cb4432
          class="c09_td_value is-hidden-mml">b817a4c8ca2479be0ea7e5dab1cb4432
     

        /vsworkdir/CSCA1.DLL
          class="c09_td_value is-hidden-mml">/vsworkdir/CSCA1.DLL
     

            MS-DOS executable (EXE), OS/2 or MS
        Windows
          class="c09_td_value is-hidden-mml">MS-DOS executable (EXE),
          OS/2 or MS Windows
          class="is-visible-mml"> not detected
  (because I
            haven’t kept my database up to date)
          class="c09_td_value is-hidden-mml">not detected

          (because I haven’t kept my database up to date)
Fri Jun
            19 15:22:17 1992
          class="c09_td_value is-hidden-mml">Fri Jun 19 15:22:17 1992
     

        80e1d714045a4402e3992a195f7e7a08
          class="c09_td_value is-hidden-mml">80e1d714045a4402e3992a195f7e7a08
     

        /vsworkdir/shantazh.jpg
          class="c09_td_value is-hidden-mml">/vsworkdir/shantazh.jpg
     

            JPEG image data, JFIF standard 1.00, comment: “LEAD
            Technologies Inc. V1.01″
          class="c09_td_value is-hidden-mml">JPEG image data, JFIF
          standard 1.00, comment: “LEAD Technologies Inc. V1.01″
     

        N/A
          class="c09_td_value is-hidden-mml">N/A

 

So what does it do?


 

VSCrypt (svchost.exe) searches each directory on the
  system, for the following files:


 


 

*.pdf

*.jpg




*.rar




*.zip




*.txt




*.xls




*.rtf




*.jpeg




*.html




*.htm




*.php




*.eml




*.3gp




*.7z








 

For each file like this it finds, it encrypts it using the Control
  Sum Cript Algorithm v1.0 (CSCA1.DLL) with the password
  Fantazma1518061DgFgvFdvHyfvFdWwlm876Ql, more on this below. Adds a
  .vscrypt to the end of the filename, and deletes the
  original. At the end of this process, it drops
  shantazh.jpg and sets [HKEY_CURRENT_USER\Control
    Panel\Desktop] ConvertedWallpaper =
  "C:\vsworkdir\shantazh.jpg"
in the registry — setting
  the desktop background to the «шантаж» or blackmail note.


 

All your files are belong to us.


 

I went through the effort of typing this in while translating, so
  here is the text of the message in the shantazh.jpg file.
  I don't speak Russian very well, so please forgive me if I made any typos.


 
Привет я Trojan encoder точнее одна из его разновидностей
  ::) мой автор человек с ником КО