Clicky

Pages

Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Saturday, September 7, 2024

2024-08-30 Cicada ESXi Ransomware Sample

 



Cicada3301, a ransomware group first detected in June 2024, appears to be either a rebranded or derivative version of the ALPHV ransomware group, employing a ransomware-as-a-service (RaaS) model. The ransomware, written in Rust, targets both Windows and Linux/ESXi environments, utilizing ChaCha20 for encryption. Technical analysis reveals several key similarities with ALPHV: both use nearly identical command structures for shutting down VMs and removing snapshots, and share a similar file-naming convention. The ransomware's binary is an ELF file, with its Rust origin confirmed through string references and investigation of the .comment section.

Key parameters include sleep, which delays the ransomware's execution, and ui, which displays the encryption progress on the screen. The key parameter is crucial for decryption; if it's not provided or incorrect, the ransomware will stop running. The main function, linux_enc, starts the encryption process by generating a random key using OsRng. Files larger than 100 MB are encrypted in parts, while smaller files are encrypted entirely using ChaCha20. The ChaCha20 key is then secured with an RSA public key and added, along with a specific file extension, to the end of the encrypted file.

Initial access appears to be facilitated by the Brutus botnet, with threat actors using stolen or brute-forced credentials to gain entry via ScreenConnect. The IP address associated with this attack is tied to the Brutus botnet, raising the possibility of a direct connection between the botnet operators and Cicada3301. The ransomware also features a decryption check routine, where an encoded and encrypted ransomware note stored within the binary is decrypted using the provided key, validating the correct decryption.


Download


Download. (Email me if you need the password scheme)



File Information

63e0d4e861048f581c9e5c64b28a053eb0023d58eebf2b943868d5f68a67a8b7 esxi

The article didn't include any hashes, only the YARA rule. While this sample doesn't trigger a match with the rule, I believe it's the same malware

Monday, September 2, 2024

2024-08-29 UNDERGROUND Ransomware Samples





The Underground ransomware is likely spread by the RomCom group (also known as Storm-0978). The group exploits the Microsoft Office and Windows HTML RCE vulnerability (CVE-2023-36884). Other methods, such as phishing emails and access via Initial Access Brokers (IABs), may also be used.

    • Shadow Copies Deletion: It removes all shadow copies to prevent file recovery:
    • bash
    • Copy code
    • vssadmin.exe delete shadows /all /quiet
    • RDP Session Limits: Sets a 14-day limit on Remote Desktop sessions to maintain persistence:
    • bash
    • Copy code
    • reg.exe add HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services / v MaxDisconnectionTime / t REG_DWORD / d 1209600000 / f
    • SQL Server Service Stop: Halts the MS SQL Server service to disrupt operations:
    • bash
    • Copy code
    • net.exe stop MSSQLSERVER /f /m
    • Ransom Note Deployment: Drops a ransom note named “!!readme!!!.txt” in directories containing encrypted files.
  • File Encryption: The ransomware encrypts files without altering their extensions, making it harder to visually identify encrypted files. It avoids encrypting critical system files (e.g., .sys, .exe, .dll) to maintain system functionality.
  • Log and File Deletion: It creates and runs a script (temp.cmd) to delete the original ransomware file and clear Windows Event logs, complicating forensic analysis.
  • Data Leak Site: The ransomware group maintains a site where they post stolen data from their victims, spanning industries such as construction, pharmaceuticals, and manufacturing. As of July 2024, they have listed 16 victims.
  • Telegram Channel: The group also uses a Telegram channel to distribute stolen data, with links to files hosted on Mega, a cloud storage service.


Download

Monday, May 24, 2010

Malware - Blackmailer - Ransomware (warning NSFW)

Malware - Blackmailer - Ransomware (warning NSFW)
Original location hxxp://hotblondy.ru/video-loaderv2.exe
 File b4ac31487f8874a20b05f7c31eba9ca6 received on 2010.04.22 05:19:43 (UTC)
Result: 29/40 (72.50%)
Antivirus     Version     Last Update     Result
a-squared     4.5.0.50     2010.04.22     Trojan.Win32.Inject!IK
AntiVir     7.10.6.169     2010.04.21     TR/Inject.alte
Avast     4.8.1351.0     2010.04.21     Win32:Malware-gen
Avast5     5.0.332.0     2010.04.21     Win32:Malware-gen
AVG     9.0.0.787     2010.04.21     Generic15.CGKN
BitDefender     7.2     2010.04.22     Trojan.Generic.3068304
CAT-QuickHeal     10.00     2010.04.22     Trojan.Inject.aknv
Comodo     4663     2010.04.22     UnclassifiedMalware
DrWeb     5.0.2.03300     2010.04.22     Trojan.Blackmailer.1555
F-Secure     9.0.15370.0     2010.04.22     Trojan.Generic.3068304
Fortinet     4.0.14.0     2010.04.21     Malware_fam.A
GData     21     2010.04.22     Trojan.Generic.3068304
Ikarus     T3.1.1.80.0     2010.04.22     Trojan.Win32.Inject
Jiangmin     13.0.900     2010.04.20     Trojan/Inject.icg
Kaspersky     7.0.0.125     2010.04.22     Trojan.Win32.Inject.alte
McAfee     5.400.0.1158     2010.04.22     Generic.dx!hvk
McAfee-GW-Edition     6.8.5     2010.04.22     Heuristic.LooksLike.Win32.SuspiciousPE.C
Microsoft     1.5703     2010.04.21     Trojan:Win32/Trufip!rts
NOD32     5048     2010.04.21     a variant of Win32/LockScreen.FF
Norman     6.04.11     2010.04.21     W32/Inject.UIN
nProtect     2010-04-21.01     2010.04.21     Trojan/W32.Inject.367616
Panda     10.0.2.7     2010.04.21     Trj/CI.A
PCTools     7.0.3.5     2010.04.22     Trojan.Generic
Prevx     3.0     2010.04.22     Medium Risk Malware
Sophos     4.53.0     2010.04.22     Mal/Generic-A
Sunbelt     6206     2010.04.22     Trojan.Win32.Generic!SB.0
Symantec     20091.2.0.41     2010.04.22     Trojan Horse
VBA32     3.12.12.4     2010.04.19     Trojan.Win32.Inject.amif
VirusBuster     5.0.27.0     2010.04.21     Trojan.Delf.EBNJ
Additional information
File size: 367616 bytes
MD5   : b4ac31487f8874a20b05f7c31eba9ca6