CryptoFortress mimics TorrentLocker but is a different ransomware

CryptoFortress mimics TorrentLocker but is a different ransomware

ESET assess the differences between CryptoFortress and TorrentLocker: two very different strains of ransomware.

Last week, Kafeine published a blog post about a ransomware being distributed by the Nuclear Pack exploit kit. This ransomware identify itself as “CryptoFortress”, but the ransom message and payment page both looks like an already known ransomware: TorrentLocker.

After further analysis, ESET researchers found out is the two threats are in fact very different. It appears the group behind CryptoFortress has stolen the HTML templates with its CSS. The malware code and the scheme are actually very different. Here is a table summering the similarities and differences:

 TorrentLockerCryptoFortress
PropagationSpamExploit kit
File encryptionAES-256 CBCAES-256 ECB
Hardcoded C&C serverYesNo
Ransom page locationFetched from C&C serverIncluded in malware
Payment page locationOnion-routed (but same server as the hardcoded C&C)Onion-routed
AES key encryptionRSA-1024RSA-1024
Cryptographic libraryLibTomCryptMicrosoft CryptoAPI
Encrypted portion of files2 Mb at beginning of fileFirst 50% of the file, up to 5 Mb
PaymentBitcoin (variable amount)1.0 Bitcoin

 

CryptoFortress ransom page

CryptoFortress ransom page

TorrentLocker ransom page

TorrentLocker ransom page

Differences in the HTML pages

Differences in the HTML pages

Last Friday, Renaud Tabary from Lexsi published a complete analysis of the new ransomware. ESET researchers have independently analyzed the CryptoFortress samples before Lexsi released the details. The technical details described in the article matches our findings.

ESET Telemetry also shows TorrentLocker campaign is still propagating via spam messages. Both campaign are now running in parallel.

References

CryptoFortress: Teerac.A (aka TorrentLocker) got a new identity, http://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html

CryptoFortress, http://www.lexsi-leblog.com/cert-en/cryptofortress.html

Sample analyzed

CryptoFortress public key

-----BEGIN PUBLIC KEY-----
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDmeXVlPGxKoOyvZgLUoyDdzPEH
8D6gKlAdZVKmbv2RTjjTAcyOY/40zloPX+iJupuvwO1B/yXlsHZD8y0x/jv7v6ML
jHxetmZxUjqv9gLQJE8mJBbU/h0qwc9R7LQwcMapLxvv9O6aMa3Bimjp7bP7WY/9
fXgr1m/wA6Tz/kxF+wIDAQAB
-----END PUBLIC KEY-----

 




Source link