Jump to content

CryptoFortress mimics TorrentLocker but is a different ransomware


Reefa

Recommended Posts

Last week, Kafeine published a blog post about a ransomware being distributed by the Nuclear Pack exploit kit. This ransomware identify itself as “CryptoFortress”, but the ransom message and payment page both looks like an already known ransomware: TorrentLocker.

After further analysis, ESET researchers found out is the two threats are in fact very different. It appears the group behind CryptoFortress has stolen the HTML templates with its CSS. The malware code and the scheme are actually very different. Here is a table summering the similarities and differences:

2015-03-09_21-34-12_zpswvppmqkk.png

cryptofortress_ransom_page-1024x686.png

CryptoFortress ransom page

torrentlocker_ransom_page-1024x686.png

TorrentLocker ransom page

torrentlocker_vs_cryptofortress_html-102

Differences in the HTML pages

Last Friday, Renaud Tabary from Lexsi published a complete analysis of the new ransomware. ESET researchers have independently analyzed the CryptoFortress samples before Lexsi released the details. The technical details described in the article matches our findings.

ESET Telemetry also shows TorrentLocker campaign is still propagating via spam messages. Both campaign are now running in parallel.

References

CryptoFortress: Teerac.A (aka TorrentLocker) got a new identity, http://malware.dontneedcoffee.com/2015/03/cryptofortress-teeraca-aka.html

CryptoFortress, http://www.lexsi-leblog.com/cert-en/cryptofortress.html

Sample analyzed

SHA-1 sum 	ESET Detection named7085e1d96c34d6d1e3119202ab7edc95fd6f304 	Win32/Kryptik.DAPB

CryptoFortress public key

-----BEGIN PUBLIC KEY-----MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDmeXVlPGxKoOyvZgLUoyDdzPEH8D6gKlAdZVKmbv2RTjjTAcyOY/40zloPX+iJupuvwO1B/yXlsHZD8y0x/jv7v6MLjHxetmZxUjqv9gLQJE8mJBbU/h0qwc9R7LQwcMapLxvv9O6aMa3Bimjp7bP7WY/9fXgr1m/wA6Tz/kxF+wIDAQAB-----END PUBLIC KEY-----

welivesecurity

Link to comment
Share on other sites


  • Views 1.3k
  • Created
  • Last Reply

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...