Home / malwarePDF  

Ransom:Win32/Criakl.C


First posted on 31 December 2014.
Source: Microsoft

Aliases :

There are no other names known for Ransom:Win32/Criakl.C.

Explanation :

Threat behavior

Installation

We have seen this threat use the file name winrar.exe, likely to make you think it is a legitimate app.

This threat drops a copy of itself in the following directory:

  • %ProgramFiles% /temp/


It also drops the following files:

  • d.bat
  • temp .tmp - this file contains the infection ID number as mentioned in the ransomware message
  • destop.bmp - the ransomware message that is shown on your desktop


Payload

Encrypts your files

The threat might encrypt the following files types on your PC's hard drives:

  • .doc
  • .docx
  • .jpg
  • .txt
  • .xml
  • .zip


It renames your files by adding the following string to the file extension:

  • .id-{<36 random numbers>-@@ @@ }-email--ver-


For example, if you have a file called myfile.doc, the threat would rename the file to look like the following (note that "X" would be replaced with a number):

  • myfile.doc.id-{XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX-01@01@2000 01@01@01 AM1111111}-email--ver-X.X.X.X


It then shows you the following screen, which demands you send an email to the malware author and transfer an undisclosed amount of money:



The message is written in Russian, and is:

ФÐÐ™Ð›Ы Ð—ÐШИФРОÐ’АНЫ!

ФанÑ‚омас Ñ€азбушевался и зашиÑ„Ñ€овал все Ð’аши важнÑ‹е Ñ„айлÑ‹, да, да, даже оÑ„иснÑ‹е!
Но не отчаивайÑ‚есÑÂŒ, он гоÑ‚ов иÑÂ… Ð’ам веÑ€нутÑÂŒ, если ÐÂ’Ñ‹ напишиÑ‚е на его Ñ„анÑ‚омаса-почту и пÑ€едложиÑ‚е некоÑ‚оруÑÂŽ сумму денег.
Не забудÑŒте указаÑ‚ÑÂŒ Ñ„анÑ‚омас-иденÑ‚иÑ„икаÑ‚оÑ€, написаннÑ‹й в конце каждого Ñ„айла.
ФанÑ‚омас лÑŽбиÑ‚ замеÑ‚аÑ‚ÑÂŒ следÑ‹, поэтому если ÐÂ’Ñ‹ не напишиÑ‚е ему в Ñ‚ечении 48 часов, он удалиÑ‚ Ð’аш клÑŽч Ñ€асшиÑ„Ñ€овки и Ñ€асшиÑ„Ñ€овка Ñ„айлов будеÑ‚ невозможна!

When translated into English, the message is:

FILES ENCRYPTED!

Fantomas got angry and encrypted all your files, yes, yes, office files too.
But don't despair, he's ready to return them to you, if you send him a fanto-mail and offer a certain amount of money.
Don't forget to include fanto-id written at the end of the name of every file.
Fantomas likes to sweep the traces, and that's why if you don't reply within 48 hours, he will delete your decryption key and decrypting of your files will become impossible!



Analysis by Carmen Liang

SymptomsThe following can indicate that you have this threat on your PC:
  • You can't open your files, and they look similar to this:
    • myfile.doc.id-{XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX-01@01@2000 01@01@01 AM1111111}-email--ver-X.X.X.X
  • You see a message similar to this one:

Last update 31 December 2014

 

TOP