TROJ_CRYPCTB.TMC

 Analysis by: Francis Xavier Antazo

 ALIASES:

Ransom:Win32/Critroni.A (MICROSOFT), a variant of Win32/Injector.BRJT trojan (NOD32)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Downloaded from the Internet, Dropped by other malware


This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size:

827,392 bytes

File Type:

EXE

Memory Resident:

Yes

Payload:

Encrypts files

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan drops the following files:

  • %User Profile%\My Documents\Decrypt All Files {random characters}.bmp - image used as wallpaper
  • %User Profile%\My Documents\Decrypt All Files {random characters}.txt - ransom note in text file
  • %User Profile%\My Documents\{random characters}.html - contains ransom note and list of encrypted files

(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)

Autostart Technique

This Trojan drops the following files:

  • C:\Windows\Tasks\{random filename}.job

Other System Modifications

This Trojan modifies the following registry entries:

HKEY_CURRENT_USER\Control Panel\Desktop
Wallpaper = "%User Profile%\My Documents\Decrypt All Files {random characters}.bmp"

(Note: The default value data of the said registry entry is {user-defined}.)

Other Details

This Trojan encrypts files with the following extensions:

  • 7z
  • arj
  • bz2
  • cab
  • chm
  • cpio
  • dmg
  • flv
  • gz
  • lha
  • lzh
  • lzma
  • rar
  • swm
  • tar
  • tbz2
  • tgz
  • wim
  • xar
  • xz
  • z
  • zip
  • 3gp
  • aac
  • ans
  • ape
  • asc
  • asm
  • asp
  • aspx
  • avi
  • awk
  • bas
  • bat
  • bmp
  • c
  • cs
  • cls
  • clw
  • cmd
  • cpp
  • csproj
  • css
  • ctl
  • cxx
  • def
  • dep
  • dlg
  • dsp
  • dsw
  • eps
  • f
  • f77
  • f90
  • f95
  • fla
  • flac
  • frm
  • gif
  • h
  • hpp
  • hta
  • htm
  • html
  • hxx
  • ico
  • idl
  • inc
  • ini
  • inl
  • java
  • jpeg
  • jpg
  • js
  • la
  • mak
  • manifest
  • wmv
  • mov
  • mp3
  • mp4
  • mpe
  • mpeg
  • mpg
  • m4a
  • ofr
  • ogg
  • pac
  • pas
  • pdf
  • php
  • php3
  • php4
  • php5
  • phptml
  • pl
  • pm
  • png
  • ps
  • py
  • pyo
  • ra
  • rb
  • rc
  • reg
  • rka
  • rm
  • rtf
  • sed
  • sh
  • shn
  • shtml
  • sln
  • sql
  • srt
  • swa
  • tcl
  • tex
  • tiff
  • tta
  • txt
  • vb
  • vcproj
  • vbs
  • wav
  • wma
  • wv
  • xml
  • xsd
  • xsl
  • xslt