While Ransomlock Trojans have become quite widespread in recent years, we are seeing cybercriminals increasingly using Ransomcrypt Trojans. The difference between Ransomlock and Ransomcrypt Trojans is that Ransomlocks lock the desktop of computers, while Ransomcrypt encrypts individual files. Both threats blackmail and demand ransom from their victims.
Recently, Symantec detected Trojan.Ransomcrypt.F , ( also known as Cryptolocker ). Trojan.Ransomcrypt.F encrypts files, such as images and Microsoft Office documents and then demands a ransom in Bitcoin or MoneyPak to decrypt them. The Ransomcrypt Trojan uses strong encryption algorithms that make it almost impossible to decrypt the files without the encryption key.
Figure 1. Trojan.Ransomcrypt.F payment screen
Most of the Trojan.Ransomlock.F observed by Symantec were found in North America.
Figure 2. Trojan.Ransomlock.F infection map
The malicious files arrive via an email that contains a malicious attachment, the Trojan.Zbot, which then installs the Trojan.Ransomlock.F. The Trojan Ransomcrypt uses a domain generation algorithm (DGA) to locate and connect to the command and control server (C&C).
Figure 3. Ransomcrypt DNS requests
Malware developers use DGAS to give their malicious software the ability to use very few static servers. However, malware such as Trojan.Ransomcrypt.F uses dynamic domain names based on certain criteria. This makes it even more difficult to block its connection to the command-and-control servers.
Figure 4. Trojan.Zbot
When we compare Trojan.Zbot and Trojan.Ransomcrypt.F we see similarities in the code that lead us to conclude that there may be a connection between the two Trojans. The source code of Zbot is freely available on the Internet.




