A modified version of the open-source ransomware desuCrypt is being used as the base code for a new ransomware outbreak that has begun. The new variant comes with two extensions: “.insane” and “.DEUSCRYPT.”.
When desuCrypt is run, a window will be created that displays the current status of the encryption process. This window will remain open until the ransomware has finished encrypting the computer.
According to Michael Gillespie, the creator of ID-Ransomware, the .Insane variant of desuCrypt encrypts files using RC4 encryption. This RC4 key is further encrypted using an embedded RSA-2048 key and then appended to it. Depending on the version, when encrypting a file the ransomware will append either the [Rememberggg@tutanota.com].DEUSCRYPT or [Insane@airmail.cc].insane extension to the name of the encrypted file.
After all data has been encrypted, 2 .txt files are then created (How_decrypt_files.txt for the Insane variant) and (note.txt for the DeusCrypt variant). Both notes tell the victim to contact the listed email addresses and read the payment instructions.
Michael Gillespie has managed to create a decryptor for both variants of desuCrypt. To use the program, you need to have the same file in its encrypted and unencrypted form, and the file must be larger than 10MB. These will then be used to learn the decryption key. Once the decryption key is retrieved, the decryptor can be used to recover all the remaining files.
