
A new ransomware, known as 5ss5c, appears to have been created by the same group behind Satan ransomware. The group is also rumored to be the creator of DBGer and Lucky ransomware, and possibly Iron ransomware.
As Bart Blaze reports, the malicious group has been planning the 5ss5c ransomware since at least November 2019, and the malicious code is likely still in development. Experts have discovered that the malicious code contains an Enigma VirtualBox, called poc.exe.
“There are some indications that 5ss5c is still in active development and is derived from the Satan Ransomware,” Blaze said in a post.
As the security, he discovered several pieces of evidence that suggest that 5ss5c comes from the Satan ransomware, one of which is that updates for Satan stopped last November, when 5ss5c first appeared.
5ss5c starts its process via a downloader and uses the EternalBlue exploit to spread. As Blaze reports, many of 5ss5c's elements, techniques, and procedures (TTPs) share similarities with both Satan and DBGer, and to some extent with Iron ransomware.
The poc.exe file is moved to C:\ProgramData\poc.exe and executes the command:
cd /DC:ProgramData&star.exe –OutConfig a –TargetPort 445 –Protocol SMB –Architecture x64 –Function RunDLL –DllPayload C:ProgramDatadown64.dll –TargetIp
which is similar to the command executed by Satan ransomware:
cmd /c cd /DC:UsersAlluse~1&blue.exe –TargetIp & star.exe –OutConfig a –TargetPort 445 –Protocol SMB –Architecture x64 –Function RunDLL –DllPayload down64.dll –TargetIp
Both Satan and 5ss5c have a list of files that are not encrypted by malicious code. The list of new ransomware includes additional files, such as those associated with Qih00 360 (360download and 360safe files).
Once the ransomware is executed, it displays a note in Chinese demanding 1 bitcoin to decrypt the victim's files.
If the victim does not pay the ransom within 48 hours, the amount is doubled. The message does not include an email address to contact the hackers or to make the payment. Instead, the ransomware appends the email address (5ss5c (at) mail [.] Ru) to the name of each encrypted file, for example a test.txt file will have the following format: [5ss5c@mail.ru]test.txt.Y54GUHKIG1T2ZLN76II9F3BBQV7MK4UOGSQUND7U.5ss5c.
