A new piece of crypto-malware is hitting Russian-speaking countries, stealing email addresses as well as spreading itself to the victim's account contacts.
In addition to these specifics of the malware, security researchers note that it is written in an active file and uses multiple freely available tools to carry out its "dirty" work.
The attack vector is a Word document transmitted via email, which claims to include a change to the terms of service agreement that must be reviewed before being signed.
Once the victim opens the document, a downloader written in JavaScript stores some executables camouflaged with the BTC extension. These are tools that are freely available to the public and are necessary for encrypting the data stored on your computer, as well as for spreading the malware.
Jaromir Horejsi and Honza Zika of Avast, who analyzed the threat, noticed that all malicious actions were initiated from a BAT file.
To cover the process of encrypting the files (XLS, XLSX, DOC, DOCX, XLSM, DWG, SVG, MDB, PDF, ZIP, RAR, and JPG) on the disk, the Word document is displayed, only to show garbled characters, which is justified by the fact that it was created with a newer version of the Microsoft Word editor.
The data is locked with a 1024-bit RSA algorithm, and relies on public key cryptography that includes a public key to encrypt the data, and a private one to decrypt it, which is sent to the attacker in this case.
A message then appears asking the victim to pay €140/$185 for the private key that unlocks the files, and to send two files (UNIQUE.PRIVATE and KEY.PRIVATE.) to an email address (paycrypt@gmail.com) controlled by the cybercriminals.
This information is required to identify the encrypted information and its location on the disk, as well as to provide the decryption key.
Email usernames and passwords are also sent to the attacker and then checked against common webmail services in Russia: Mail.ru and Yandex.
The interesting thing about the propagation method is that the 100 messages that are downloaded from the victim's inbox are filtered and those that are received are automatically deleted.
Additionally, ten variations of the emails were created, each with a custom link that redirects to different files hiding the JavaScript downloader.
This is not a typical ransomware, as it leverages free software such as GPG (for encryption), Email Extractor, Browser Password Dump (for recovering passwords stored in the web browser), and Blat (for sending e-mails).
When the illegal activity is complete, all temporary files are deleted from the system using the SDelete tool from Sysinternals, a division of Microsoft.

