Home / malware Ransom:Win32/Criakl.C
First posted on 31 December 2014.
Source: MicrosoftAliases :
There are no other names known for Ransom:Win32/Criakl.C.
Explanation :
Threat behavior
Installation
We have seen this threat use the file name winrar.exe, likely to make you think it is a legitimate app.
This threat drops a copy of itself in the following directory:
- %ProgramFiles% /temp/
It also drops the following files:
- d.bat
- temp
.tmp - this file contains the infection ID number as mentioned in the ransomware message - destop.bmp - the ransomware message that is shown on your desktop
Payload
Encrypts your files
The threat might encrypt the following files types on your PC's hard drives:
- .doc
- .docx
- .jpg
- .txt
- .xml
- .zip
It renames your files by adding the following string to the file extension:
- .id-{<36 random numbers>-
@ @ @ @ }-email- -ver-
For example, if you have a file called myfile.doc, the threat would rename the file to look like the following (note that "X" would be replaced with a number):
- myfile.doc.id-{XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX-01@01@2000 01@01@01 AM1111111}-email-
-ver-X.X.X.X
It then shows you the following screen, which demands you send an email to the malware author and transfer an undisclosed amount of money:
The message is written in Russian, and is:
ФÐÂÐ™Ð›Ы Ð—ÐÂШИФРОÐÂ’ÐÂÐÂЫ!
ФанÑ‚омаѠразбушевалÑÂÑ и зашиÑ„Ñ€овал вÑÂе Ð’аши важнÑ‹е Ñ„айлÑ‹, да, да, даже оÑ„иÑÂнÑ‹е!
ÐÂо не отчаивайÑ‚еÑÂÑÂŒ, он гоÑ‚ов иÑÂ… Ð’ам веÑ€нутÑÂŒ, еÑÂли ÐÂ’Ñ‹ напишиÑ‚е на его Ñ„анÑ‚омаÑÂа-почту и пÑ€едложиÑ‚е некоÑ‚оруÑÂŽ ÑÂумму денег.
ÐÂе забудÑŒте указаÑ‚ÑÂŒ Ñ„анÑ‚омаÑÂ-иденÑ‚иÑ„икаÑ‚оÑ€, напиÑÂаннÑ‹й в конце каждого Ñ„айла.
ФанÑ‚омаÑ лÑŽбиÑ‚ замеÑ‚аÑ‚ÑÂŒ ÑÂледÑ‹, поÑÂÑ‚ому еÑÂли ÐÂ’Ñ‹ не напишиÑ‚е ему в Ñ‚ечении 48 чаÑÂов, он удалиÑ‚ Ð’аш клÑŽч Ñ€аÑÂшиÑ„Ñ€овки и Ñ€аÑÂшиÑ„Ñ€овка Ñ„айлов будеÑ‚ невозможна!
When translated into English, the message is:
FILES ENCRYPTED!
Fantomas got angry and encrypted all your files, yes, yes, office files too.
But don't despair, he's ready to return them to you, if you send him a fanto-mail and offer a certain amount of money.
Don't forget to include fanto-id written at the end of the name of every file.
Fantomas likes to sweep the traces, and that's why if you don't reply within 48 hours, he will delete your decryption key and decrypting of your files will become impossible!
Analysis by Carmen Liang
SymptomsThe following can indicate that you have this threat on your PC:
- You can't open your files, and they look similar to this:
- myfile.doc.id-{XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX-01@01@2000 01@01@01 AM1111111}-email-
-ver-X.X.X.X - You see a message similar to this one:
Last update 31 December 2014