查看: 13295|回复: 104
收起左侧

[病毒样本] 勒索病毒CryptXXX又升级!TrendMicro实验室命名为 —— CrypMIC【已更新多三枚】

  [复制链接]
Eset小粉絲
发表于 2016-7-29 09:55:20 | 显示全部楼层 |阅读模式
本帖最后由 Eset小粉絲 于 2016-7-30 10:24 编辑
They say imitation is the sincerest form of flattery. Take the case of CrypMIC—detected by Trend Micro as RANSOM_CRYPMIC—a new ransomware family that mimics CryptXXX in terms of entry point, ransom notes and payment site UIs. CrypMIC’s perpetrators are possibly looking for a quick buck owing to the recent success of CryptXXX.

CrypMIC and CryptXXX share many similarities; both are spread by the Neutrino Exploit Kit and use the same format for sub-versionID/botID (U[6digits] /  UXXXXXX]) and export function name (MS1, MS2). Both threats also employed a custom protocol via TCP Port 443 to communicate with their command-and-control (C&C) servers.

Upon closer look, CrypMIC and CryptXXX differ in source codes and capabilities. For instance, CrypMIC does not append an extension name to files it encrypts, making it trickier to determine which files have been held in ransom. They also differ in the use of compilers and obfuscation methods. CrypMIC has a VM check routine and sends that information to its C&C.

The demise of the Angler exploit kit from crypto-ransomware activity has made CryptXXX migrate to Neutrino exploit kit, which have been recently reported to be delivering other ransomware families such as CryptoWall, TeslaCrypt, CryptoLocker and Cerber.

We have observed that CrypMIC and CryptXXX were distributed by Neutrino interchangeably over the course of a week. CrypMIC was first pushed by Neutrino on July 6th before switching back to delivering CryptXXX 4.001 on July 8th. It started redistributing CrypMIC on July 12th before reverting to CryptXXX the next day. On the same week, Neutrino also distributed Cerber via malvertising, as well as other malware from other cybercriminal groups. By July 14th, Neutrino has started to distribute an apparently newer version of CryptXXX (5.001).

CryptXXX 5.001 is not a major version update, having only little changes such as the structure of information appended to encrypted files. Its encryption routine, number of targeted extensions and packet format among others is the same as 4.001.

Both CrypMIC and CryptXXX pose dangers to organizations and users as these threats steal and hold data hostage, and even pilfer credentials from various programs. Paying the ransom does not guarantee that end-users will get their files back. For instance, the decryptor created by CrypMIC’s developers has been reported to be not functioning properly. Additionally, paying the ransom only makes businesses and users susceptible to more ransomware attacks.

Besides regularly backing up files, keeping systems updated with the latest patches is another means of mitigating the risks of ransomware. A multilayered defense that can secure systems, servers and networks is also recommended.

Trend Micro Solutions

Enterprises can use Trend Micro solutions such as Trend Micro™ Deep Discovery™ Email Inspector and InterScan™ Web Security to block ransomware at the exposure layer—web and email. Trend Micro’s  Deep Discovery Inspector detects malicious traffic, communications, and other suspicious activities associated with attempts to inject ransomware into the network.

Trend Micro’s Deep Security™ can shield applications such as browsers from exploits—which both CrypMIC and CryptXXX rely on—that facilitate the injection of ransomware into systems. At the endpoint level, Trend Micro’s Smart Protection Suites detects and stops suspicious behavior and exploits associated with ransomware with its behavior monitoring, application control, vulnerability shielding and web security.

Trend Micro also provides security solutions for SMBs via Worry-Free™ Services Advanced’s cloud security, behavior monitoring and real-time web reputation for devices and emails. For home users, Trend Micro Security 10 provides robust protection against ransomware by blocking malicious websites, emails, and files associated with threats like CrypMIC and CryptXXX.


CryptXXX 和 CrypMIC的分别





30/7/16 -  @驭龙 @windows7爱好者


没送上人气是怎样啦

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 2人气 +2 收起 理由
230f4 + 1 根据版规,加1分以示鼓励
Flying_Bird + 1 版区有你更精彩: )

查看全部评分

轩夏
发表于 2016-7-29 10:00:16 | 显示全部楼层
MSE miss
蓝天二号
发表于 2016-7-29 10:02:21 | 显示全部楼层
McAfee miss
驭龙
发表于 2016-7-29 10:03:37 | 显示全部楼层
@windows7爱好者   快来测蜘蛛,你不来的话,我晚上就测蜘蛛了,哈哈
vm001
发表于 2016-7-29 10:05:04 | 显示全部楼层


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
o0net315
发表于 2016-7-29 10:07:07 | 显示全部楼层
本帖最后由 o0net315 于 2016-7-29 10:09 编辑

卡巴斯基 KILL ALL
刚才是杀1,另外两个过了1分钟,这是云连接有问题,还是刚刚云入库?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
dongwenqi + 1 感谢解答: )

查看全部评分

ericdj
发表于 2016-7-29 10:09:52 | 显示全部楼层
@aboringman

BD 右键,miss
断簪
发表于 2016-7-29 10:29:17 | 显示全部楼层
本帖最后由 断簪 于 2016-7-30 20:45 编辑

ESET 全杀
2016/7/30 20:44:13        文件系统实时防护        文件        G:\Downloads\CrypMIC-2\CrypMIC.dll        Win32/Kryptik.FDJK 特洛伊木马 的变种
2016/7/30 20:44:09        文件系统实时防护        文件        G:\Downloads\CrypMIC-2\CrypMIC (2).dll        Win32/Filecoder.CryptProjectXXX.H 特洛伊木马
2016/7/30 20:44:08        文件系统实时防护        文件        G:\Downloads\CrypMIC-2\CrypMIC (1).dll        Win32/Kryptik.FDJK 特洛伊木马 的变种
2016/7/30 20:43:54        文件系统实时防护        文件        G:\Downloads\CrypMIC\CrypMIC (3).dll        Win32/Filecoder.CryptProjectXXX.H 特洛伊木马
2016/7/30 20:43:53        文件系统实时防护        文件        G:\Downloads\CrypMIC\CrypMIC (2).dll        Win32/Filecoder.CryptProjectXXX.H 特洛伊木马
2016/7/30 20:43:52        文件系统实时防护        文件        G:\Downloads\CrypMIC\CrypMIC (1).dll        Win32/Filecoder.CryptProjectXXX.H 特洛伊木马
vm001
发表于 2016-7-29 10:31:12 | 显示全部楼层
没有修改文档?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aboringman
发表于 2016-7-29 11:11:57 | 显示全部楼层
ESET:

扫描:kill all files.

C:\Users\Killer\Desktop\CrypMIC\CrypMIC (1).dll.dll - Win32/Filecoder.CryptProjectXXX.H trojan - cleaned by deleting [1]

C:\Users\Killer\Desktop\CrypMIC\CrypMIC (2).dll.dll - Win32/Filecoder.CryptProjectXXX.H trojan - cleaned by deleting [1]

C:\Users\Killer\Desktop\CrypMIC\CrypMIC (3).dll.dll - Win32/Filecoder.CryptProjectXXX.H trojan - cleaned by deleting [1]


您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-14 07:40 , Processed in 0.127669 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表