A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28890  by maddog4012
 Thu Jul 14, 2016 9:35 pm
Com_loader.exe is a variant of ransomeware

text found in the readme.html file that was drop to the system
Code: Select all
 All of your files were protected by a strong encryption with RSA-4096<br/>
                            More information about the encryption RSA-4096 can be found here: <a
                                href="http://en.wikipedia.org/wiki/RSA">http://en.wikiDedia.orQ/wiki/RSA</a>
                            (cryptosystem)
                        </p>
                        <div class="title">
                            <span class="left"></span>
                            <i class="num">- <span>2</span> -</i>
                            <h3>How did this happen?
                            </h3>
                        </div>

                        <p class="text">Specially for your PC was generated personal RSA4096 key, both public and
                            private. </p>

                        <p class="text">ALL YOUR FILES were encrypted with the public key, which has been transferred to
                            your computer via the Internet.
                            Decrypting of your files is only possible with the help of the private key and decrypt
                            program, which is on our secret server
                        </p>

                        <div class="title">
                            <span class="left"></span>
                            <i class="num">- <span>3</span> -</i>
                            <h3>What do I do?
                            </h3>
                        </div>
                        <p class="text">So , there are two ways you can choose: wait for a _miracle_ and get _your_ PRICE DOUBLED! Or start obtaining *BITCOIN NOW! , and restore _YOUR_ _DATA_ easy way
				If You have really valuable _DATA_, you better _NOT_ _WASTE_ _YOUR_ _TIME_, because there is _NO_ other way to get your files, except make a _PAYMENT_</p>
                        <div class="clr"></div>
                        <div class="personal-id">
                            <div class="row">
                                <div class="col-md-12">
                                    <p class="id-title">Your personal ID</p>
                                    <div class="id-block">8F806111:47235589:7DC4E1BC:58155022     </div>
                                </div>

                            </div>
                        </div>
                        <div class="blue-block">
                            <div class="blue-block-title">
                                For more specific instructions,please visit your personal home page, there are a few
                                different addresses pointing to your page below:
                            </div>
                            <div class="info">
                                <ol>
                                    <li><a href="">http://jchiyogcbhkamxv5.onion.to</a></li>
                                    <li><a href="">http://jchiyogcbhkamxv5.onion.city</a></li>
                                </ol>
                            </div>
                        </div>
                        <div class="blue-block">
                            <div class="blue-block-title">
                                If for some reasons the addresses are not available, follow these steps:
                            </div>
                            <div class="info">
                                <ol>
                                    <li>Download and install tor-browser: <a href="">https://torproject.org/projects/torbrowser.html</a>
                                    </li>
                                    <li>After a successful installation, run the browser</li>
                                    <li>Type in the address bar: <a href="">http://jchiyogcbhkamxv5.onion</a></li>
                                    <li>Follow the instructions on the site.</li>
 
[/i]
reaches out to the following

IP Address Port Accessed By
91.220.131.147 443 com_loader.exe

this is from the dropped text file
Code: Select all
[quote][i]NOT YOUR LANGUAGE? USE https://translate.google.com

What happened to your files ?
All of your files were protected by a strong encryption with RSA4096
More information about the encryption keys using RSA4096 can be found here: http://en.wikipedia.org/wiki/RSA_(cryptosystem)

How did this happen ?
!!! Specially for your PC was generated personal RSA4096 Key , both public and private.
!!! ALL YOUR FILES were encrypted with the public key, which has been transferred to your computer via the Internet.
!!! Decrypting of your files is only possible with the help of the private key and decrypt program , which is on our Secret Server

What do I do ?
So , there are two ways you can choose: wait for a _miracle_ and get _your_ PRICE DOUBLED! Or start obtaining *BITCOIN NOW! , and restore _YOUR_ _DATA_ easy way
If You have really valuable _DATA_, you better _NOT_ _WASTE_ _YOUR_ _TIME_, because there is _NO_ other way to get your files, except make a _PAYMENT_


Your personal ID: D2D3DDCA:4EDF31E1:8FCDBCA6:3308D4D7     

For more specific instructions, please visit your personal home page, there are a few different addresses pointing to your page below:

1 - http://jchiyogcbhkamxv5.onion.to
2 - http://jchiyogcbhkamxv5.onion.city

If for some reasons the addresses are not availablweropie, follow these steps:

1 - Download and install tor-browser: http://www.torproject.org/projects/torbrowser.html.en
2 - Video instruction: https://www.youtube.com/watch?v=NQrUZdsw2hA
3 - After a successful installation, run the browser
4 - Type in the address bar: http://jchiyogcbhkamxv5.onion
5 - Follow the instructions on the site[/i][/quote]