@abuse.ch wrote a very interesting post about the providers hosting the C2 infrastructure which is being used by malware encrypted with Qrypter.
Since a few weeks Qrypter has migrated to a new platform and doesn't use Tor any more
data:image/s3,"s3://crabby-images/4971b/4971bc37eec62c6be211ab52d40b2ccbfb28dede" alt=""
data:image/s3,"s3://crabby-images/9aba0/9aba0a7bb1091b81ab22719b3bab768031dc53a4" alt=""
data:image/s3,"s3://crabby-images/3962a/3962a97da7705321ceeafbcde1d3fb94ecdd7bd9" alt=""
The new version of Qrypter uses a Java application running locally, which encrypts the files.
data:image/s3,"s3://crabby-images/3ea16/3ea161141f997ba178aa864b110ed014cb751c1a" alt=""
In order to use the application, the user must be registered and buy a license (credits).
data:image/s3,"s3://crabby-images/1a6ab/1a6ab8a5a6335ca0a801e484ba39811ed36d01a1" alt=""
data:image/s3,"s3://crabby-images/a3882/a3882759498fc6d9bff8994bacdfa81d948e9d6f" alt=""
I wanted to check if there is any substantial change in how the malware is encrypted with the service, hence I took a look to a recent sample. The behaviour analysis doesn't really show any difference.
data:image/s3,"s3://crabby-images/6c8e2/6c8e2035487dddb765d371d80fb2e029f6619e25" alt=""
While debugging the malware I can see the different Java processes executed until the final payload is decrypted and executed
data:image/s3,"s3://crabby-images/17ddb/17ddb6c38630f2acb70a523068d7064244a2b132" alt=""
In the end the configuration for the command and controlled is obtained the same way than with previous Qrypter version
data:image/s3,"s3://crabby-images/bd006/bd006df027ce7e7f118af5f2d1eb26ea33ccc6cc" alt=""
data:image/s3,"s3://crabby-images/150dd/150dd97b880a034044f6df55d674b5689fa7024a" alt=""
During the analysis process, I can see the typical Adwind behaviour executing VB scripts for checking AV installed, local firewall and making itself persistent via the registry
data:image/s3,"s3://crabby-images/f053d/f053daadae8d240c99768c315604a5daa9675f4b" alt=""
data:image/s3,"s3://crabby-images/e2f27/e2f272a05a7f9828c45a074bfaf032fd96228630" alt=""
data:image/s3,"s3://crabby-images/743f3/743f3f79e26ecd0b2b2708a3d12b05568932d3f2" alt=""
data:image/s3,"s3://crabby-images/95a4f/95a4f3477aeb8458f89b96149bc537306775aa78" alt=""
Qthelegend, the new Qrypter, has not really change in terms of how the malware is encrypted.