Undetected PowerShell Ransomware Easily Blocked by Acronis Active Protection

A new ransomware variant avoided detection by being spread through a spear phishing email campaign as an obfuscated PowerShell script. Many traditional anti-malware solutions are not ready for the next generation of ransomware attacks, according to NioGuard Security Lab. Acronis, however, has been successful in detecting and blocking recent zero-day ransomware attacks.

Virustotal showed 0/57 detection ratio on July 9, 2017.

Two days later, still, more than a half of the tested anti-malware programs were incapable of detecting this type of dangerous ransomware.

Ransomware delivery method

The malicious JS (Readable Msg-j8k5b798d4.js) is delivered in a ZIP archive (EML_j8k5b798d4.zip) attached to a fake delivery status notification email that supposedly contained a letter blocked by a spam filter.

Once extracted and executed by the user, the JavaScript starts a PowerShell console and sends the deobfuscated shell script to it:

"C:\Windows\system32\windowspowershell\v1.0\powershell.exe" iex $env:LoadShellCodeScript

Data encryption

First, three random Base64-like strings are generated:

  • String1
  • String2
  • UUID

These strings are sent to a remote server and used to generate the Rijndael session key.

The Rijndael key is generated using the ‘Rfc2898DeriveBytes’ class. The constructor accepts the following parameters to create a cryptographic object:

  • string1 - the password used to derive the key;
  • hex_byte_array(string2) - the key salt used to derive the key;
  • 5 - the number of iterations to generate the Rijndael key.

The initialization vector (IV) is calculated as first 16 bytes of the SHA-1 hash from the word ‘alle’. Both IV and key are the same for all files. It uses the Rijndael encryption algorithm with a 256-bit key and CBC mode.

The cryptolocker encrypts the first 4096 bytes of the file and if the file size is greater than that, or the entire file if the file size is lower.

The ransom note is decoded from a Base64 string and a Personal ID is added at the end. The ID is generated randomly earlier. The html file with the ransom note named ‘_README-Encrypted-Files.html’ is dropped in the folders with encrypted files.

The PowerShell ransomware encrypts files having the following extensions:

yuv, ycbcra, xis, x3f, x11, wpd, tex, sxg, stx, st8, st5, srw, srf, sr2, sqlitedb, sqlite3, sqlite, sdf, sda, sd0, s3db, rwz, rwl, rdb, rat, raf, qby, qbx, qbw, qbr, qba, py, psafe3, plc, plus_muhd, pdd, p7c, p7b, oth, orf, odm, odf, nyf, nxl, nx2, nwb, ns4, ns3, ns2, nrw, nop, nk2, nef, ndd, myd, mrw, moneywell, mny, mmw, mfw, mef, mdc, lua, kpdx, kdc, kdbx, kc2, jpe, incpas, iiq, ibz, ibank, hbk, gry, grey, gray, fhd, fh, ffd, exf, erf, erbsql, eml, dxg, drf, dng, dgc, des, der, ddrw, ddoc, dcs, dc2, db_journal, csl, csh, crw, craw, cib, ce2, ce1, cdrw, cdr6, cdr5, cdr4, cdr3, bpw, bgt, bdb, bay, bank, backupdb, backup, back, awg, apj, ait, agdl, ads, adb, acr, ach, accdt, accdr, accde, ab4, 3pr, 3fr, vmxf, vmsd, vhdx, vhd, vbox, stm, st7, rvt, qcow, qed, pif, pdb, pab, ost, ogg, nvram, ndf, m4p, m2ts, log, hpp, hdd, groups, flvv, edb, dit, dat, cmt, bin, aiff, xlk, wad, tlg, st6, st4, say, sas7bdat, qbm, qbb, ptx, pfx, pef, pat, oil, odc, nsh, nsg, nsf, nsd, nd, mos, indd, iif, fpx, fff, fdb, dtd, design, ddd, dcr, dac, cr2, cdx, cdf, blend, bkp, al, adp, act, xlr, xlam, xla, wps, tga, rw2, r3d, pspimage, ps, pct, pcd, m4v, fxg, flac, eps, dxb, drw, dot, db3, cpi, cls, cdr, arw, ai, aac, thm, srt, save, safe, rm, pwm, pages, obj, mlb, md, mbx, lit, laccdb, kwm, idx, html, flf, dxf, dwg, dds, csv, css, config, cfg, cer, asx, aspx, aoi, accdb, 7zip, 1cd, xls, wab, rtf, prf, ppt, oab, msg, mapimail, jnt, doc, dbx, contact, n64, m4a, m4u, m3u, mid, wma, flv, 3g2, mkv, 3gp, mp4, mov, avi, asf, mpeg, vob, mpg, wmv, fla, swf, wav, mp3, qcow2, vdi, vmdk, vmx, wallet, upk, sav, re4, ltx, litesql, litemod, lbf, iwi, forge, das, d3dbsp, bsa, bik, asset, apk, gpg, aes, ARC, PAQ, tar.bz2, tbk, bak, tar, tgz, gz, 7z, rar, zip, djv, djvu, svg, bmp, png, gif, raw, cgm, jpeg, jpg, tif, tiff, NEF, psd, cmd, bat, sh, class, jar, java, rb, asp, cs, brd, sch, dch, dip, pl, vbs, vb, js, asm, pas, cpp, php, ldf, mdf, ibd, MYI, MYD, frm, odb, dbf, db, mdb, sql, SQLITEDB, SQLITE3, 011, 010, 009, 008, 007, 006, 005, 004, 003, 002, 001, pst, onetoc2, asc, lay6, lay, ms11, sldm, sldx, ppsm, ppsx, ppam, docb, mml, sxm, otg, odg, uop, potx, potm, pptx, pptm, std, sxd, pot, pps, sti, sxi, otp, odp, wb2, 123, wks, wk1, xltx, xltm, xlsx, xlsm, xlsb, slk, xlw, xlt, xlm, xlc, dif, stc, sxc, ots, ods, hwp, 602, dotm, dotx, docm, docx, DOT, 3dm, max, 3ds, xml, txt, CSV, uot, RTF, pdf, XLS, PPT, stw, sxw, ott, odt, DOC, pem, p12, csr, crt, key

C&C Communication

The PowerShell script sends the check-in request to the remote server hxxp://joelosteel.gdn/pi.php using the HTTP protocol. The request contains three strings (password, salt, and UUID). First two are used to create the encryption key.

After the check-in request is sent, the script sleeps for 2 min and goes on to files encryption.

The remote server’s IP is registered to DigitalOcean, LLC and is located in New York City, US:

The decryption service is hosted in the Tor network:


At the moment of writing this report, the decryption service was not responsive.

Deleting Shadow Copies

At the end, the script deletes shadow copies of files:


  • Being an obfuscated script (JS, PowerShell) the ransomware easily bypasses antivirus protection.
  • The ransomware is delivered as a targeted attack using spear-phishing emails.
  • The PowerShell cryptolocker uses Rijndael encryption algorithm with the key length 256 bits. The strings used to derive the key are sent to the attacker. Therefore, victims can not decrypt files without getting access to the ISP’s HTTP traffic dump.
  • The ransomware deletes shadow copies (backup versions) of files.

Acronis True Image blocks PowerShell ransomware

Acronis True Image blocks the encryption attack and lets users restore affected files.

1. Acronis TrueImage detects ransomware activity:

2. Clicking the Recover files button restores the affected files.

The files have been successfully recovered.


Try Acronis True Image Now!