KeRanger

KeRanger (also known as OSX.KeRanger.A) is a ransomware trojan horse targeting computers running macOS. Discovered on March 4, 2016, by Palo Alto Networks, it affected more than 7,000 Mac users.

KeRanger is remotely executed on the victim's computer from a compromised installer for Transmission, a popular BitTorrent client downloaded from the official website. It is hidden in the .dmg file under General.rtf. The .rtf is actually a Mach-O format executable file packed with UPX 3.91. When users click these infected apps, their bundle executable Transmission.app/Content/MacOS/Transmission will copy this General.rtf file to ~/Library/kernel_service and execute this "kernel_service" before any user interface appearing.[1] It encrypts the files with RSA and RSA public key cryptography, with the key for decryption only stored on the attacker's servers. The malware then creates a file, called "readme_to_decrypt.txt", in every folder. When the instructions are opened, it gives the victim directions on how to decrypt the files, usually demanding a payment of one bitcoin. The ransomware is considered to be a variant of the Linux ransomware Linux.Encoder.1.[2]

Warning issued to Transmission users.

Discovery

On March 4, 2016, Palo Alto Networks added Ransomeware.KeRanger.OSX to their virus database. Two days after, they published a description and a breakdown of the code.

Propagation

According to Palo Alto Research Center, KeRanger was most commonly infected into Transmission from the official website being compromised, then the infected .dmg was uploaded to look like the "real" Transmission. After it was reported, the makers of Transmission issued a new download on the website and pushed out a software update.

The only way the malware infected the victim's computer was by using a valid developer signature issued by Apple, which allowed it to bypass Apple's built-in security.

Encryption process

"README_FOR_DECRYPTION.txt" file placed in all folders.

The first time it executes, KeRanger will create three files ".kernel_pid", ".kernel_time" and ".kernel_complete" under ~/Library directory and write the current time to ".kernel_time". It will then sleep for three days.[1] After that, it will collect information about the Mac, which includes the model name and the UUID. After it collects the information, it uploads it to one of its Command and Control servers. These servers’ domains are all sub-domains of onion[.]link or onion[.]nu, two domains that host servers only accessible over the Tor network. After it connects with the Command and Control servers, it returns the data with a "README_FOR_DECRYPT.txt" file. It then tells the user that their files have been encrypted, etc. and that they need to pay a sum of one bitcoin, which used to be roughly $400 in United States dollar.

KeRanger encrypts each file (e.g. Test.docx) by first creating an encrypted version that uses the .encrypted extension (i.e. Test.docx.encrypted.) To encrypt each file, KeRanger starts by generating a random number (RN) and encrypts the RN with the RSA key retrieved from the C2 server using the RSA algorithm. It then stores the encrypted RN at the beginning of resulting file. Next, it will generate an Initialization Vector (IV) using the original file’s contents and store the IV inside the resulting file. After that, it will mix the RN and the IV to generate an AES encryption key. Finally, it will use this AES key to encrypt the contents of the original file and write all encrypted data to the result file.

Encrypted files

After connecting to the C2 server, it will retrieve the encryption key, then start the process. It will first encrypt the "/Users" folder, then after that "/Volumes" There are also 300 file extensions that are encrypted, such as:

  • Documents: .doc, .docx, .docm, .dot, .dotm, .ppt, .pptx, .pptm, .pot, .potx, .potm, .pps, .ppsm, .ppsx, .xls, .xlsx, .xlsm, .xlt, .xltm, .xltx, .txt, .csv, .rtf, .te
  • Images: .jpg, .jpeg
  • Audio and video: .mp3, .mp4, .avi, .mpg, .wav, .flac
  • Archives: .zip, .rar., .tar, .gzip
  • Source code: .cpp, .asp, .csh, .class, .java, .lua
  • Database: .db, .sql
  • Email: .eml
  • Certificate: .pem

References

  1. ^ a b Xiao, Claud; Chen, Jin (6 March 2016). "New OS X Ransomware KeRanger Infected Transmission BitTorrent Client Installer - Palo Alto Networks Blog". Palo Alto Networks Blog. Retrieved 2016-03-10.
  2. ^ "KeRanger Is Actually A Rewrite of Linux.Encoder". Bitdefender Labs. Retrieved 28 March 2016.

Read other articles:

Naomi NovikLahir30 April 1973 (umur 50)New York, ASPekerjaanPenulis, programer komputerKebangsaanAmerikaPeriodePerang era NapoleonGenreFantasi sejarah/Sejarah alternatifTemaPerang Napoleonik bertarung dengan para nagaPasanganCharles ArdaiAnakEvidence Novik ArdaiWebsitewww.temeraire.org Naomi Novik (lahir 30 April 1973) adalah seorang penulis Amerika. Ia menulis serial sembilan novel fantasi/sejarah alternatif Temeraire. Buku pertamanya, His Majesty's Dragon, memenangkan Penghargaan Compt...

 

 

Kamancheh Kamancheh (Persia: کمانچهcode: fa is deprecated , bahasa Azerbaijan: Kamança, bahasa Kurdi: کەمانچە ,Kemançe) adalah sebuah alat musik gesek Iran yang digunakan di Persia,[1] Azerbaijan[2] dan musik Kurdi.[3] Kamancheh terkait dengan rebab yang merupakan nenek moyang historis kamancheh dan lyra Bizantium yang tertekuk.[4] Senar dimainkan dengan busur variabel-ketegangan. Ini banyak digunakan dalam musik klasik Iran, Azerbaijan, ...

 

 

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (فبراير 2023) أشنات أليفة الأوراق تنمو على ورقة في غابات الأمازون[؟] قرب تينا، الإكوادور أليف الأوراق أو محب الأوراق (بالإنجليزية: Foliicolous)‏ مصطلح يشير إلى عادة نمو بع�...

ألفية: ألفية 3 قرون: القرن 20 – القرن 21 – القرن 22 عقود: عقد 1970  عقد 1980  عقد 1990  – عقد 2000 –  عقد 2010  عقد 2020  عقد 2030 سنين: 2005 2006 2007 – 2008 – 2009 2010 2011 2008 في التقاويم الأخرىتقويم ميلادي2008MMVIIIتقويم هجري1428–1430تقويم هجري شمسي1386–1387تقويم أمازيغي2958من بداية روما2761ت...

 

 

TeurastamoTeurastamo area in July 2016TeurastamoShow map of HelsinkiTeurastamoShow map of FinlandEtymologyliterally meaning slaughterhouseGeneral informationStatusGeneral public spaceLocationHermanniAddressTyöpajankatu 2 ATown or cityHelsinkiCountryFinlandCoordinates60°11′23″N 24°58′18″E / 60.18979°N 24.97179°E / 60.18979; 24.97179Opened1933 (as slaughterhouse)2012 (as public area)OwnerTukkutoriDesign and constructionArchitect(s)Bertel Liljequist Teurastam...

 

 

Academic journalJournal of the American Mathematical SocietyDisciplinePure and applied mathematicsLanguageEnglishEdited byLaura DeMarco, Simon Donaldson, Pavel Etingof, Michael J. Larsen, Sylvia Serfaty, Richard Taylor, Shmuel WeinbergerPublication detailsHistory1988-presentPublisherAmerican Mathematical Society (United States)FrequencyQuarterlyImpact factor4.692 (2016)Standard abbreviationsISO 4 (alt) · Bluebook (alt1 · alt2)NLM (alt) · Mat...

Social class in Middle Age and Early Modern France This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: French nobility – news · newspapers · books · scholar · JSTOR (July 2009) (Learn how and when to remove this message) Pierre d'Hozier (1592–1660), genealogist and juge d'armes of France, employed to verify th...

 

 

Polygon with 13 edges Regular tridecagonA regular tridecagonTypeRegular polygonEdges and vertices13Schläfli symbol{13}Coxeter–Dynkin diagramsSymmetry groupDihedral (D13), order 2×13Internal angle (degrees)≈152.308°PropertiesConvex, cyclic, equilateral, isogonal, isotoxalDual polygonSelf In geometry, a tridecagon or triskaidecagon or 13-gon is a thirteen-sided polygon. Regular tridecagon A regular tridecagon is represented by Schläfli symbol {13}. The measure of each internal angle of ...

 

 

American outlaw and gunfighter (1859–1881) For other uses, see Billy the Kid (disambiguation). Billy the KidPortrait attributed to Ben Wittick, c. 1880BornHenry McCarty[1]September 17 or (1859-11-23)November 23, 1859New York City, U.S.DiedJuly 14, 1881(1881-07-14) (aged 21)Fort Sumner, New MexicoCause of deathGunshot woundResting placeOld Fort Sumner Cemetery34°24′13″N 104°11′37″W / 34.40361°N 104.19361°W / 34.40361; -104.19361...

Temporary rescission of corporate personhood This article is part of a series onCorporate law By jurisdiction Anguilla Australia BVI Canada Cayman Islands India South Africa UK United States Vietnam European Union France Germany General corporate forms Company Conglomerate Cooperative Corporation Holding company Joint-stock Partnership General Limited Limited liability Private limited Shell corporation Shelf corporation Sole proprietorship Corporate formsby jurisdiction European Union Societa...

 

 

Fox flagship station in New York City This article is about the Fox flagship station in New York City. For other stations that previously used the WNEW callsign, see WNEW (disambiguation). For the former shortwave radio station, see WNYW (shortwave) and WYFR. WNYWNew York, New YorkUnited StatesChannelsDigital: 27 (UHF)Virtual: 5BrandingFox 5 New York; The News On Fox 5ProgrammingAffiliations5.1: Foxfor others, see § SubchannelsOwnershipOwnerFox Television Stations, LLCSister stationsWWO...

 

 

Pour les articles ayant des titres homophones, voir Houilles et Ouille (homonymie). Pour les articles homonymes, voir Houille (rivière) et Houille blanche. Houille. La houille est une roche carbonée sédimentaire correspondant à une qualité spécifique de charbon, intermédiaire entre le lignite et l'anthracite (soit 80 à 90 % de carbone). De couleur noirâtre, elle provient de la carbonisation d'organismes végétaux et peut donc servir de combustible fossile. Ce combustible est u...

Conference on World War I reparations (1929-30) Paris Peace Conference League of Nations Covenant of the League of Nations Members Organisation Minority Treaties Little Treaty of Versailles Mandates Treaty of Versailles War Guilt clause Reparations Dawes Plan Hague conference on reparations Young Plan Lausanne Conference Locarno Treaties Possible cause of World War II International Opium Convention Treaty of Saint-Germain-en-Laye Treaty of Saint-Germain-en-Laye Treaty of Neuilly-sur-Seine Tre...

 

 

Isole Marianne Settentrionali (dettagli) (dettagli) Isole Marianne Settentrionali - Localizzazione Dati amministrativiNome completoCommonwealth delle Isole Marianne Settentrionali Nome ufficialeCommonwealth of the Northern Mariana Islands Dipendente da Stati Uniti Lingue ufficialiinglese[1] Altre linguechamorro, caroliniano[1] CapitaleSaipan  (48220 ab. / 2010) PoliticaStatusCommonwealth in unione politica con gli Stati Uniti PresidenteJoe Biden Gover...

 

 

Map all coordinates using OpenStreetMap Download coordinates as: KML GPX (all coordinates) GPX (primary coordinates) GPX (secondary coordinates) This list is of paintings designated in the category of paintings (絵画, kaiga) for the Prefecture of Kōchi, Japan.[1] National Cultural Properties As of 1 July 2019, two Important Cultural Properties have been designated, being of national significance.[2][3] Property Date Municipality Ownership Comments Image Dimensions ...

Artikel ini memerlukan pemutakhiran informasi. Harap perbarui artikel dengan menambahkan informasi terbaru yang tersedia. Halaman ini berisi artikel tentang sepeda motor sport bermesin dua-silinder segaris yang diperkenalkan pada pertengahan tahun 2016. Untuk untuk sepeda motor sport bermesin silinder-tunggal yang diproduksi sejak tahun 2011, lihat Honda CBR250R. Honda CBR250RRProdusenAstra Honda MotorPerusahaan indukHonda Motor CompanyTahun Produksi2017[1]PerakitanIndonesia: Karawang...

 

 

Award ceremony for Hindi language films 62nd Filmfare Awards62nd Filmfare AwardsDate14 January 2017SiteNSCI Dome, MumbaiHosted byShah Rukh Khan Karan Johar Kapil SharmaOfficial websiteFilmfare Awards 2017HighlightsBest FilmDangalCritics Awardfor Best FilmNeerjaMost awardsNeerja (6)Most nominationsAe Dil Hai Mushkil & Udta Punjab (9)Television coverageNetworkSony Entertainment Television (India) ← 61st Filmfare Awards 63rd → The 62nd Filmfare Awards ceremony, presente...

 

 

Baptismal rite in Sethian Gnosticism   Part of a series onGnosticism Gnostic concepts Adam kasia Adam pagria Aeon Anima mundi Archon Barbelo Demiurge Five Seals Gnosis Kenoma Luminary Manda Monad Ogdoad Pleroma Sophia Uthra World of Light World of Darkness Yaldabaoth Gnostic sects and founders List of Gnostic sects Proto-Gnosticism Maghāriya Thomasines Judean / Israelite Adam Mandaeism Elksai Elkasaites Samaritan Baptist Dositheos Simon Magus (Simonians) Menander Quqites Christian Gnost...

Cet article est une ébauche concernant la Révolution française. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Jean-Baptiste Royer (député à la Convention nationale et au Conseil des Cinq-Cents, évêque constitutionnel de l'Ain puis de la Seine) En France, un évêque constitutionnel est un évêque membre de l'Église constitutionnelle entre 1790 et 1801, et ayant à ce titre prêté l'un des serments e...

 

 

This is an archive of past discussions. Do not edit the contents of this page. If you wish to start a new discussion or revive an old one, please do so on the current talk page. CfD nomination of Category:Writers by ethnic or national descent Category:Writers by ethnic or national descent has been nominated for deletion, merging, or renaming. You are encouraged to join the discussion on the Categories for discussion page. Aristophanes68 (talk) 06:58, 9 August 2014 (UTC) Category:Rock singer-s...