
The SonicWall Capture Labs Threat Research Team have observed a variant of the Jigsaw Ransomware trojan in the wild called Zapium. Like most ransomware there is a time limit after which files are permanently lost. We have observed the Jigsaw ransomware as having a limit of around one hour. However, Zapium will delete one file every 5 minutes thus increasing the pressure to act!
Infection Cycle:
Upon execution the Trojan encrypts files on the system then displays the following message:

The Trojan adds the following keys to the registry:
The UI contains an option to view a list of encrypted files and also files that have been permanently deleted:

The binary contains the following list of bitcoin addresses:
125RrXD8jULtcnszHZGyiESYrpns6cSe1612F9p9WWoLCN8rHtidqutBeVMxLUZns4ZB12hPkgUxCJTYE71Q1dhVGcjS2G34dMGbjq134ASGd32EBVAtJ3hyUyGMjaLi2P6sxDk1136nTvjTVgvYzDasu1ZREaVfAry4FXMiLV136UCwpSzGHd4fGsvKBvJCc9aJnWBWS3CJ13aQpBtt4n62SB7ppAFMTu5eEnyNKcJxNE13h8twBhFvZpHm6LBBzEXNiB1zv4dhR9nB13TBNzG8CLToXZ5Rh2w6v5qZBwLHyUWh8N14ediHbQw3239ruucgWdi3rUNGscZtJG5j14hgTiDfpQVHfkSFDJ1RnUF2TcEwCfgd1q14NEEhsZkKbjjMogRgQwNw6n6yhgCRHKoT14ZEt4LeJDNXqKyUpU2fP7rL9DhrfyTEwF153A5bbfuuMCAN1zdTsijvqAHAqtsx9i4f15e9J8LC1wYERpR8g2nTCq2SxEeBYTGSzP15FVgRHfKTPghYW5yvr6ZAasA3ynRLsVqB15kjcYbpRQFqYSJPCVqKoziQEWJ872ifEr168YhbnrimYPmvmsRszjGoe7tQ2Lf9RHTY16mTHRfW84GcgPYu9ffw3QY7ce2nay2NYp16PhdF7PzvQJm4JE1TgihrGXnFY6fYrbXV16tPXK8RECtq2f7ASonXqyuvrZu3hJETMs174KYmna8mp2uGebpcxiY1EfmMqfJ2sjLR17aZdtgFdNcFzk8GTbGBxmqzetFFd7crJi17C7MNabfSuB8Bv24KhduoubmHvWAT42DD17dsK4krDgLKD88yz6RTujqAxTiJhkK5a917EFPvB7cREmeUQwtvJTfEFJoYJirg1mRf17GydxtQSPiD1nYnLvJHycELA1Ag4m4iuu17xaHhbCWBUiNDRUeNJHRrCtcDRnRhCr86181BoTUFvjee5sTdNGcQ1x2craer5wQMij187MmCbFFRiHXJJoKE5GxpNL3Y2LiuGywf18p1qndKMCuLTkWsVBftDTqpCfwCzSVC8x18UP3Kz2RGRiM8jZg5S51FLBMJvhMDHop118Wy3bszLBhkzai4zWvyam1gL4pRfoDfbV18zSpqoKdz7RH7DEiRBjViLJoBMm5zFToD196iP6DmLDX7yBtiuzp1XL2HCZpMSahv5V196yWeJKua6se2dX8RBkWbTMXCH5aSMyY2198ESRJa3HwrVFV3PVu8v4LaNDM1BqN2fc19BGQoPZDcVm9XPyxWGzPDmsGvA18G5fnx19F27CTGvxid5dseiAnsC3pkytfjRiqTDJ19vwKs6QwheUhVKyaSNXbj77AS4BqpKeak1ANjzQk2EDcAH1fBwjBF6EmSWCbDZHcvzT1AQjFJkBmzpnXpAwQtZYmGVkvy7rZaHrUa1AqWpBTxFhnoVsMSUbmpxi5qrtaiDVdgMi1At2Benfw9xZ6vDGJu5NGzitJFZVLG6BiA1Atg34avReaTWD5XYsQzmEvFSSnwAiu5Fc1B7chv2YiBPV8r6dDgrq586inP5ACEBfXp1Baf76UaYEEnK1ctinDkqWpNH1n3xyeQDp1BLebicTdoHEReACDn61aTJhMErTSPrK7h1BXYp9uc3QdqCfu4n68rhLVJYgcRntqRNL1CB1vmDWqGDbF7JAQvHjG5YG4NcJHptYds1CGPZmAJ12SgH9JrbuMiQmhoZKdW28bwYw1CkX2PjEzpg6Vik9djrTSSET2FdggUqeXe1CMkZrjn37T9Sp1aVNhSGTPArc3y2mKeQ71CPWoS5Ps8HetvYUq5SnE6CPDb4e3U5tsF1EC5egdwnc8RmMthTkz5w3WoiPme6Zvyj41EkyQZbBEH473r5ipKjVuqRC6t5CWSbLrp1EmeHBDwEU22AVhZXofT2vT6gy58fWSZ461EpNNZVpGXS7JQKoTg89WBRSyJ75sQF4jT1ERmca2rgBD1vf6mFPByu3pK1T3qa9Trf81ETE54mux3p47RvcEoEXuV7zW7g5qRao2B1Evwa8QTVf4FBoNmmwsEq86LFq286pbMiA1EZvKXwq3A8qTLdDjAayo3woxDinbxfyds1F3j6KRLMayUDZgqogo9asr2F2QCve9Z4q1FEEARpkWZRmBc7fmLuNxSrvoAiNdzdjiw1FkYatSXPiwhwm8hk8FaqCNZHaosn28MJ41Fnw9g1yRz3bEnN8TGuDa6FbrU7B54Jpix1GLv8xL6mkwkcmT4Y7ovNdmQZbKSt5rtxr1GNzEneufUziU3a6fvWHRwDvPXjNgK5ua51GokYfGJLaXmSvgcdM9a4KB4nKWCs4XUvt1GouMaHURxVEwPZRiSTkNisnLJnve1syzM1HKHjRMSb3SG6eZVC9VTASZ2R3RJwCYQzY1HqaUDqhZHUgSXz2S9qEozmsRcHQeAUHQY1HWP196S4vCQxQXpngxYtfnwq146pA91BX1J4Zk3FDm9j9yhkLnsJxKt2fdpkgQw9BJK1JmuF2WpVQEiuBjKXnpV9vbqRNLCbqq6S91JR2e1oNKo5xQFBDR7MY5w39k4ZX4i17vQ1Jtt3oyRcaoKxyKkEqPL9WLFhTLBa5999D1jUPnCxxGDyZHwz2pAETQduhqwdpfsKiZ1KjkcrPW9zEofJNJtfxnFLMjmGSwmRgWuU1KvYPRtC2FH7zutpAjS4PzVcDSGgdBLZGX1L1hAUBhHat3vmjEpZP4vDk4qUoYN6j4Qf1L7DiuWwNwpBoMfHwjBs9Z3pUnsqcX7Mb1LAJTiUd5WnT4QHSoCrVJrie4a7nYAf8ko1LLEzbc6RPT9nHqyPFfW6M2TkuYtuPUsaq1M9WdD6AdtgTKwK7DDq4fP6Ag39JyowBvL1MCyw1TNf9hN69Zhi4ZkungXWJXzeEdUKa1MopVXkbxAyW9jF1y91KHsFgerA5mqeXBT1N36M1bQB3BboyRozLy4LyBtqiCGdWSj2a1N66JTDkneKZ6Y8pHLaA97ncq6uiuPJj2o1N83vL7ukSkRYFd2yxcdBFgwVSnLxQcUNN1NkrCNMXjMYaRpX7oavR5gfqRrf5mmTpQ91NNWZdjA7htVWsY8Wnobt2kY3CWePP3x4G1NtkeQY5pgcmsiRSoJrAjx3hah5dSrwxii1NVqE82oq6MAtrMasvtE49dqdesVpGGPdm1p6fKYPm98NmcQ4ySQEMRbewGhR1T8yAt1PDaTn2y3kfZojpwyTPYCDhwbZrwR8Pbqn1PGuWJPxjr3jrrTwrmFq5qSNEgBmFKEEs31PHfjxqovXd4zEaCt7rELyUAFdKTRa4SB31PNezzgm41qL9JdAJqGdumsiDssemMYUGP1xmBrLpi8uA2SVGa7ysT98itj4MuRYHcDThe UI also has a "Check Payments" button which can be used to determine if payment has been made after which files will be decrypted. It contacts btc.clockr.io which points to www.coinbase.com:


SonicWALL Gateway AntiVirus provides protection against this threat via the following signature:
Share This Article

An Article By
An Article By
Security News
Security News