Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FTcode targets European countries... one perform the register action as new client to infect with the ransomware. The second use in more stealer actions by NET class... Unfortunately, this group can let several hours or days before drops the ransomware payload... it's impossible to study the last part the ransomware ftcode... Compared to the analysis in early January 2020, the Threat Actor added the password dump for IE and Outlook at their script.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
$task = ( schtasks . exe / create / TN "WindowsApplicationService" / sc DAILY / st 00 : 00 / f / RI 14 / du 23 : 59 / TR $ path_vbs )
It also creates a scheduled task named WindowsApplicationService for executing the WindowsIndexingService.vbs file.
CreateObject( "WScript.Shell" ).Run Data, Mod ... iex ( [ string ] [ System . Text . Encoding ] :: ASCII . GetString ( [ System . Convert ] :: FromBase64String ... ))
Recently, the Zscaler ThreatLabZ team came across PowerShell-based ransomware called “FTCODE,” which targets Italian-language users.
The downloaded script is saved in %Public%\Libraries\WindowsIndexingService.vbs . | In the recent campaign, the ransomware is being downloaded using VBScript. Once a user executes the VBScript, it executes the PowerShell script shown in the screenshot below.
Execution through API ... [ System . Security . Cryptography . ProtectedData ] : : Unprotect ... LoadLibrary ... GetProcAddress
$task = ( schtasks . exe / create / TN "WindowsApplicationService" / sc DAILY / st 00 : 00 / f / RI 14 / du 23 : 59 / TR $ path_vbs )
$task = ( schtasks . exe / create / TN "WindowsApplicationService" / sc DAILY / st 00 : 00 / f / RI 14 / du 23 : 59 / TR $ path_vbs )
With the obfuscated Javascript and VB Script samples... The JS Stage includes a few unused variables, entangled functions and scrambled strings.
The script first downloads a decoy image into the %temp% folder and opens it trying to trick users into believing that they simply received an image, but in the background, it downloads and runs the ransomware.
The first variant use regular expression (regex) for parse each lines, the result is merged for be the command to execute... The second VBS use too a regex for parse each line...
The next functionalities are for dumping the credential from the differents versions of Outlook, this check for the IMAP, SMTP and POP3 credentials and configuration. | A second variant of the code use an additional class in .NET for stealing the credentials... The next section of code defines the function for decode the passwords from Chrome browser... dumping the credential from the differents versions of Outlook... IE use vault systems...
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based ransomware targeting Italian-language users. It is delivered via malicious macro documents and later via VBScript downloaders, establishes persistence, communicates with C2, encrypts files using Rijndael with generated keys, drops a ransom note, and newer versions also steal credentials from browsers and email clients including Internet Explorer, Firefox, Thunderbird, Chrome, and Outlook.
A PowerShell-based ransomware family that appends the .FTCODE extension to encrypted files, drops HTML ransom notes, and disables recovery mode while deleting backups and shadow copies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.