Author Topic: EvilZone makes Fortinet News  (Read 1108 times)

0 Members and 2 Guests are viewing this topic.

Offline chris_kzn

  • Serf
  • *
  • Posts: 25
  • Cookies: 2
    • View Profile
EvilZone makes Fortinet News
« on: December 08, 2015, 08:42:47 pm »

Offline 0E 800

  • Not a VIP
  • VIP
  • Baron
  • *
  • Posts: 895
  • Cookies: 131
  • • тнε ιηтεяηεт ιs мү яεcүcℓε-вιη •
    • View Profile
Re: EvilZone makes Fortinet News
« Reply #1 on: December 08, 2015, 09:34:24 pm »
More specifically:


Who is behind Encryptor RaaS?

The TOR- and Bitcoin-based operation of Encryptor RaaS makes it hard to track the author behind this ransomware. On top of that, the author uses the dark web mail service SIGAINT to talk to clients.

We found that a thread was created in the forum evilzone.org regarding our previous Encryptor RaaS post. A user with the handle jeiphoos has replied to the thread and identified himself as the author of Encryptor RaaS. One of his replies to the thread suggests that he has been or is around many German-speaking people:

Figure 7. Forum post of jeiphoos on evilzone.org

Additionally, his forum profile shows that his local timezone is Central European Time, which is Germany's timezone. Therefore, it is possible that the author is located in Germany or in one of the countries under the CET timezone.
The invariable mark of wisdom is to see the miraculous in the common.

Offline KOR

  • Serf
  • *
  • Posts: 23
  • Cookies: -3
    • View Profile
Re: EvilZone makes Fortinet News
« Reply #2 on: December 12, 2015, 08:20:47 pm »
Well, this is interesting. RaaS as a new platform for affiliates? That's the last time I click a link that says I've been referred by a friend.

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: EvilZone makes Fortinet News
« Reply #3 on: December 12, 2015, 08:46:48 pm »
I love how queery is in the screenshot xD
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline jeiphoos

  • NULL
  • Posts: 4
  • Cookies: 2
    • View Profile
Re: EvilZone makes Fortinet News
« Reply #4 on: December 20, 2015, 03:40:03 am »
Quote
Hello Roland,

First, my RaaS isn't written in Java. The references to
"libgcj.dll"/"libgcj-12.dll" are even included when Java support isn't
compiled into MingW GCC.

Second, the filenames 'wallet.dat' and 'electrum.dat' aren't exempted from
the encryption. What it's actually doing is a homework for you.

Third, CET is the default timezone on the evilzone.org board. I just
didn't felt to change it, so I left it to it's default value.

Fourth, as it seems, that you weren't able to find out which encryption
algorithm I'm using, it's RC6.


Kind regards,
jeiphoos

PS:
Can you ask someone at Microsoft, why they've called my RaaS "Sarento"?




That's what I wrote him, he didn't answered it by now.
Apparently he hates to be reminded on his mistakes.

PS:
CET were at least shown to me as the default timezone.