Help crack Gpcode
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | 7cc9a5e0f936ed75c75ac7ce5c6ef32fff996e94c01ed301289479d8d7d708b2 | ad6f2773df8dc98b4033a3205f21c44703da73d91631c6523fe73560724 7cc9a5e0f936ed75c75ac7ce5c6ef32fff996e94c01ed301289479d8d7d708b2 c030fb79d225a7e0be2a64e5e46e8336e03e0f6ced482939fc571514b8d |
| sha256 | 9e01d088e41e0eafd85055b6f55d232749ef48cfe6fe905011c197e4ac6498c0 | 4729668fc920ee15fe0b587d1b61894d1ee15f5793c18e2d2c8cc64b053 9e01d088e41e0eafd85055b6f55d232749ef48cfe6fe905011c197e4ac6498c0 e60567819eab1471cfa4f2f4a27e3275b62d4d1bf0c79c66546782b81e9 |
| sha256 | b5f4045106b7a4b7fa6bd586c8d26dafb14b3de71ca521432d6538526f308afb | b79d225a7e0be2a64e5e46e8336e03e0f6ced482939fc571514b8d7280a b5f4045106b7a4b7fa6bd586c8d26dafb14b3de71ca521432d6538526f308afb The RSA exponent for both keys is 0x10001 (65537) . The inf |
| sha256 | c030fb79d225a7e0be2a64e5e46e8336e03e0f6ced482939fc571514b8d7280a | 5e0f936ed75c75ac7ce5c6ef32fff996e94c01ed301289479d8d7d708b2 c030fb79d225a7e0be2a64e5e46e8336e03e0f6ced482939fc571514b8d7280a b5f4045106b7a4b7fa6bd586c8d26dafb14b3de71ca521432d6538526f3 |
| sha256 | c0c21d693223d68fb573c5318982595799d2d295ed37da38be41ac8486ef900a | xchange bitlength: 1024 RSA exponent: 00010001 RSA modulus: c0c21d693223d68fb573c5318982595799d2d295ed37da38be41ac8486ef900a ee78b4729668fc920ee15fe0b587d1b61894d1ee15f5793c18e2d2c8cc6 |
| sha256 | d6046ad6f2773df8dc98b4033a3205f21c44703da73d91631c6523fe73560724 | xchange bitlength: 1024 RSA exponent: 00010001 RSA modulus: d6046ad6f2773df8dc98b4033a3205f21c44703da73d91631c6523fe73560724 7cc9a5e0f936ed75c75ac7ce5c6ef32fff996e94c01ed301289479d8d7d |
| sha256 | e60567819eab1471cfa4f2f4a27e3275b62d4d1bf0c79c66546782b81e93f85d | 088e41e0eafd85055b6f55d232749ef48cfe6fe905011c197e4ac6498c0 e60567819eab1471cfa4f2f4a27e3275b62d4d1bf0c79c66546782b81e93f85d The second is used for encryption in versions of Windows pr |
| sha256 | ee78b4729668fc920ee15fe0b587d1b61894d1ee15f5793c18e2d2c8cc64b053 | d693223d68fb573c5318982595799d2d295ed37da38be41ac8486ef900a ee78b4729668fc920ee15fe0b587d1b61894d1ee15f5793c18e2d2c8cc64b053 9e01d088e41e0eafd85055b6f55d232749ef48cfe6fe905011c197e4ac6 |
Full article393 words · extracted from securelist.com · click to collapse
If you read Vitaly’s blogpost yesterday, you’ll know that on the 4th June 2008 we detected a new variant of Gpcode, a dangerous file encryptor. Details of the encryption algorithms used by the virus are all in Vitaly’s post and the description of Gpcode.ak.
Along with antivirus companies around the world, we’re faced with the task of cracking the RSA 1024-bit key. This is a huge cryptographic challenge. We estimate it would take around 15 million modern computers, running for about a year, to crack such a key.
Of course, we don’t have that type of computing power at our disposal. This is a case where we need to work together and apply all our collective knowledge and resources to the problem.
So we’re calling on you: crytographers, governmental and scientific institutions, antivirus companies, independent researchers…join with us to stop Gpcode. This is a unique project – uniting brain-power and resources out of ethical, rather than theoretical or malicious considerations.
Here are the public keys used by the authors of Gpcode.
The first is used for encryption in Windows XP and higher.
Key type: RSA KeyExchange
bitlength: 1024
RSA exponent: 00010001
RSA modulus:
c0c21d693223d68fb573c5318982595799d2d295ed37da38be41ac8486ef900a
ee78b4729668fc920ee15fe0b587d1b61894d1ee15f5793c18e2d2c8cc64b053
9e01d088e41e0eafd85055b6f55d232749ef48cfe6fe905011c197e4ac6498c0
e60567819eab1471cfa4f2f4a27e3275b62d4d1bf0c79c66546782b81e93f85d
The second is used for encryption in versions of Windows prior to XP.
Key type: RSA KeyExchange
bitlength: 1024
RSA exponent: 00010001
RSA modulus:
d6046ad6f2773df8dc98b4033a3205f21c44703da73d91631c6523fe73560724
7cc9a5e0f936ed75c75ac7ce5c6ef32fff996e94c01ed301289479d8d7d708b2
c030fb79d225a7e0be2a64e5e46e8336e03e0f6ced482939fc571514b8d7280a
b5f4045106b7a4b7fa6bd586c8d26dafb14b3de71ca521432d6538526f308afb
The RSA exponent for both keys is 0x10001 (65537).
The information above is sufficient to start factoring the key. A specially created utility could be of great help in factoring.
We’re happy to provide additional information to anyone involved in stopping Gpcode. To keep everyone up to date, we’ve set up a dedicated forum.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/help-crack-gpcode/30425/