Welcome to the Computer Security Wiki! You can help us by expanding stubs, create new articles and improve current articles.
You can also help us by logging-in or creating an account!

Rensenware

From Malware Wiki
Jump to: navigation, search
Rensenware
Rensenware.png
TypeRansomware
Creator0x00000FF
DateApril 6th, 2017
OriginSouth Korea
Programming LanguageC#
PlatformMicrosoft Windows
File Type*Win32/64 executable (.EXE)
MD560335edf459643a87168da8ed74c2b60
SHA-161f3e01174a6557f9c0bfc89ae682d37a7e91e2e
SHA-2567bf5623f0a10dfa148a35bebd899b7758612f1693d2a9910f716cf15a921a76a
SSDEEP3072:kGXc7vE4k8sWJnmiWpJtCkGwJ1ED7qztG:RXD8sWBmiW0wX6Gx
Authentihash04842590634775ed2ac35a92e4ea78752963b25848183e3420e971ddb61c2c76
IMPhashf34d5f2d4577ed6d9ceec516c1f5a744
This box: view  talk  edit

Rensenware is a ransomware trojan on Microsoft Windows. It shows a picture of Minamitsu Murasa which is an official artwork from the game and a message which tells the user to play Touhou 12: Unidentified Fantastic Object to get the user's files back. The user will need to find the game separately, as because the ransomware does not come with it.

The developer has said that his computer had also been infected during the development. He did not reach a score of 200 million points due to the difficulty of the game, and he uploaded a patch for file decryption and updated the code in GitHub by removing the ransom part but keeping the rest.

Payload

This ransomware will encrypt all the files in the computer when the ransomware is executed. After the files are encrypted, the ransomware will display an uncloseable message with the instructions.

This ransomware will crash if it finds some files that cannot be encrypted.

This ransomware does not ask for a certain amount of bitcoins, but rather that the user play Touhou 12: Undefined Fantastic Object in Lunatic difficulty and reach 200 million points to decrypt the data.

This ransomware does not have an encryption key.

References

Media

File:Trojan.Ransom.Rensenware
Trojan.Ransom.Rensenware

zh:Rensenware es:RensenWare