Infection Channel: Downloaded from the Internet, Dropped by other malware
This police ransomware locks the infected system and urges users to pay verbally via its WAVE file.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

For the related story, you may read the blog post Latest on Police Ransomware - It Speaks!
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It connects to a website to send and receive information.
File size: 282,624 bytes
File type: DLL
Memory resident: Yes
Initial samples received date: 26 Nov 2012
Payload: Displays graphics, Downloads files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following component file(s):
- %System Root%\Documents And Settings\All Users\Application Data\lsass.exe
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It injects itself into the following processes as part of its memory residency routine:
- IEXPLORE.EXE
- IESTART.EXE
- FIREFOX.EXE
- OPERA.EXE
- CHROME.EXE
Autostart Technique
This Trojan drops the following file(s) in the Windows User Startup folder to enable its automatic execution at every system startup:
- %User Startup%\ctfmon.lnk
(Note: %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
Other System Modifications
This Trojan adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\0
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\1
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\2
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\3
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\4
2500 = "3"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
NoProtectedModeBanner = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
NoProtectedModeBanner = "1"
It modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\0
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\1
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\2
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\3
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Zones\4
1609 = "0"
(Note: The default value data of the said registry entry is 1.)
Backdoor Routine
This Trojan connects to the following websites to send and receive information:
NOTES:
It downloads an encrypted file and saves it to the infected system as %System Root%\Documents And Settings\All Users\Application Data\{reversed filename}.pad.
This encrypted file contains a .DLL file and WAVE file when decrypted. The contents of the encrypted file may vary depending on the remote server.
The said .DLL file contains a lock screen image while the WAVE file contains the audio which urges users to pay verbally.
Once the malware is executed, It locks the user's system and displays the following screen where a fake FBI message is displayed.

To unlock the system, the user is forced to pay 100 GBP via Ukash or Paysafecard.
Connect with us on
| | | |