Technical Analysis of PartyTicket Ransomware
ID: c927cbac-349d-5e54-b648-cb3617ffcea3
STIX ID: report--c927cbac-349d-5e54-b648-cb3617ffcea3
Feed Name: Zscaler Security Research Blog
This report analyzes PartyTicket, an unsophisticated Go-based ransomware observed alongside the Hermetic Wiper targeting Ukrainian organizations; it enumerates targeted file extensions, explains the file encryption format (AES-GCM with a deterministic 32-character key wrapped by a hardcoded RSA public key), highlights design flaws that allow recovery of the AES key (use of Go's non-cryptographic RNG), documents operational behavior (creates many timestamp/MAC-based UUID-named copies, skips System/Program Files, appends a distinct marker, and leaves a read_me.html ransom note), and notes Zscaler detection coverage for the payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
