{"id":47408,"date":"2022-07-06T00:00:00","date_gmt":"2022-07-06T00:00:00","guid":{"rendered":"urn:uuid:81e7d466-1f8b-9888-f8d2-1783c574eba4"},"modified":"2022-07-06T00:00:00","modified_gmt":"2022-07-06T00:00:00","slug":"brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/","title":{"rendered":"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/HavanaCrypt_641.jpg\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <!-- Begin mPulse library --> <!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"endpoints,ransomware,research,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2022-07-06\"> <meta property=\"article:tag\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html\"> <title>Brand-New HavanaCrypt Ransomware Poses as Google Software Update App Uses Microsoft Hosting Service IP Address as C&amp;C Server<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html\"><br \/>\n<meta property=\"og:title\" content=\"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App Uses Microsoft Hosting Service IP Address as C&amp;C Server\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/HavanaCrypt_641.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App Uses Microsoft Hosting Service IP Address as C&amp;C Server\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/HavanaCrypt_641.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"51.088997897687\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1242071363\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"11.805755395683\">\n<div class=\"article-details\" role=\"heading\" readability=\"43.287769784173\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__description\">We recently found a new ransomware family, which we have dubbed as HavanaCrypt, that disguises itself as a legitimate Google Software Update application and uses a Microsoft web hosting service IP address as its command-and-control (C&amp;C) server to circumvent detection. <\/p>\n<p class=\"article-details__author-by\">By: Nathaniel Morales, Monte de Jesus, Ivan Nicole Chavez, Bren Matthew Ebriega, Joshua Paul Ignacio <time class=\"article-details__date\">July 06, 2022<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"43.413815364751\">\n<div readability=\"37.082633957392\">\n<p><a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/ransomware\">Ransomware<\/a> is not at all novel, but it continues to be one of the top cyberthreats in the world today. In fact, according to data from Trend Micro\u2122 Smart Protection Network\u2122, we detected and blocked <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-by-the-numbers\/lockbit-conti-and-blackcat-lead-pack-amid-rise-in-active-raas-and-extortion-groups-ransomware-in-q1-2022\">more than 4.4 million ransomware threats<\/a> across email, URL, and file layers in the first quarter of 2022 \u2014 a 37% increase in overall ransomware threats from the fourth quarter of 2021.<\/p>\n<p>Ransomware\u2019s pervasiveness is rooted in its being evolutionary: It employs ever-changing tactics and schemes to deceive unwitting victims and successfully infiltrate environments. For example, this year, there have been reports of ransomware being distributed as <a href=\"https:\/\/www.techradar.com\/news\/these-fake-windows-10-updates-will-land-you-with-a-ransomware-infection\">fake Windows 10<\/a>, <a href=\"https:\/\/tech.co\/news\/fake-chrome-microsoft-edge-update-ransomware\">Google Chrome, and Microsoft Exchange updates<\/a> to fool potential victims into downloading malicious files.<\/p>\n<p>Recently, we found a brand-new ransomware family that employs a similar scheme: It disguises itself as a legitimate Google Software Update application and uses a Microsoft web hosting service IP address as its command-and-control (C&amp;C) server to circumvent detection. Our investigation also shows that this ransomware uses the <a href=\"https:\/\/docs.microsoft.com\/en-us\/dotnet\/api\/system.threading.threadpool.queueuserworkitem?view=net-6.0#system-threading-threadpool-queueuserworkitem(system-threading-waitcallback)\">QueueUserWorkItem<\/a> function, a .NET System.Threading namespace method that queues a method for execution, and the modules of <a href=\"https:\/\/keepass.info\/\">KeePass Password Safe<\/a>, an open-source password manager, during its file encryption routine.<\/p>\n<p>In this blog entry, we provide an in-depth technical analysis of the infection techniques of this new ransomware family, which we have dubbed HavanaCrypt.<\/p>\n<p>HavanaCrypt arrives as a fake Google Software Update application.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig1_HavanaCrypt%20Ransomware.png\" alt=\"The file description of the binary file of HavanaCrypt\"><figcaption>Figure 1. The file description of the binary file of HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"30.08\">\n<div readability=\"8.46\">\n<p>This malware is a .NET-compiled application and is protected by <a href=\"https:\/\/github.com\/obfuscar\/obfuscar\">Obfuscar,<\/a> an open-source .NET obfuscator used to help secure codes in a .NET assembly.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%202_HavanaCrypt%20Ransomware.png\" alt=\"The properties of the binary file of HavanaCrypt as shown in the Detect It Easy tool, a program used to determine file types\"><figcaption>Figure 2. The properties of the binary file of HavanaCrypt as shown in the Detect It Easy tool, a program used to determine file types<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"30.287234042553\">\n<div readability=\"9.3191489361702\">\n<p>The malware also has multiple anti-virtualization techniques that help it avoid dynamic analysis when executed in a virtual machine. To analyze the sample and generate the deobfuscated code, we used tools such as <a href=\"https:\/\/github.com\/de4dot\/de4dot\">de4dot<\/a> and <a href=\"https:\/\/github.com\/DarkObb\/DeObfuscar-Static\">DeObfuscar<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%203_HavanaCrypt%20Ransomware.png\" alt=\"An obfuscated HavanaCrypt ransomware code sample\"><figcaption>Figure 3. An obfuscated HavanaCrypt ransomware code sample<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%204_HavanaCrypt%20Ransomware.png\" alt=\"A deobfuscated HavanaCrypt ransomware code sample\"><figcaption>Figure 4. A deobfuscated HavanaCrypt ransomware code sample<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>Upon execution, HavanaCrypt hides its window by using the ShowWindow function with parameter 0 (SW_HIDE)<i>.<\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%205_HavanaCrypt%20Ransomware.png\" alt=\"The ShowWindow function as it is used by HavanaCrypt\"><figcaption>Figure 5. The ShowWindow function as it is used by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>HavanaCrypt then checks the AutoRun registry to see whether the \u201cGoogleUpdate\u201d registry is present. If the registry is not present, the malware continues with its malicious routine.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%206A_HavanaCrypt%20Ransomware.png\" alt=\"The function containing the parameters used by HavanaCrypt in checking the registry key\"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%206B_HavanaCrypt%20Ransomware.png\" alt=\"The function containing the parameters used by HavanaCrypt in checking the registry key\"><figcaption>Figure 6. The function containing the parameters used by HavanaCrypt in checking the registry key<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>It then proceeds with its anti-virtualization routine, where it terminates itself if the system is found running in a virtual machine environment.<\/p>\n<p>HavanaCrypt has four stages of checking whether the infected machine is running in a virtualized environment.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%207_HavanaCrypt%20Ransomware.png\" alt=\"The function used by HavanaCrypt to implement its antivirtualization mechanism.\"><figcaption>Figure 7. The function used by HavanaCrypt to implement its antivirtualization mechanism.<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%208_HavanaCrypt%20Ransomware.png\" alt=\"The entire antivirtualization routine of HavanaCrypt\"><figcaption>Figure 8. The entire antivirtualization routine of HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%209A_HavanaCrypt%20Ransomware.png\" alt=\"The services being checked by HavanaCrypt\"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%209B_HavanaCrypt%20Ransomware.png\" alt=\"The services being checked by HavanaCrypt\"><figcaption>Figure 9. The services being checked by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>Second, it checks for the usual files that are related to virtual machine applications.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2010A_HavanaCrypt%20Ransomware.png\" alt=\"The virtual machine files being checked by HavanaCrypt\"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2010B_HavanaCrypt%20Ransomware.png\" alt=\"The virtual machine files being checked by HavanaCrypt\"><figcaption>Figure 10. The virtual machine files being checked by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>Third, it checks for file names used by virtual machines for their executables.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2011A_HavanaCrypt%20Ransomware.png\" alt=\"The virtual machine executables being checked by HavanaCrypt \"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2011B_HavanaCrypt%20Ransomware.png\" alt=\"The virtual machine executables being checked by HavanaCrypt \"><figcaption>Figure 11. The virtual machine executables being checked by HavanaCrypt <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>Last, it checks the machine\u2019s MAC address and compares it to organizationally unique identifier (OUI) prefixes that are typically used by virtual machines.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2012A_HavanaCrypt%20Ransomware.png\" alt=\"The OUI prefixes being checked by HavanaCrypt\"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2012B_HavanaCrypt%20Ransomware.png\" alt=\"The OUI prefixes being checked by HavanaCrypt\"><figcaption>Figure 12. The OUI prefixes being checked by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div class=\"responsive-table-wrap\" readability=\"14\">\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"5\">\n<tr>\n<td>Range or prefix<\/td>\n<td>Product<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>00:05:69<\/td>\n<td>VMware ESX and VMware GSX Server<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>00:0C:29<\/td>\n<td>Standalone VMware vSphere, VMware Workstation, and VMware Horizon<\/td>\n<\/tr>\n<tr>\n<td>00:1C:14<\/td>\n<td>VMWare<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>00:50:56<\/td>\n<td>VMware vSphere, VMware Workstation, and VMware ESX Server<\/td>\n<\/tr>\n<tr>\n<td>08:00:27<\/td>\n<td>Oracle VirtualBox 5.2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Table 1. Virtual machines\u2019 OUI ranges or prefixes<\/p>\n<p>After verifying that the victim machine is not running in a virtual machine, HavanaCrypt downloads a file named \u201c2.txt\u201d from 20[.]227[.]128[.]33,<b> <\/b>a Microsoft web hosting service IP address,<b> <\/b>and saves it as a batch (.bat) file with a file name containing between 20 and 25 random characters.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2013_HavanaCrypt%20Ransomware.png\" alt=\"The details of the Microsoft web hosting service IP address\"><figcaption>Figure 13. The details of the Microsoft web hosting service IP address<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.979381443299\">\n<div readability=\"10.659793814433\">\n<p>(Image source: <a href=\"http:\/\/www.AbuseIPDB\">AbuseIPDB<\/a>)<\/p>\n<p>It then proceeds to execute the batch file using cmd.exe with a \u201c\/c start\u201d parameter. The batch file contains commands that are used to configure Windows Defender scan preferences to allow any detected threat in the \u201c%Windows%\u201d and \u201c%User%\u201d directories.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2014_HavanaCrypt%20Ransomware.png\" alt=\"The function that contains the downloading and execution of the batch file\"><figcaption>Figure 14. The function that contains the downloading and execution of the batch file<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2015_HavanaCrypt%20Ransomware.png\" alt=\"The Base64-encoded 2.txt file as seen on the Microsoft web hosting service IP address\"><figcaption>Figure 15. The Base64-encoded 2.txt file as seen on the Microsoft web hosting service IP address<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2016_HavanaCrypt%20Ransomware.png\" alt=\"The decoded batch file downloaded from the Microsoft web hosting service IP address\"><figcaption>Figure 16. The decoded batch file downloaded from the Microsoft web hosting service IP address<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>HavanaCrypt also terminates certain processes that are found running in the machine:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">agntsvc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">axlbridge<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ccevtmgr<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ccsetmgr<\/span><\/li>\n<li><span class=\"rte-red-bullet\">contoso1<\/span><\/li>\n<li><span class=\"rte-red-bullet\">culserver<\/span><\/li>\n<li><span class=\"rte-red-bullet\">culture<\/span><\/li>\n<li><span class=\"rte-red-bullet\">dbeng50<\/span><\/li>\n<li><span class=\"rte-red-bullet\">dbeng8<\/span><\/li>\n<li><span class=\"rte-red-bullet\">dbsnmp<\/span><\/li>\n<li><span class=\"rte-red-bullet\">dbsrv12<\/span><\/li>\n<li><span class=\"rte-red-bullet\">defwatch<\/span><\/li>\n<li><span class=\"rte-red-bullet\">encsvc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">excel<\/span><\/li>\n<li><span class=\"rte-red-bullet\">fdlauncher<\/span><\/li>\n<li><span class=\"rte-red-bullet\">firefoxconfig<\/span><\/li>\n<li><span class=\"rte-red-bullet\">httpd<\/span><\/li>\n<li><span class=\"rte-red-bullet\">infopath<\/span><\/li>\n<li><span class=\"rte-red-bullet\">isqlplussvc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">msaccess<\/span><\/li>\n<li><span class=\"rte-red-bullet\">msdtc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">msdtsrvr<\/span><\/li>\n<li><span class=\"rte-red-bullet\">msftesql<\/span><\/li>\n<li><span class=\"rte-red-bullet\">msmdsrv<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mspub<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mssql<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mssqlserver<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mydesktopqos<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mydesktopservice<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mysqld<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mysqld-nt<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mysqld-opt<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ocautoupds<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ocomm<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ocssd<\/span><\/li>\n<li><span class=\"rte-red-bullet\">onenote<\/span><\/li>\n<li><span class=\"rte-red-bullet\">oracle<\/span><\/li>\n<li><span class=\"rte-red-bullet\">outlook<\/span><\/li>\n<li><span class=\"rte-red-bullet\">powerpnt<\/span><\/li>\n<li><span class=\"rte-red-bullet\">qbcfmonitorservice<\/span><\/li>\n<li><span class=\"rte-red-bullet\">qbdbmgr<\/span><\/li>\n<li><span class=\"rte-red-bullet\">qbidpservice<\/span><\/li>\n<li><span class=\"rte-red-bullet\">qbupdate<\/span><\/li>\n<li><span class=\"rte-red-bullet\">qbw32<\/span><\/li>\n<li><span class=\"rte-red-bullet\">quickboooks.fcs<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ragui<\/span><\/li>\n<li><span class=\"rte-red-bullet\">rtvscan<\/span><\/li>\n<li><span class=\"rte-red-bullet\">savroam<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqbcoreservice<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqladhlp<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqlagent<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqlbrowser<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqlserv<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqlserveragent<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqlservr<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sqlwriter<\/span><\/li>\n<li><span class=\"rte-red-bullet\">steam<\/span><\/li>\n<li><span class=\"rte-red-bullet\">supervise<\/span><\/li>\n<li><span class=\"rte-red-bullet\">synctime<\/span><\/li>\n<li><span class=\"rte-red-bullet\">tbirdconfig<\/span><\/li>\n<li><span class=\"rte-red-bullet\">thebat<\/span><\/li>\n<li><span class=\"rte-red-bullet\">thebat64<\/span><\/li>\n<li><span class=\"rte-red-bullet\">thunderbird<\/span><\/li>\n<li><span class=\"rte-red-bullet\">tomcat6<\/span><\/li>\n<li><span class=\"rte-red-bullet\">vds<\/span><\/li>\n<li><span class=\"rte-red-bullet\">visio<\/span><\/li>\n<li><span class=\"rte-red-bullet\">vmware-converter<\/span><\/li>\n<li><span class=\"rte-red-bullet\">vmware-usbarbitator64<\/span><\/li>\n<li><span class=\"rte-red-bullet\">winword<\/span><\/li>\n<li><span class=\"rte-red-bullet\">word<\/span><\/li>\n<li><span class=\"rte-red-bullet\">wordpad<\/span><\/li>\n<li><span class=\"rte-red-bullet\">wrapper<\/span><\/li>\n<li><span class=\"rte-red-bullet\">wxserver<\/span><\/li>\n<li><span class=\"rte-red-bullet\">wxserverview<\/span><\/li>\n<li><span class=\"rte-red-bullet\">xfssvccon<\/span><\/li>\n<li><span class=\"rte-red-bullet\">zhudongfangyu<\/span><\/li>\n<li><span class=\"rte-red-bullet\">zhundongfangyu<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2017_HavanaCrypt%20Ransomware.png\" alt=\"The processes that HavanaCrypt terminates\"><figcaption>Figure 17. The processes that HavanaCrypt terminates<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>It should be noted that this list includes processes that are part of database-related applications, such as Microsoft SQL Server and MySQL. Desktop apps such as Microsoft Office and Steam are also terminated.<\/p>\n<p>After it terminates all relevant processes, HavanaCrypt queries all available disk drives and proceeds to delete the shadow copies and resize the maximum amount of storage space to 401 MB.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2018_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt deleting shadow copies and resizing the maximum storage space of available drives to 401 MB\"><figcaption>Figure 18. HavanaCrypt deleting shadow copies and resizing the maximum storage space of available drives to 401 MB<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>It also checks for system restore instances via Windows Management Instrumentation (WMI) and proceeds to delete them by using the<b> <\/b>SRRemoveRestorePoint function.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2019_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt deleting system restore instances via WMI\"><figcaption>Figure 19. HavanaCrypt deleting system restore instances via WMI<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>It then drops copies of itself in the %ProgramData% and %StartUp% folders in the form of executable (.exe) files with different file names containing between 10 and 15 random characters. Their attributes are then set to \u201cHidden\u201d and \u201cSystem File.\u201d<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2020_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt dropping copies of itself in the %ProgramData% and %StartUp% folders\"><figcaption>Figure 20. HavanaCrypt dropping copies of itself in the %ProgramData% and %StartUp% folders<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2021_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt setting the dropped files as \u201cHidden\u201d and \u201cSystem File\u201d\"><figcaption>Figure 21. HavanaCrypt setting the dropped files as \u201cHidden\u201d and \u201cSystem File\u201d<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>HavanaCrypt also drops a file named \u201cvallo.bat\u201d onto %User Startup%<i>,<\/i> which contains functions that can disable the Task Manager.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2022_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt dropping vallo.bat onto %User Startup%\"><figcaption>Figure 22. HavanaCrypt dropping vallo.bat onto %User Startup%<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2023_HavanaCrypt%20Ransomware.png\" alt=\"The content of vallo.bat\"><figcaption>Figure 23. The content of vallo.bat<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>HavanaCrypt uses the QueueUserWorkItem function to implement thread pooling for its other payloads and encryption threads. This function is used to execute a task when a thread pool becomes available.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2024_HavanaCrypt%20Ransomware.png\" alt=\"The QueueUserWorkItem function as it is used by HavanaCrypt\"><figcaption>Figure 24. The QueueUserWorkItem function as it is used by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>It also uses the DebuggerStepThrough attribute, which causes it to step through the code during debugging instead of stepping into it. This attribute must be removed before one can analyze the function inside.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2025_HavanaCrypt%20Ransomware.png\" alt=\"The DebuggerStepThrough attribute as it is used by HavanaCrypt\"><figcaption>Figure 25. The DebuggerStepThrough attribute as it is used by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"37.5\">\n<div readability=\"20\">\n<p>Before it proceeds with its encryption routine, HavanaCrypt gathers certain pieces of information and sends them to its C&amp;C server, 20[.]227[.]128[.]33\/index.php. These are the unique identifier (UID) and the token and date.<\/p>\n<h2><span class=\"body-subhead-title\">UID<\/span><i><\/i><\/h2>\n<p>The UID contains the machine\u2019s system fingerprint. HavanaCrypt gathers pieces of machine information and combines them, by appending one to another, before converting the information into its SHA-256 hash in the format:<\/p>\n<p><span class=\"blockquote\">[{Number of Cores}{ProcessorID}{Name}{SocketDesignation}] BIOS Information [{Manufacturer}{BIOS Name}{Version}] Baseboard Information [{Name}]<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2026_HavanaCrypt%20Ransomware.png\" alt=\"The function used by HavanaCrypt to gather machine information\"><figcaption>Figure 26. The function used by HavanaCrypt to gather machine information<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2027_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt converting its gathered machine information into a SHA-256 hash\"><figcaption>Figure 27. HavanaCrypt converting its gathered machine information into a SHA-256 hash<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>The pieces of machine information that HavanaCrypt gathers include:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">The number of processor cores<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The processor ID<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The processor name<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The socket designation<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The motherboard manufacturer<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The motherboard name<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The BIOS version<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The product number<\/span><\/li>\n<\/ul>\n<h2><span class=\"body-subhead-title\">Token and date<\/span><i><\/i><\/h2>\n<p>HavanaCrypt &nbsp;replaces the string \u201cindex.php\u201d with \u201cham.php\u201d to send a GET<b> <\/b>request to its C&amp;C server (hxxp[:]\/\/20[.]227[.]128[.]33\/ham.php) using \u201cHavana\/1.0\u201d as the user agent.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2028A_HavanaCrypt%20Ransomware.png\" alt=\"The function used by HavanaCrypt to send a GET request to its C&amp;C server \"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2028B_HavanaCrypt%20Ransomware.png\" alt=\"The function used by HavanaCrypt to send a GET request to its C&amp;C server \"><figcaption>Figure 28. The function used by HavanaCrypt to send a GET request to its C&amp;C server <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2029_HavanaCrypt%20Ransomware.png\" alt=\"The response from 20[.]227[.]128[.]33\/ham.php that we obtained via Fiddler, a web application debugging tool\"><figcaption>Figure 29. The response from 20[.]227[.]128[.]33\/ham.php that we obtained via Fiddler, a web application debugging tool<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>HavanaCrypt decodes the response from ham.php in Base64 and decrypts it via the AES decryption algorithm using these parameters:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Aes.key: d8045c7174c2649e96e68a01a5d77f7dec4846ebebb7ed04fa8b1325c14d84b0 (SHA-256 of \u201cHOLAKiiaa##~~@#!2100\u201d)<b><\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\">Aes.IV: consists of 16 sets of 00 bytes<\/span><\/li>\n<\/ul>\n<p>HavanaCrypt then stores the output in two different arrays with \u201c\u2013\u201d as their delimiter. The first array is used as the token, while the second is used as the date.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2030_HavanaCrypt%20Ransomware.png\" alt=\"The initialization of parameters to be used by HavanaCrypt in AES decryption\"><figcaption>Figure 30. The initialization of parameters to be used by HavanaCrypt in AES decryption<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2031_HavanaCrypt%20Ransomware.png\" alt=\"Decryption by HavanaCrypt via AES\"><figcaption>Figure 31. Decryption by HavanaCrypt via AES<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.685236768802\">\n<div readability=\"9.7493036211699\">\n<p>Using <a href=\"https:\/\/gchq.github.io\/CyberChef\/\">CyberChef<\/a>, a web app that provides operations such as encoding and encryption, we replicated HavanaCrypt\u2019s decryption routine using the response from 20[.]227[.]128[.]33\/ham.php:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Output: d388ed2139d0703b7c2a810b09e513652eb9402c92304addd34679e21a826537-1655449622<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Token: d388ed2139d0703b7c2a810b09e513652eb9402c92304addd34679e21a826537<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Date: 1655449622<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2032_HavanaCrypt%20Ransomware.png\" alt=\"Our replication of HavanaCrypt\u2019s decryption routine using the CyberChef app\"><figcaption>Figure 32. Our replication of HavanaCrypt\u2019s decryption routine using the CyberChef app<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>After gathering all the necessary machine information, HavanaCrypt sends it via a POST<b> <\/b>request to hxxp:\/\/20[.]227[.]128[.]33\/index.php using \u201cHavana\/1.0\u201d as the user agent.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2033_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt\u2019s POST request to hxxp[:]20[.]227[.]128[.]33\/index[.]php that we obtained using Fiddler\"><figcaption>Figure 33. HavanaCrypt\u2019s POST request to hxxp[:]20[.]227[.]128[.]33\/index[.]php that we obtained using Fiddler<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>If the request is successful, HavanaCrypt receives a response that contains the encryption key, the secret key, and other details.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2034_HavanaCrypt%20Ransomware.png\" alt=\"The response from hxxp[:]20[.]227[.]128[.]33\/index[.]php that we obtained using Fiddler\"><figcaption>Figure 34. The response from hxxp[:]20[.]227[.]128[.]33\/index[.]php that we obtained using Fiddler<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>HavanaCrypt checks whether hava.info is already present in \u201c%AppDataLocal%\/Google\/Google Software Update\/1.0.0.0\u201d. If it does not find the file, it drops the hava.info file, which contains the RSA key generated by HavanaCrypt using the RSACryptoServiceProvider function.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2035_HavanaCrypt%20Ransomware.png\" alt=\"The contents of hava.info that we obtained using HIEW, a console hex editor\"><figcaption>Figure 35. The contents of hava.info that we obtained using HIEW, a console hex editor<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2036_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt\u2019s generation of an RSA key using the RSACryptoServiceProvider function\"><figcaption>Figure 36. HavanaCrypt\u2019s generation of an RSA key using the RSACryptoServiceProvider function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.401812688822\">\n<div readability=\"10.800604229607\">\n<p>We have observed that HavanaCrypt uses KeePass Password Safe modules during its encryption routine. In particular, it uses the CryptoRandom function to generate random keys needed for encryption. The similarity between the function used by HavanaCrypt and the KeePass Password Safe module from <a href=\"https:\/\/github.com\/aramrami\/KeePass-2.41\/blob\/master\/KeePassLib\/Cryptography\/CryptoRandom.cs\">GitHub<\/a> is evident.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2037_HavanaCrypt%20Ransomware.png\" alt=\"The functions used by HavanaCrypt in generating random bytes\"><figcaption>Figure 37. The functions used by HavanaCrypt in generating random bytes<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2038_HavanaCrypt%20Ransomware.png\" alt=\"A snippet of KeePass Password Safe\u2019s code from GitHub\"><figcaption>Figure 38. A snippet of KeePass Password Safe\u2019s code from GitHub<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>HavanaCrypt encrypts files and appends \u201c.Havana\u201d as a file name extension.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2039_HavanaCrypt%20Ransomware.png\" alt=\"HavanaCrypt\u2019s encryption routine\"><figcaption>Figure 39. HavanaCrypt\u2019s encryption routine<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>It avoids encrypting files with certain extensions, including files that already have the appended \u201c.Havana\u201d extension.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2040_HavanaCrypt%20Ransomware.png\" alt=\"The function used by HavanaCrypt to avoid certain file name extensions\"><figcaption>Figure 40. The function used by HavanaCrypt to avoid certain file name extensions<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2041_HavanaCrypt%20Ransomware.png\" alt=\"The file name extensions files of which HavanaCrypt avoids encrypting \"><figcaption>Figure 41. The file name extensions files of which HavanaCrypt avoids encrypting <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>HavanaCrypt also avoids encrypting files found in certain directories.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2042_HavanaCrypt%20Ransomware.png\" alt=\"The directories in which HavanaCrypt avoids encrypting files\"><figcaption>Figure 42. The directories in which HavanaCrypt avoids encrypting files<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2043_HavanaCrypt%20Ransomware.png\" alt=\"The function used by HavanaCrypt to avoid certain directories\"><figcaption>Figure 43. The function used by HavanaCrypt to avoid certain directories<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2044_HavanaCrypt%20Ransomware.png\" alt=\"Some files encrypted by HavanaCrypt\"><figcaption>Figure 44. Some files encrypted by HavanaCrypt<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>During encryption, HavanaCrypt creates a text file called \u201cfoo.txt\u201d, which logs all the directories containing the encrypted files.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/Fig%2045_HavanaCrypt%20Ransomware.png\" alt=\"The foo.txt text file that contains logs of directories that contain encrypted files \"><figcaption>Figure 45. The foo.txt text file that contains logs of directories that contain encrypted files <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"42\">\n<div class=\"responsive-table-wrap\" readability=\"29\">\n<p>The HavanaCrypt ransomware\u2019s disguising itself as a Google Software Update application is meant to trick potential victims into executing the malicious binary. The malware also implements many antivirtualization techniques by checking for processes, files, and services related to virtual machine applications.<\/p>\n<p>It is uncommon for ransomware to use a C&amp;C server that is part of Microsoft web hosting services and is possibly used as a web hosting service to avoid detection. Aside from its unusual C&amp;C server, HavanaCrypt also uses KeePass Password Safe\u2019s legitimate modules during its encryption phase.<\/p>\n<p>It is highly possible that the ransomware\u2019s author is planning to communicate via the Tor browser, because Tor\u2019s is among the directories that it avoids encrypting files in. It should be noted that HavanaCrypt also encrypts the text file foo.txt and does not drop a ransom note. This might be an indication that HavanaCrypt is still in its development phase. Nevertheless, it is important to detect and block it before it evolves further and does even more damage.<\/p>\n<p>Organizations and users can benefit from having the following multilayered defense solutions that can detect ransomware threats before operators can launch their attacks:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Trend Micro Vision One\u2122 provides multilayered protection and behavior detection, which helps block questionable behavior and tools early on, before the ransomware can do irreversible damage to the system.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Trend Micro Apex One\u2122 offers next-level automated threat detection and response against advanced concerns such as fileless threats and ransomware, ensuring the protection of endpoints.<\/span><\/li>\n<\/ul>\n<p><i><b>Additional insights by Nathaniel Gregory Ragasa<\/b><\/i><\/p>\n<p><b>Files<\/b><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"9\">\n<tr>\n<td>SHA-256<\/td>\n<td>Detection name<\/td>\n<td>Description<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>b37761715d5a2405a3fa75abccaf6bb15b7298673aaad91a158725be3c518a87&nbsp;<\/td>\n<td>Ransom.MSIL.HAVANACRYPT.THFACBB<\/td>\n<td>Obfuscated HAVANACRYPT ransomware&nbsp;<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>bf58fe4f2c96061b8b01e0f077e0e891871ff22cf2bc4972adfa51b098abb8e0&nbsp;<\/td>\n<td>Ransom.MSIL.HAVANACRYPT.THFACBB<\/td>\n<td>Deobfuscated HAVANACRYPT ransomware&nbsp;<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>aa75211344aa7f86d7d0fad87868e36b33db1c46958b5aa8f26abefbad30ba17&nbsp;<\/td>\n<td>Ransom.MSIL.HAVANACRYPT.THFBABB<\/td>\n<td>Deobfuscated HAVANACRYPT ransomware&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>URLs<\/b><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\">\n<tbody readability=\"3\">\n<tr readability=\"2\">\n<td>http:\/\/20[.]227[.]128[.]33\/2.txt<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>http:\/\/20[.]227[.]128[.]33\/index.php<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>http:\/\/20[.]227[.]128[.]33\/ham.php<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently found a new ransomware family, which we have dubbed as HavanaCrypt, that disguises itself as a legitimate Google Software Update application and uses a Microsoft web hosting service IP address as its command-and-control (C&#038;C) server to circumvent detection. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":47409,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9539,9509],"class_list":["post-47408","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-07-06T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/HavanaCrypt_641.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server\",\"datePublished\":\"2022-07-06T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/\"},\"wordCount\":2258,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/\",\"name\":\"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png\",\"datePublished\":\"2022-07-06T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png\",\"width\":327,\"height\":241},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/","og_locale":"en_US","og_type":"article","og_title":"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-07-06T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-c-c-server\/HavanaCrypt_641.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server","datePublished":"2022-07-06T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/"},"wordCount":2258,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/","url":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/","name":"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png","datePublished":"2022-07-06T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/07\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server.png","width":327,"height":241},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/brand-new-havanacrypt-ransomware-poses-as-google-software-update-app-uses-microsoft-hosting-service-ip-address-as-cc-server\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47408","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=47408"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47408\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/47409"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=47408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=47408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=47408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}