Home Malware Programs Ransomware PadCrypt Ransomware

PadCrypt Ransomware

Posted: February 17, 2016

Threat Metric

Threat Level: 10/10
Infected PCs: 33
First Seen: February 17, 2016
Last Seen: March 15, 2020
OS(es) Affected: Windows

The PadCrypt Ransomware is a file encryptor that modifies your files for the purpose of selling a decryption solution to you. Although the PadCrypt Ransomware provides relatively extensive support for purchasing this service, malware researchers caution against paying its fee, which con artists may collect without decrypting any files. Backups can protect your PC's data from permanent damage, and anti-malware programs can, as always, remove the PadCrypt Ransomware safely.

The PadCrypt Ransomware: Making Illegal Ransoms Easier than Ever

The PadCrypt Ransomware is another revision of the popular CryptoWall Ransomware, and hews to that Trojan's same tactic of encrypting files, and then waiting for the victims' payments made out of hope of buying data restoration. Because of the PadCrypt Ransomware's relative newness to the threat scene, no decryptors have been made available for the public's free use, although various PC security entities claim to be working on solutions.

Early reports have seen the PadCrypt Ransomware, much like '.locky File Extension' Ransomware, using e-mail attachments for installing itself. Instead of using an exploit embedded in an otherwise standard document, however, the PadCrypt Ransomware uses a corrupted executable with both the icon and the name of a PDF file, to trick readers into opening the program. Since the PadCrypt Ransomware 's Trojan installer is an independent program, this delivery method is less reliant on software vulnerabilities that could be averted by security patches.

After its installation, the PadCrypt Ransomware scans all local hard drives for non-essential files of formats worth encrypting, such as documents or spreadsheets. Trojan-encrypted files, much like archives, can't be read by any associated programs, and will need to be run through a decryption process using a key unique to the PadCrypt Ransomware's payload. The PadCrypt Ransomware sells its victims this service, both with multiple instruction messages, as well as a 'live help' feature built into its pop-up window. Perhaps appropriately, this feature is non-functional currently due to a lack of response from the PadCrypt Ransomware's servers.

Overcoming a File Encryptor without Paying a Penny for Decryption

The PadCrypt Ransomware emphasizes the ease of use of its decryption 'purchase,' which requires transferring BitCoin currency to third parties in return for a feature that they may, or may not, deliver. Unlike past file encryptors with similar features, the PadCrypt Ransomware builds its chat feature directly into itself, rather than asking victims to download, install, and use a separate program, such as the TOR browser. Rather than paying this 450 USD ransom, however, malware experts always encourage using secure backups that can overwrite encrypted files without any need for decrypting your data. Note that your local backups, including VSS data, may be subjected to deletion by the PadCrypt Ransomware.

A PadCrypt Ransomware infection is extremely visible from its changes to your file names and desktop, in addition to its pop-ups and other ransom messages. If you do detect any of these symptoms on a PC, disconnect the machine from the Internet and reboot it into Safe Mode. Scan your machine with any reliable brand of anti-malware products and allow it to remove the PadCrypt Ransomware, as well as any other threats (such as its faux-PDF installer).

Particularly unusually, the PadCrypt Ransomware's current samples include uninstaller files. However, since these uninstallers may provide incomplete uninstallation and cannot decrypt your files, victims should avoid using them. Since the uninstaller can remove parts of the PadCrypt Ransomware without harming the file-ransoming payload, con artists may have provided their uninstallers as a means of limiting samples available to the PC security industry. Such efforts could slow down the development of free decryptors.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\PadCrypt\package.exe File name: package.exe
Size: 802.3 KB (802304 bytes)
MD5: 04cb6917c78cbba1824a2bf57a26f019
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PadCrypt
Group: Malware file
Last Updated: February 18, 2016
b4f886df55015695eaafe3da712b431b75493623c53200f642ced5d7f89f2fdd.exe File name: b4f886df55015695eaafe3da712b431b75493623c53200f642ced5d7f89f2fdd.exe
Size: 784.89 KB (784896 bytes)
MD5: 84aa7c891cd5ae136117317f451819c0
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2016
730e78721dcb792f9343d6b632a22b6874e5945b204fbc4b04d75e544ed2bdf0.exe File name: 730e78721dcb792f9343d6b632a22b6874e5945b204fbc4b04d75e544ed2bdf0.exe
Size: 797.69 KB (797696 bytes)
MD5: 9dbeff5ac47058fb8fe61c3948cc26ca
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2016
3c9fbf881eb73ed3194c65e046857349ccdf2297e8b6770ecc4ab16825a695de.exe File name: 3c9fbf881eb73ed3194c65e046857349ccdf2297e8b6770ecc4ab16825a695de.exe
Size: 784.89 KB (784896 bytes)
MD5: 7ed0c7cd88bf661ecef8abec2ff310aa
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2016
%APPDATA%\PadCrypt\package.exe File name: package.exe
Size: 537.6 KB (537600 bytes)
MD5: 786d201145aa227e816c2c480ca24e23
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PadCrypt
Group: Malware file
Last Updated: February 18, 2016
%APPDATA%\PadCrypt\package.exe File name: package.exe
Size: 469.5 KB (469504 bytes)
MD5: eeb4d8fab06a892a3862a251864719a7
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PadCrypt
Group: Malware file
Last Updated: February 18, 2016
file.exe File name: file.exe
Size: 384 KB (384000 bytes)
MD5: 3e1e3f83032c2237d0df9e45ccb52f3a
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 4, 2017
file.exe File name: file.exe
Size: 1.91 MB (1919488 bytes)
MD5: 93d2ff0ea17d747ad55c01c9a71529d8
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 15, 2020
%APPDATA%\PadCrypt\package.exe File name: package.exe
Size: 797.69 KB (797696 bytes)
MD5: a34632d75f4eba0fb0dd90f77db2f90d
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PadCrypt
Group: Malware file
Last Updated: February 18, 2016
%APPDATA%\PadCrypt\package.exe File name: package.exe
Size: 1.4 MB (1406976 bytes)
MD5: 17822a81505e56b8b695b537a42a7583
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PadCrypt
Group: Malware file
Last Updated: February 18, 2016
file.exe File name: file.exe
Size: 492.03 KB (492032 bytes)
MD5: 841453bdff5905f17c0074a65b263893
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 17, 2016
%APPDATA%\PadCrypt\package.exe File name: package.exe
Size: 1.45 MB (1451008 bytes)
MD5: 0116f296640ef8e3b43227ac0028518a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PadCrypt
Group: Malware file
Last Updated: February 18, 2016

Additional Information

The following directories were created:
%APPDATA%\PadCrypt
Loading...