Ransomware - Philadelphia

Philadelphia
Decryptor Available
Yes
Description

Philadelphia is the second ransomware-as-a-service (RaaS) created by The Rainmaker. The first was its predecessor, Stampado. Oddly enough, the first mentions of Philadelphia come from a Bleeping Computer forum post by Arslan0708 on September 7, 2016. Arslan0708 allegedly hacked a user on Alphabay and caught a conversation from The Rainmaker to SkrillGuide2015. In these conversations, The Rainmaker states they will begin selling the Philadelphia RaaS kit "tomorrow" (September 8, 2016). Thus, the first time this ransomware was seen was in September 2016.

The Rainmaker distributed a lot of content to sell its $389 RaaS software written in AutoIT. There was a YouTube video and official PowerPoint presentation slides to advertise its features. Features that allowed for customization of the ransomware include the color of the ransom note, folder encryption location, user access controls, mutexes, a custom BTC wallet, and more.

This ransomware uses the extortion types "Give Mercy" and "Data Russian Roulette." The Russian Roulette extortion type allows operators to delete a random amount of data from the victim's machine after the timer expires, and, as you may have guessed, giving mercy is providing the victim decryption keys without payment. Philadelphia was popular enough for APTs such as TA505 to acquire a license and use it against more victims worldwide. The smallest extortion seen in the wild was 0.5 BTC, and the largest was 15 BTC.

Ransom note pictures derived from The Crypto-Ransomware Digest and Proofpoint.

Ransomware Type
Crypto-Ransomware
RaaS
First Seen
Last Seen
Lineage
Threat Actors
Type
Actor
Individual
The Rainmaker
APT
TA505
Extortion Types
Data Russian Roulette
Direct Extortion
Give Mercy
Communication
Medium
Identifier
Encryption
Type
Symmetric
Files
AES-256
File Extension
<random alphanumeric sequence>.locked
12587ba985f95d58acd65039709a5820b1608b33866d023370afa9b46daed6e7
55793f2cd2a061646e73f0520f5f43a82da1c890624c0317777d5917efe68761
57ac35dc3a92242f14f37709177b064907d6b1a7fe6027931ebbbcd66eccdb3e
6c3d69053a19e336289efbe0ee65eba1ef21076019a4b71b39bca8bd105e86cd
6d21e538115bcf30354360e81969cc5b438e5cd5be48eebf6243cc37e06cff0c
7f9dfb67e4fd3b0853863ccb5e6b42eadc0cd7b1c32bd0b457aab5cff8310e3b
812ddd619e12fb2c90c8395fd02fe12638e997a29f86f7d39e42d50de832d4f0
a1e1b22f907b4b5d801e7c1dd3855d77bf28831eaadc2fbf9ed16ee0cdcc8ccf
b6be75155ca197c4931ed166dcc7725ad44adcfc8b9b6947f7cb69d2bf63ff64
cc9edc887142fc50112db7bad99afc39518c2e132413b1d0a548fc1f267ea628
fe07c2ec0f5068aeaa406fda57a7e74dece53b1eab18478a4e3c44155f2efb5d