Ransomware - Stampado

Stampado
Aliases
Zelta
Decryptor Available
Yes
Description

Stampado is the first Ransomware-as-a-Service created by The Rainmaker and "his team." The subsequent variant was Philadelphia. The Stampado RaaS was discovered by researchers in early July 2016, being sold on the dark web for $39. A significantly small sum compared to the other RaaS being sold on the dark web for thousands of dollars. The $39 would give attackers a license to use the software, allowing them to use their own custom communication method (email) for extortions. We found no tangible evidence of extortion amounts, but several researchers reported that 1 BTC was the amount of one extortion attempt, which, at the time of compilation, was around $660.

As for the ransomware itself, it was written using AutoIT and used AES-256 asymmetrical encryption to modify files. Some variants would encrypt files and then change the extension to <file name>.locked. Other variants didn't bother to change file extension names; they only encrypted them. Most variants, however, dropped two ransom notes - an executable that invokes a modal with decryption instructions and a traditional readme note titled "How to recover my files.txt." The executable provides a countdown that gives victims 96 hours to pay, or no decryption will be provided. It also performs "Russian Roulette," which deletes a random set of files every 6 hours of nonpayment. 

Thankfully, there are three known decryptors for this ransomware since it was poorly written and implemented in AutoIT. Avast, Emsisoft, and Trend Micro are all known to have decryptors for Stampado.

Ransomware Type
Crypto-Ransomware
RaaS
First Seen
Last Seen
Threat Actors
Type
Actor
Individual
The Rainmaker
Extortion Types
Blackmail
Data Russian Roulette
Direct Extortion
Extortion Timeout
Extortion Amounts
Amount
1BTC($660)
Encryption
Type
Symmetric
Files
AES-256
File Extension
<file name>.locked
Ransom Note Name
How to recover my files.txt
<ransomware file name>.exe
Samples (SHA-256)
342933cb4cbb31a2c30ac1733afc318a6e5cd0226160a59197686d635ec71b20
4771050b6ebfdf191f0d0e39d03fac7dc9dd81bdcdf7e2004a5b3a4956f0c382
78db508226ccacd363fc0f02b3ae326a2bdd0baed3ae51ddf59c3fc0fcf60669
b4af48993bcc97f90e6d9c292c096a2819c11043104e6bb08ab398ede2e6fa20
d676d9dfab6a4242258362b8ff579cfe6e5e6db3f0cdd3e0069ace50f80af1c5