GandCrab 5.2 ransomware – a decryptable malware variant

The virus employs a secure encryption algorithm to lock files and then demands a ransom to be paid in their return. The personal data that is marked with .[random] file extension is also accompanied by a ransom note [random]-DECRYPT.txt file, that is populated into each of the affected folders. This version of the virus appears to have changed slightly, with minor differences in ransom size ($550 in Dash or BTC) and payment instructions via the Tor browser.
| Name | GandCrab 5.2 |
|---|---|
| Type | Cryptovirus/ransomware |
| Family | GandCrab |
| Extension | Random 5-10 characters |
| Ransom size | $550 in Dash or BTC (might vary) |
| Ransom note | [random]-DECRYPT.txt |
| Distribution | Spam email attachments, exploit kits, brute-force attacks, etc. |
| Decryption | Decryption tool is available for this virus version |
| Elimination & system fix | We recommend performing ransomware removal using anti-malware software and then clean the virus damage with FortectIntego |
Within the few days of GandCrab 5.2 discovery, malware researchers reported more than ten samples uploaded by victims[2]. Despite the newest malware strain being actively distributed, researchers noticed that V5.1 is still being delivered with the help of Fallout EK. For a long time, there was no decryption tool for the 5.2 version. However, Bitdefender has finally released a decrypter for this version also.
It appears that ransomware developers were focusing on releasing the new version as soon as possible, so all the previously known features were kept in development of the V5.2 variant:
- the file extension placed at the end of encrypted data is formed from 5-10 random characters;
- the ransom message gets delivered after the encryption process and appears on the Desktop wallpaper;
- the note reveals payment methods and is also named according to the file appendix;
- [random]-DECRYPT.txt ransom note encourages victims to pay up using TOR browser links, so there are no contact emails.
[random]-DECRYPT.txt is the pattern of a ransom note which is delivered by ransomware after a successful file locking process and reads the following:
—= GANDCRAB V5.2 =—
UNDER NO CIRCUMSTANCES DO NOT DELETE THIS FILE, UNTIL ALL YOUR DATA IS RECOVERED
FAILING TO DO SO WIL RESULT IN YOUR SYSTEM CORRUPTION, IF THERE ARE DECRYPTION ERRORSAttention!
All your files, documents, photos, databases and other important files are encrypted and have the extension:
The only method of recovering files is to purchase an unique private key. Only we can give you this key and only and only we can recover your files.
The server with your key is in a closed network TOR. You can get there by the following ways:
—————————————————————————————–
| 0. Download Tor browser – https://www.torproject.org/
| 1. Install Tor Browser
| 2. Open Tor Browser
| 3. Open link in TOR browser http://gandcrabmfe6mnef.onion/ b6314679c4ba3647/
| 4. Follow the instructions on this page—————————————————————————————–
On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.
ATTENTION!
IN ORDER TO PREVENT DATA DAMAGE:
* DO NOT MODIFY ENCRYPTED FILES
* DO NOT CHANGE DATA BELOW—BEGIN GANDCRAB KEY—
–
—END GANDCRAB KEY——BEGIN PC DATA—
–
—END PC DATA—

The newest 5.2 release was discovered by Tamas Boczan – malware researcher who reported about it on Twitter and included ten malware samples and his analysis.[3]
Experts[4] recommend using automatic malware removal tools and employ FortectIntego for the job, although other tools like SpyHunterCombo Cleaner can be used as well. This variant of malware is detected under various names, including:
- TR/AD.GandCrab.tvnwv
- Win32:Malware-gen
- RDN/Generic.grp
- Trojan:Win32/Dynamer!rfn
- Ransom.GandCrab, etc.
According to the text file, you should go to the TOR browser[5] and launch the payment website. When this is done, you will be able to view a browser window containing instructions and the ransom size. As previous members in this family, the 5.2 version demands to pay in DASH or Bitcoin cryptocurrency.

However, the amount may differ according to the number of encrypted files, victim origin, and other factors. The demanded payment can reach $2,400, although some users reported that this version asks for $550. Although cybercriminals promise free decryption of one file and even guarantee the full data decryption, later on, these people are cybercriminals and cannot be trusted regardless. The main focus of virus developers is your money.
Make sure that you remove GandCrab 5.2 instead of paying the ransom or contacting these criminals because it is not advisable, especially, when cybercriminals are known for their malicious behavior for a while. Your concern about the encrypted data is understandable, but you need to focus on the malware termination first as locked files can only be restored after the cyber threat is terminated from the infected Windows computer system.
Spam email attachments hide infected files that execute ransomware payload
While browsing the internet, you will get alerts when you encounter phishing or malware-laden sites if you have reputable anti-malware employed. However, when it comes to spam email, you cannot be sure that the email is not safe without checking it manually. It is possible to scan the attached file before opening the document on the system and make sure that its purpose is not malicious.
Unfortunately, when you are not doing so, you can easily get malware infections from the PDF or Word attachment when you download and open the file on your device without checking. These emails often include names of well-known services or companies to trick people more. When the malicious script gets triggered direct ransomware payload, or other malicious programs get on your system without any interruption.
Clear the system from GandCrab 5.2
You need to start ransomware removal as soon as you notice the activity of this virus or any other suspicious behavior. It can be done easily if you use professional anti-malware programs. These automatic tools can perform a full system scan and indicate possibly malicious programs immediately.

After the thorough system scan, FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes suggests methods to remove the virus and clean the PC. You should follow those steps and terminate the virus including virus damage. Repeat the scan with another similar program and double-check before entering an external device with backups or installing the data recovery software.
5.2 is the most recent version in this particular family, and there was no official decryption tool developed for a long time until now. Check the data recovery methods that are provided at the end of this article and you will also find the Bitdefender's decrypter that has been released not so long ago.
Did this guide help?
Be the first to comment