Skip to content

Malware

Ordinypt

aka GermanWiper · HSDFSDCrypt

This malware claims to be a ransomware, but it's actually a wiper.

Ordinypt, also known as GermanWiper, HSDFSDCrypt, is a Windows malware family.

Background

Although it presents itself as ransomware, this malware is in fact a wiper. Once running, it kills off a range of processes, including database services, presumably to free up files those programs may have locked. Ordinypt deliberately spares certain files and directories so the host remains bootable. Targeted files are overwritten with null characters and given a random 5 character file extension, after which shadow copies are deleted and Windows startup repair is turned off to hinder recovery. The desktop wallpaper is swapped out and a ransom note is left for the victim. The malware also checks in with its C2 to record the file extension applied to that particular machine and the BitCoin address randomly assigned to the victim for payment, which is selected from a lengthy list embedded in the configuration.


Source: Malpedia (Fraunhofer FKIE).