In this quick blog post we’ll have a look at BKRansomware, a Vietnamese ransomware that wants you to top up its phone.
Analysis
This ransomware is named “BKRansomware” based on the file name and debug path. Properties:
- MD5: 892da86e60236c5aaf26e5025af02513
- SHA1: 6f36c02161a83a3683921fc73319474157f4fb92
- SHA256: c23f695a19346bf3a5b21fb5a281771808953930d8dcb0a359f163ba0329305f
- Compilation timestamp: 2018-05-03 10:04:35
- VirusTotal report:
c23f695a19346bf3a5b21fb5a281771808953930d8dcb0a359f163ba0329305f
BKRansomware will run via command line and displays the following screen:
Figure 1 - Ransom message |
The ransomware message is very brief, and displays:
send 50k viettel to 0963210438 to restore your data
As such, it appears the creators are in desperate need of more credit so they can make calls again 

It only encrypts a small amount of extensions:
.txt, .cpp, .docx, .bmp, .doc, .pdf, .jpg, .pptx, .png, .c, .py, .sql
Noteworthy is the debug path:
C:\Users\Gaara\Documents\Visual Studio 2013\Projects<b>BKRansomware-20180503T093651Z-001\BKRansomware\Release\BKRansomware.pdb
It appears "BKRansomware"was written in Visual Studio 2013 C++.
Conclusion
While BKRansomware is not exactly very sophisticated, it is able to encrypt (or rather encode) files, and is unique in the sense that it asks you to top up a mobile phone.
Article Link: Blaze's Security Blog: Vietnamese ransomware wants you to add credit to a mobile phone