According to BleepingComputer, the TellYouThePass ransomware group, active since 2019, targets various industries and individuals. They are exploiting the recently patched CVE-2024-4577 vulnerability in PHP to deploy webshells and execute their ransomware payloads. These attacks began on June 8, immediately after PHP released security updates, using publicly available exploit code.
Researchers have found that the ransomware appears to alter the service to an open directory, encrypt files, and add ransom notes (with filenames including READ_ME9.html, READ_ME10.html, READ_ME11.html).
A live dashboard tracking #TellYouThePass ransomware infections have been made available by**** Censys. When writing this blog, there are over 1,000 infected servers.

Let’s understand CVE-2024-4577
According to NVD, in PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use “Best-Fit” behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to the PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
Best-Fit Behavior:
- When certain characters are input or passed through the command line, Windows uses “Best-Fit” mapping to replace characters it cannot represent exactly with similar ones.
- This can happen because the code page in use does not support the exact character and thus approximates it.
Best-Fit behavior using a simple example:
- Attacker’s Request: An attacker sends a request to the server: http://yourserver.com/script.php?input=%C4d (where %C4 is the URL-encoded form of the character Ä).
- Character Replacement: Due to Best-Fit behavior, Windows replaces Ä with A. (Note: This is a more realistic example. “Ä” is often replaced with “A” or “A” with an accent depending on the code page.)
- PHP-CGI Interpretation: PHP-CGI might misinterpret the replaced character. For example, if the URL encoded Ä results in a command-line interpretation where Ä is converted to a character that is treated as a PHP option (-d).
- Command-Line Option: The PHP-CGI sees the command-line option -d, which is a directive to set a PHP configuration value. For instance, php-cgi.exe -d display_errors=1 script.php, where -d display_errors=1 was not intended by the original request but was introduced due to character replacement.
As a result, PHP-CGI may change its behavior, potentially exposing errors, sensitive information, or even executing arbitrary code provided by the attacker.
Analysis of Ransomware Note
As noted in the following screenshot, the ransomware group demands 0.1 BTC (around USD 6692.09). Other artifacts here mentioned are the BTC address and an email ID.
Wallet Address: bc1qnuxx83nd4keeegrumtnu8kup8g02yzgff6z53l
Email ID: service@cyberkiller[.]xyz

Whois Details cyberkiller[.]xyz:
- Registered: 29th March 2024 (2 months, 16 days back)
- Registrar: HOSTINGER operations, UAB
- IP Address: 84.32.84[.]32
- Hosted on: Hostinger
VirusTotal Detection:
VirusTotal shows a low detection score for this domain.
![Virustotal detection of the domain - cyberkiller[.]xyz](/uploads/research/9741a882-bfe2-4f30-b014-ffe2136663e32232x525.webp)
However, the domain’s IP address appears hosted by the shared hosting provider Hostinger.

Checking the passive DNS indicates that multiple other domain names ending with the .online suffix have been flagged as malicious. However, there is no evidence linking them to this campaign.

Wallet Address:
The wallet has been transacted 6 times. It has received a total of 0.279 BTC and has sent a total of 0.279 BTC. The current balance of this address is 0 BTC. The last transaction was observed on 2024-04-27. However, there have been no recent transactions observed since then.

Looking up the email ID (service@cyberkiller[.]xyz) on Google provided us with around 250 entries of the infected websites that Google has crawled so far but of course, there are more as indicated by Censys.

Reference:
Censys Query:
services.http.response.body:{"READ_ME1.html", "READ_ME4.html", "READ_ME9.html", "READ_ME10.html", "READ_ME11.html"}
