📜 ⬆️ ⬇️

New Ransomwar asks bitcoins

image
The little animal , CryptoLocker, has surfaced on Reddit and on the Ars Technique news.

The target audience of the beast is cars from XP to 7-bit 64-bit. The malware spreads in attachments to emails and is not detected by antivirals immediately (redditers tested on MSE, Trend Micro WFBS, Eset, and Kaspersky). The victims of the Zeus botnet also got this virus through push.

Virustotal scan
The malware uses the public 2048-bit RSA key and takes the private key from the C & C server to encrypt documents in alphabetical order on the disk, as well as on all shared network folders where it has access to the recording (many have network backups encrypted). When activated, the virus creates encrypted files that fall under the mask: * .odt, * .ods, * .odp, * .odm, * .odc, * .odb, * .doc, * .docx, * .docm, * .wps, * .xls, * .xlsx, * .xlsm, * .xlsb, * .xlk, * .ppt, * .pptx, * .pptm, * .mdb, * .accdb, * .pst, * .dwg, *. dxf, * .dxg, * .wpd, * .rtf, * .wb2, * .mdf, * .dbf, * .psd, * .pdd, * .eps, * .ai, * .indd, * .cdr, ???????? .jpg, ????????. jpe, img _ *. jpg, * .dng, * .3fr, * .arw, * .srf, * .sr2, * .bay , * .crw, * .cr2, * .dcr, * .kdc, * .erf, * .mef, * .mrw, * .nef, * .nrw, * .orf, * .raf, * .raw, * .rwl, * .rw2, * .r3d, * .ptx, * .pef, * .srw, * .x3f, * .der, * .cer, * .crt, * .pem, * .pfx, * .p12 , * .p7b, * .p7c, * .pdf, * .tif

Having finished your dark business or when disconnecting from the Internet, CryptoLocker displays a window like the one you see above and asks for $ 300 or 2BTC for a certain account for decrypting the data. For everything about everything, the victim is given 72 hours (although the timer can be deceived through the BIOS), after which the malware is deleted. Also, at the moment, many providers have already blocked the C & C server, and therefore some of the victims can not even buy their files.
')
From the translator: I want to say a lot of foul language about the fact that the 21st century is in the yard and that it would be time to stop opening executables in attachments, but I will not. Make cold backups, waving.

Source: https://habr.com/ru/post/198010/


All Articles