Showing posts with label Bleeping Computer. Show all posts
Showing posts with label Bleeping Computer. Show all posts

Thursday, 19 November 2015

New Version Tesla Crypt Spotted In The Wild



There's a new version around the stubborn ransomware trojan Tesla Crypt. Although not much seems to have renewed the software, it is very difficult for them to komen.De off new variant, Tesla Crypt v2.2.0, encrypts files with the .ccc file extension, such as happened in previous versions.

What is new is that there are multiple names for ransom notification files. According to posts on forums that filename can vary and it looks like "_how_recover_.HTML 'or' _how_recover_.TXT.

The ransomware Crypt Tesla earlier this year for the first time discovered and has targeted files with extensions which had mainly to do with games. To regain access to the files, often $ 500 was demanded.

According Bleepingcomputer it is virtually impossible to undo the encryption of Tesla Crypt v2.2.0 without paying the cyber criminals. Because version 1 yet made ​​use of a symmetric encryption method, soon developed a tool to "liberate" hostage files without paying. This new variant is working tool which unfortunately no longer.

Sunday, 8 November 2015

Ransomware Destroys Files By Programming Error


A new ransomware variant that is currently scattered ensures that victims will never recover encrypted files, even if they decide to pay the ransom of 700 euro on time. Because the developer has made a major programming error.

Power Worm ransomware uses AES encryption to encrypt the files on infected computers, but then throws away the key.Since the decryption key is not initialized in time and saved, the victim can never recover his files, even if he pays, warns Lawrence Abrams forum BleepingComputer. He advises victims would not have to pay, because they will not recover their files will.

Abrams says that researchers BleepingComputer choose to make no bugs and bugs in ransomware known as the creators can then resolve the issue. In this case they make an exception and it is the ransomware developer even explained how he can rectify his mistake. This must be the case that his creation continues to destroy the files of victims.

Tuesday, 21 July 2015

Scammers Trick Users With Blue Screen Of Death


The Blue Screen of Death for many Windows users a signal that something is wrong with the computer or install Windows, but Internet scammers use the report to highlight users for a lot of money and have this kind of fraud refined.

Counterfeit versions of the Blue Screen of Death will be shown to users in different ways, such as pop-ups. It establishes that there are major problems with Windows and the user "Microsoft engineers" to call. In reality it is to foist telephone scammers people products and services a try. In addition to the pop-ups scammers also use potentially unwanted software (PUP) to display the messages on the user's screen.

Last year, though there ransomware discovered that showed these messages on the computer, but scammers have further refined the message. Through a program called iLivid is a PUP called Sensei Updater then installed on the computer displays a convincing blue screen of death, according to a message on the forum of Bleeping Computer . The warning again contains a phone number of a help desk.

When users dial the number then takes the classic scam phone off. The telephone scammer tells the user that his computer is loaded with malware and clearly demonstrates all kinds of supposedly alarming warnings. Then the user to remove the malware must pay, which can cost between $ 150 and $ 400, warns anti-virus company Malwarebytes .

Wednesday, 3 June 2015

Ransomware Maker Decrypts As Promised Infected PCs


The creator of the Locker-ransomware has promised as encrypted files on all computers he infected without charge and automatically decrypted. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.

At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files. Rich is the author therefore did not become. According to Symantec, he would total 152 euros received 22 victims.


Last week the ransomware maker on Pastebin posted a message in which he regret expressed. It was at its say never been his intention to spread the ransomware. He compiled a file with all the encryption keys available and stated that on June 2, all remaining infected computers would be automatically decrypted. And the author has fulfilled that promise, reports Bleeping Computer . For users that their computer had been disinfected, there is a unlocker tool made ​​available. How to distribute the ransomware is managed is still unknown.

Tuesday, 2 June 2015

Ransomware-Maker Repents And Gives Decryption Keys Away




Last Monday, numerous computers suddenly by a new ransomware variant called Locker hit a small amount to the victims asked for decryption, but the automaker would now regret his actions and provides all the decryption keys free of charge.

In addition, the ransomware on June 2 will automatically create all encrypted files accessible. Locker really came up out of nowhere. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files.

On Saturday put someone who "Poka Bright Minds" calls a message on Pastebin . In it he claims to be responsible for Locker. According to him it was never intended to spread the ransomware. The online storage Mega he has now a file with bitcoin addresses and keys installed. The forum Bleeping Computer confirms that the file actually contains the keys of victims. In addition, on June 2, the automatic start decryption. How the malware spread exactly is still unknown.

File Information 
Name: database_dump.csv
Size: 127.5 MB
MD5: d4d781412e562b76fe0db0977cf6279b
SHA-1: 6ba671ce2a6c256c74d7db81186b0dbddd5e2185
SHA-256: d7fd791b86615fada64fe0290aecb70e5584b9ac570e7b55534555a3b468b33f

VirusTotal Link

Mega Link

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .

Friday, 1 May 2015

New Ransomware Avoids US Computers


Researchers have discovered a new ransomware variant that strikes because the US does not infect computers intentional. Crypt0L0cker such as ransomware called, according to researchers from Bleeping Computer a version of the famous Torrent Locker ransomware.

Crypt0L0cker appears to use the same communication methods as Torrent Locker and encrypts all kinds of files, which then users hundreds of dollars can be decrypt. If victims do not ransom doubling pay on time.

Why Crypt0L0cker US avoids computers is unknown. In the past happened that Russian cyber criminals infecting computers no Russian, so as not to attract the attention of the Russian authorities. The new ransomware is now in Europe, Asia and Australia surfaced and spreads via emails posing as traffic violations or government posts.

Sunday, 19 April 2015

Ransomware Allows Victims To Recover From Error Files



A new ransomware variant that first appeared in late January and make the last month was increasingly active shows an error causing casualties without paying their files can be recovered. It is the Threat Finder ransomware which spreads through vulnerabilities in Java, Adobe Flash Player and Microsoft Silverlight that Internet users are not patched.

Once the ransomware encrypts which operates numerous files and asks here for 1.25 bitcoins, what with the current exchange rate is 259 euros. A researcher from Bleeping Computer discovered that the ransomware the Volume Shadow Copies are not removed from the computer, making it possible to access the files using the " Previous options can restore "of Windows, or a tool like Shadow Explorer .

Friday, 12 December 2014

OphionLocker Ransomware Forget To Remove Files Thoroughly


Researchers have discovered a new ransomware variant that uses strong encryption to encrypt files, but because the original file could not be thoroughly erased victims recover their data without having to pay the ransom.


OphionLocker Message

OphionLocker, such as the ransomware by Trojan7Malware is called, spreads via hacked websites and makes use of known vulnerabilities that are not by Internet users are patched to infect their computer. Once active makes ransomware a unique hardware identifier to, based on the serial number of the first hard disk, the serial number of the motherboard and other information.

Asking For Hardware ID - Tor Link

Then it will create a Tor website link to check the specific hardware ID is already encrypted. Hereafter OphionLocker looking for all kinds of files. However it is only for files with file extensions sought in lowercase. A file as photo.jpg will encrypt the ransomware while foto.jpg is about beaten.

Encryption

To encrypt used OphionLocker elliptic-curve encryption (ECC). As far as known, it is only the second ransomware that uses this encryption method. Most ransomware uses a combination of AES and RSA encryption to encrypt the files of victims. Here, the server generates a key pair, RSA public and private, for RSA. The private key remains on the server, while the public key is sent to the ransomware. In OphionLocker is the public key already in the malware. As a result, can also on computers which are not encrypted are files connected to the Internet.

The malware after encryption displays a message indicating the amount of 1 bitcoin is asked, what with the current exchange rate is 290 euros. Victims, however, do not have to pay to get their files, reports the forum Bleeping Computer . The ransomware shows the original of the files not erase the encrypted safe and also allows the volume shadow copies alone. As a result, it is possible to access the files through a program as ShadowExplorer to recover.