Showing posts with label Encrypted Files. Show all posts
Showing posts with label Encrypted Files. Show all posts

Tuesday, 1 December 2015

Linux Ransomware Encrypts 3000 Websites



In recent weeks there have been the ransomware which it has provided encrypted hit 3,000 websites on Linux web servers. This places the Russian anti-virus company Doctor Web, which relies on weather data from Google. It is called ransomware Linux.encoder.

Attackers behind ransomware deliberately set WordPress websites and online stores using Magento. Through a still unknown vulnerability know the attackers to gain access to the Web server that hosts the website and then perform Linux.encoder.This ransomware, which additional duties require encrypts all kinds of files, and then asks one bitcoin, what with the current exchange rate is 349 euros. It is unknown how many webmasters have finally paid the ransom.

F-Secure reported in early November, about 36 people had paid, which at that time corresponded to an amount of 12,000 euros. Due to an error encrypted files can be decrypted without paying. The Romanian anti-virus company BitDefender has developed a free decryption tool for victims. From examination of the virus fighter shows that an early version of ransomware already was distributed on August 25 of this year and then seven people paid the ransom.

Wednesday, 11 November 2015

Ransomware Infects Computers British Parliament



Several computers in the secure network of the British Parliament earlier this year become infected with ransomware, as has now become known. In addition, files were encrypted on a shared network drive, reports the British newspaper The Times.

After the files were encrypted asked the ransomware to ransom. How the computers were just infected was not disclosed.After the infection was discovered network of infected computers were shut down. The hard drives were then deleted and replaced. The parliament network is used by about 8500 people, according to the Daily Express.

Saturday, 7 November 2015

Linux Users Targeted By New Ransomware


Researchers from the Russian anti-virus company Doctor Web discovered ransomware which has provided the Linux Users. How the "Linux Encoder" ransomware is spreading the virus fighter does not know. The malware has to cater to webmasters and web servers.

Once the ransomware can start with administrator privileges which will include instructions on how to download a file with the victim and to encrypt files. It is in this case to files in home directories and directories associated with the administration of the website. After this, only encrypted files with specific extensions and specific directory names. The encrypted files are a .encrypted extensions.

There is also the file installed with instructions in any directory with encrypted files. It states that the victim must first bitcoin payment, equivalent to 360 euros. According to the ransomware Doctor Web created more than 10 victims. The anti-virus company advises victims to contact the technical department of the company. To decrypt it is that important as the virus fighter users can not modify them or remove the files, otherwise the encrypted data may be permanently lost.

Friday, 18 September 2015

Ransomware Encrypts Network Hospital US


Thousands of workers of an American hospital five days can make use of an important network because some files were encrypted by ransomware. Because of the infection, it was decided to remove the network from the air.

The network is used by more than 4,000 employees at the James A. Haley Veterans' Hospital in Florida. "Some documents were infected on the shared drive and left an alarm," a spokeswoman told the Tampa Tribune. "This could affect all employees with computer access, more than 4,000 people." The damage is now mapped. All files on the network, there was a back-up, according to the spokeswoman. How ransomware could spread on the hospital network was not disclosed.

Thursday, 17 September 2015

Writer Loses Part Of His Life's Work By Ransomware


A New Zealand writer who for 50 years on a book about cars works is a part of his life's work lost by ransomware and the man did not have backups. The 73-year-old Bruce Utting in his life had some 200 cars owned and operated since 1965 trying to write about a book.

Recently touched his computer infected with ransomware which encrypted files. To regain access to the files he had to pay $ 500. If it was not paid on time would amount to $ 1000 are doubled. Utting knocked on NetSafe, an organization sponsored by the government that gives online security advisory. "It was suggested that I should throw this computer and a new one had to buy, as there was no safe way to format or to avoid the risk of reinfection," said the writer.

Utting then decided to go to the police, but they sent him back to NetSafe. The organization advised not to pay the ransom, even letting victims of ransomware regularly know that after paying their files to recover. The British anti-virus firm Sophos understands else that pay victims, especially if they have no backups. Despite all warnings the writer did not have backups, so the encrypted files can not be retrieved in a different way.

Utting was lucky however, as ransomware but four or five chapters encrypted. He uses a very old version of Microsoft Works for writing his book and the earlier chapters were not recognized by the ransomware and encrypted, reports the New Zealand news site Stuff. The writer is now planning to buy a new computer.

Tuesday, 2 June 2015

Ransomware-Maker Repents And Gives Decryption Keys Away




Last Monday, numerous computers suddenly by a new ransomware variant called Locker hit a small amount to the victims asked for decryption, but the automaker would now regret his actions and provides all the decryption keys free of charge.

In addition, the ransomware on June 2 will automatically create all encrypted files accessible. Locker really came up out of nowhere. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files.

On Saturday put someone who "Poka Bright Minds" calls a message on Pastebin . In it he claims to be responsible for Locker. According to him it was never intended to spread the ransomware. The online storage Mega he has now a file with bitcoin addresses and keys installed. The forum Bleeping Computer confirms that the file actually contains the keys of victims. In addition, on June 2, the automatic start decryption. How the malware spread exactly is still unknown.

File Information 
Name: database_dump.csv
Size: 127.5 MB
MD5: d4d781412e562b76fe0db0977cf6279b
SHA-1: 6ba671ce2a6c256c74d7db81186b0dbddd5e2185
SHA-256: d7fd791b86615fada64fe0290aecb70e5584b9ac570e7b55534555a3b468b33f

VirusTotal Link

Mega Link

Thursday, 26 March 2015

School District Shifting Exams Because Ransomware


A US school district has the math and English exams postponed after all kinds of files on the network were encrypted by ransomware. The Swedesboro-Woolwich School District in New Jersey consists of four primary schools, with a total of 2,000 students. The infection affected the entire school system, from e-mail communication and online learning tools to examinations conducted online.

Furthermore, would also files of employees are encrypted. Across New Jersey Online late headmaster Terry Van Zoeren know that teachers and students, because the systems were turned off, went to work as if it was "1981". For example, parents could receive e-mails with the numbers of pupils and other information and it was not possible to use the smart boards, as reports CBS. In a statement on its website allows the school district that the affected files mostly Word documents, Excel spreadsheets and PDF files of staff were.

Data of the student information system as well as other applications off-site should be preserved and are not affected by the ransomware. The encrypted files have been restored through a backup, as well as the servers where all the malware was removed. The school district is now working to get the e-mail and other systems in the air again.

According to Van Zoeren would ransomware to "500 bitcoins" ransom asked. An unprecedented sum for ransomware, which usually requires an amount of about $ 500. Possible that this is misunderstood or misinterpreted. How the school district became infected is not reported. In contrast, only explained in the statement how ransomware spreading in general.

Wednesday, 11 February 2015

Anti-virus Company G Data Is Encrypted Chat App


The German anti-virus company G Data will in April an application for encrypted instant launch , based on the protocol of Axolotl Text Secure . The app allows users besides conducting individual interviews and group discussions also encrypted exchange pictures and files.

Meanwhile, there would be more than 10 million users that communicate via the Axolotl protocol Text Secure. Through apps that support the protocol, as the app from G Data or Secure Text of Open Whisper Systems can either via SMS or via the messaging app itself communicate safely. The app will appear in a free and paid version.

The free version offers not only encrypted chat and file also backing up their own chat history to the SD card and encrypt the private chat history and lock with a password. The paid version offers a phishing filter URLs in instant messages and filter incoming and outgoing messages and text messages.