Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 43004
  • Total Topics: 16195
  • Online Today: 5130
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: Kaspersky succesfuly decrypts CryptXXX, download free tool for decryption.  (Read 6345 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum


Kaspersky has announced it's decrypted yet another crypto-extortion racket.

Writing here: https://blog.kaspersky.com/cryptxxx-ransomware/11939/ , the company's John Snow says Kaspersky bods can now untangle data after a CryptXXX attack.

CryptXXX was described in mid-April by Proofpoint: https://www.proofpoint.com/us/threat-insight/post/cryptxxx-new-ransomware-actors-behind-reveton-dropping-angler , which said it came from the authors of Reveton and was spreading thanks to its inclusion in the Angler exploit kit.

The group using CryptXXX were demanding US$500 per machine encrypted, which Proofpoint noted is at the high end of the extortion scale.

The ransomware encrypts files both on the victim's PC and on attached storage. Kaspersky notes there's a short delay applied to the external storage encryption “to confuse victims and make it harder to detect which websites spread the malware”.

The attackers also steal Bitcoins recorded on victims' hard drives, and copies other data back to base. Victims are told – via a Web page, an image dropped in as the user's desktop, and in a text file in case everything else fails – to download the Tor browser and navigate to an Onion site to get recovery instructions.

Although CryptXXX uses RSA4096, Snow writes it wasn' that hard to crack, and it's added decryption to its RannohDecryptor tool here: https://support.kaspersky.com/viruses/disinfection/8547

(ElReg)

Samker's Computer Forum - SCforum.info


wudz

  • SCF Member
  • **
  • Posts: 12
  • KARMA: 1
  • Gender: Male
thanks for this info

Samker's Computer Forum - SCforum.info


 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising