Post reply

Name:
Email:
Subject:
Message icon:

Verification:
Type the letters shown in the picture
Listen to the letters / Request another image

Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

shortcuts: hit alt+s to submit/post or alt+p to preview


Topic Summary

Posted by: wudz
« on: 21. September 2016., 22:40:47 »

thanks for this info
Posted by: Samker
« on: 02. May 2016., 08:51:58 »



Kaspersky has announced it's decrypted yet another crypto-extortion racket.

Writing here: https://blog.kaspersky.com/cryptxxx-ransomware/11939/ , the company's John Snow says Kaspersky bods can now untangle data after a CryptXXX attack.

CryptXXX was described in mid-April by Proofpoint: https://www.proofpoint.com/us/threat-insight/post/cryptxxx-new-ransomware-actors-behind-reveton-dropping-angler , which said it came from the authors of Reveton and was spreading thanks to its inclusion in the Angler exploit kit.

The group using CryptXXX were demanding US$500 per machine encrypted, which Proofpoint noted is at the high end of the extortion scale.

The ransomware encrypts files both on the victim's PC and on attached storage. Kaspersky notes there's a short delay applied to the external storage encryption “to confuse victims and make it harder to detect which websites spread the malware”.

The attackers also steal Bitcoins recorded on victims' hard drives, and copies other data back to base. Victims are told – via a Web page, an image dropped in as the user's desktop, and in a text file in case everything else fails – to download the Tor browser and navigate to an Onion site to get recovery instructions.

Although CryptXXX uses RSA4096, Snow writes it wasn' that hard to crack, and it's added decryption to its RannohDecryptor tool here: https://support.kaspersky.com/viruses/disinfection/8547

(ElReg)
Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising