Posts

Showing posts with the label #Ransomware

RANSOMWARES I WannaCry I Petya

Image

FIGHT BACK RANSOMEWARE !

Image

CTB LOCKER RANSOMWARE

Image
ImageSource CTB LOCKER (Curve-Tor-Bitcoin Locker) also known by Critroni is an example of file encrypting malware infections. The ransomware was released middle of July 2014 targeting windows OS. Curve - comes from its persistent cryptography based on elliptic curves, which encrypts the affected files with a unique RSA key. Tor - comes from the malicious server placed in onion-domain which is very difficult to take down. BitCoin- refers to the possibility to pay in BitCoins, avoiding normal payment systems that can lead back to attackers.  **CTB-Locker is a ransomware variant that first encrypts the files, then claims you have 4 days (96 hours) to make the payment, and if the victim doesn't send money in time, their files gets permanently encrypted.

JIGSAW RANSOMWARE

Image
ImageSource JIGSAW RANSOMWARE This ransomware was first spotted in April 2016. A notorious virus that disables the computer and encrypts the files on it and threatens to delete them, is actually the first one that carries out this threat. Once the virus invades the system a countdown timer starts and if the demanded ransom of $150 is not paid within first hour it deletes one file and continues deleting as the timer resets every 60 minutes deleting more and more files. JIGSAW virus encrypts files using AES-128-CBC and creates a secret decryption key, which is needed to decrypt all these encrypted files. Jigsaw malware creates a number of problems:- Jigsaw drops other type of infections in order to invade your system deeply. Spam files and registries are injected on to your device. A lot of pop-up ads come out on the screen. Slows down system’s performance.

TORRENTLOCKER RANSOMWARE

Image
ImageSource TorrentLocker is a ‘Trojanhorse’ that encrypts files on the compromised computer using a symmetric block cipher AES to encrypt files and an asymmetric cipher RSA to encrypt the key. Monetary ransom is demanded by the criminals to unlock the infected computer. TorrentLocker was first observed in February 2014 and by the year end 5 major releases of this malware were discovered. TorrentLocker infections are initiated with a spam email. The victim is told to pay the amount in BitCoins that usually starts around $550 within 3 days.

TESLACRYPT RANSOMWARE

Image
  ImageSource TeslaCrypt now defunct was a ransomeware Trojan that first came into light in late February 2015. TeslaCrypt was distributed widely via the Angler exploit kit. It exploited AdobeFlash (CVE-2015-0311) and hence downloads the TeslaCrypt. Initially TeslaCrypt targeted game’s-play data for computer games like the  Call of Duty series, World of Warcraft, Mine-Craft & World of Tanks. Newer variants of TeslaCrypt were not only focused on games but also encrypted Word, PDF, JPEG and other files. In all cases, the victim would then be prompted to pay a ransom of $500 worth of BitCoins in order to obtain the key to decrypt the files.

CRYSIS RANSOMWARE

Image
ImageSource CrySiS showed up first in February 2016 is a malware mostly proliferated using deceptive e-mail messages containing infectious attachments with double file extensions and fake software updates (Java, Flash player, etc.) also through social networks and file sharing services. After successful system infiltration, the malware encrypts files stored in computers. CrySiS encryption method is a mixture of RSA and AES-128 algorithms. It adds .CrySiS file extension to the encrypted files and changes the desktop wallpaper by setting a ransom note that varies from $400 to $1200. CrySiS ransomware virus can even hijack your IP and system DNS data. The purpose is to cut off your access to the network. CrySiS ransomware could also build a backdoor for remote hackers who can collect your confidential information.

LOCKY RANSOMWARE

Image
LOCKY quite a derogatory name ! ImageSource LOCKY is a ransomware that scrambles and renames all your files with .locky extension, released in 2016 LOCKY is an email-worm and macro virus Trojan program similar to Cryptolocker. This ransomware is spread through email with an attached MS-Word document containing the malicious macros to thousands of computers. When the victim enables the macros setting in the word, the macros then save and run a binary file that downloads the actual encryption Trojan, which will encrypt all files to a unique 16-digit combination using the RSA-2048 and AES-1024 algorithms. **The files could be decrypted using a decrypter given by criminals costing 0.5 BitCoins.

LECHIFFRE RANSOMWARE

Image
LECHIFFRE The manually distributed malware ! ImageSource LECHIFFRE means “the number” ! Unlike other cyber criminals manually proliferate this malware on the compromised and run a malicious executable file. Once LeChiffre infects the device successfully, it changes the system settings and encrypts the files using an RSA 1024 algorithm. To inform users about their options to recover the enciphered data an email address is provided to contact the cyber criminals. **Lechiffre reported in spring of 2015 infected three Indian banks and a pharmaceutical company, demanding one BitCoin per compromised computer and reportedly causing millions of dollars in damage.

KERANGER RANSOMWARE

Image
KERANGER the first wild  MacOS Ransomware ! KeRanger also known by OSX.KeRanger.A is known as the first CryptoRansomware Trojan effectively targeting Apple computers. Discovered on March 4, 2016, has affected more than 7,000 Mac users. KeRanger is remotely executed on the victim's computer from a flaw in transmission of Bit Torrent client. The only way this malware could invade the victim's computer was by using a valid developer signature issued by Apple, that allowed it to bypass Apple's built-in OS X’s security feature designed to block software’s from untrusted sources. **The malware display’s a ransom message, demanding the victim to pay 1 BitCoin (~ $408)