Posts
Showing posts with the label #malware
CTB LOCKER RANSOMWARE
- Get link
- X
- Other Apps
ImageSource CTB LOCKER (Curve-Tor-Bitcoin Locker) also known by Critroni is an example of file encrypting malware infections. The ransomware was released middle of July 2014 targeting windows OS. Curve - comes from its persistent cryptography based on elliptic curves, which encrypts the affected files with a unique RSA key. Tor - comes from the malicious server placed in onion-domain which is very difficult to take down. BitCoin- refers to the possibility to pay in BitCoins, avoiding normal payment systems that can lead back to attackers. **CTB-Locker is a ransomware variant that first encrypts the files, then claims you have 4 days (96 hours) to make the payment, and if the victim doesn't send money in time, their files gets permanently encrypted.
TORRENTLOCKER RANSOMWARE
- Get link
- X
- Other Apps
ImageSource TorrentLocker is a ‘Trojanhorse’ that encrypts files on the compromised computer using a symmetric block cipher AES to encrypt files and an asymmetric cipher RSA to encrypt the key. Monetary ransom is demanded by the criminals to unlock the infected computer. TorrentLocker was first observed in February 2014 and by the year end 5 major releases of this malware were discovered. TorrentLocker infections are initiated with a spam email. The victim is told to pay the amount in BitCoins that usually starts around $550 within 3 days.
CRYSIS RANSOMWARE
- Get link
- X
- Other Apps
ImageSource CrySiS showed up first in February 2016 is a malware mostly proliferated using deceptive e-mail messages containing infectious attachments with double file extensions and fake software updates (Java, Flash player, etc.) also through social networks and file sharing services. After successful system infiltration, the malware encrypts files stored in computers. CrySiS encryption method is a mixture of RSA and AES-128 algorithms. It adds .CrySiS file extension to the encrypted files and changes the desktop wallpaper by setting a ransom note that varies from $400 to $1200. CrySiS ransomware virus can even hijack your IP and system DNS data. The purpose is to cut off your access to the network. CrySiS ransomware could also build a backdoor for remote hackers who can collect your confidential information.
LOCKY RANSOMWARE
- Get link
- X
- Other Apps
LOCKY quite a derogatory name ! ImageSource LOCKY is a ransomware that scrambles and renames all your files with .locky extension, released in 2016 LOCKY is an email-worm and macro virus Trojan program similar to Cryptolocker. This ransomware is spread through email with an attached MS-Word document containing the malicious macros to thousands of computers. When the victim enables the macros setting in the word, the macros then save and run a binary file that downloads the actual encryption Trojan, which will encrypt all files to a unique 16-digit combination using the RSA-2048 and AES-1024 algorithms. **The files could be decrypted using a decrypter given by criminals costing 0.5 BitCoins.