Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Tuesday, 26 November 2019

A New Ransomware Called DeathRansom

A ransomware called DeathRansom began with a rocky start, but has now resolved it's issues and has begun to infect victims and encrypt their data.


When DeathRansom was first being distributed, it pretended to encrypt files, but researchers and users found that they could just remove the appended .wctc extension and the files would become usable again.
Starting around November 20th, though, something changed.


Not only were victim's files actually becoming encrypted, but there was a surge of submissions related to DeathRansom on the ransomware identification site, ID Ransomware.

While the numbers have dwindled since that initial surge, we are still seeing a steady trickle of new victims, which means that there is mostly likely an active distribution campaign underway. Unfortunately, we have not discovered as of yet how this ransomware is being distributed.
What we do know is that like other ransomware, when DeathRansom is launched it will attempt to clear shadow volume copies.
It will then encrypt all files on the victim's computer other than those found whose full pathnames contain the following strings:
programdata
$recycle.bin
program files
windows
all users
appdata
read_me.txt
autoexec.bat
desktop.ini
autorun.inf
ntuser.dat
iconcache.db
bootsect.bak
boot.ini
ntuser.dat.log
thumbs.db
Unlike the previous non-encryption version, the working DeathRansom variants do not append an extension to encrypted files and they just retain their original name.  The data in these files is encrypted.

The only way to identify that the file is encrypted by DeathRansom is by the ABEFCDAB file marker appended to the end of encrypted files.

In every folder that a file is encrypted, the ransomware will create a ransom note named read_me.txt that contains a unique "LOCK-ID" for the victim and an email address to contact the ransomware developer or affiliate.

The ransomware is currently being analyzed and it is not known if it can be decrypted at this time.


One strange thing that was noticed is that numerous victims who have been infected by DeathRansom were also infected by the STOP Ransomware.
This is seen in one Reddit post and numerous submissions to ID-Ransomware where the victim upload a DeathRansom ransom note and a STOP Djvu encrypted file as part of the same submission.
As STOP is only distributed through adware bundles and cracks, it is possible the DeathRansom may be distributed in a similar manner.


Source : Bleepingcomputer.com


Sunday, 14 May 2017

WannaCry Attacks All Over The World


Earlier today, our products detected and successfully blocked a large number of ransomware attacks around the world. In these attacks, data is encrypted with the extension “.WCRY” added to the filenames.
Our analysis indicates the attack, dubbed “WannaCry”, is initiated through an SMBv2 remote code execution in Microsoft Windows. This exploit (codenamed “EternalBlue”) has been made available on the internet through the Shadowbrokers dump on April 14th, 2017 and patched by Microsoft on March 14.
Unfortunately, it appears that many organizations have not yet installed the patch.
Spain’s Computer Emergency Response Team CCN-CERT, posted an alert on their site about a massive ransomware attack affecting several Spanish organizations. The alert recommends the installation of updates in the Microsoft March 2017 Security Bulletin as a means of stopping the spread of the attack.
The National Health Service (NHS) in the U.K. also issued an alert and confirmed infections at 16 medical institutions. We have confirmed additional infections in several additional countries, including Russia, Ukraine, and India.
It’s important to understand that while unpatched Windows computers exposing their SMB services can be remotely attacked with the “EternalBlue” exploit and infected by the WannaCry ransomware, the lack of existence of this vulnerability doesn’t really prevent the ransomware component from working. Nevertheless, the presence of this vulnerability appears to be the most significant factor that caused the outbreak.
Currently, we have recorded more than 45,000 attacks of the WannaCry ransomware in 74 countries around the world, mostly in Russia. It’s important to note that our visibility may be limited and incomplete and the range of targets and victims is likely much, much higher.
The malware used in the attacks encrypts the files and also drops and executes a decryptor tool. The request for $600 in Bitcoin is displayed along with the wallet. It’s interesting that the initial request in this sample is for $600 USD, as the first five payments to that wallet is approximately $300 USD. It suggests that the group is increasing the ransom demands.


The tool was designed to address users of multiple countries, with translated messages in different languages.
Note that the “payment will be raised” after a specific countdown, along with another display raising urgency to pay up, threatening that the user will completely lose their files after the set timeout. Not all ransomware provides this timer countdown.
To make sure that the user doesn’t miss the warning, the tool changes the user’s wallpaper with instructions on how to find the decryptor tool dropped by the malware.
For convenient bitcoin payments, the malware directs to a page with a QR code at btcfrog, which links to their main bitcoin wallet 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
For command and control, the malware extracts and uses Tor service executable with all necessary dependencies to access the Tor network:
In terms of targeted files, the ransomware encrypts files with the following extensions:
.der, .pfx, .key, .crt, .csr, .p12, .pem, .odt, .ott, .sxw, .stw, .uot, .3ds, .max, .3dm, .ods, .ots, .sxc, .stc, .dif, .slk, .wb2, .odp, .otp, .sxd, .std, .uop, .odg, .otg, .sxm, .mml, .lay, .lay6, .asc, .sqlite3, .sqlitedb, .sql, .accdb, .mdb, .dbf, .odb, .frm, .myd, .myi, .ibd, .mdf, .ldf, .sln, .suo, .cpp, .pas, .asm, .cmd, .bat, .ps1, .vbs, .dip, .dch, .sch, .brd, .jsp, .php, .asp, .java, .jar, .class, .mp3, .wav, .swf, .fla, .wmv, .mpg, .vob, .mpeg, .asf, .avi, .mov, .mp4, .3gp, .mkv, .3g2, .flv, .wma, .mid, .m3u, .m4u, .djvu, .svg, .psd, .nef, .tiff, .tif, .cgm, .raw, .gif, .png, .bmp, .jpg, .jpeg, .vcd, .iso, .backup, .zip, .rar, .tgz, .tar, .bak, .tbk, .bz2, .PAQ, .ARC, .aes, .gpg, .vmx, .vmdk, .vdi, .sldm, .sldx, .sti, .sxi, .602, .hwp, .snt, .onetoc2, .dwg, .pdf, .wk1, .wks, .123, .rtf, .csv, .txt, .vsdx, .vsd, .edb, .eml, .msg, .ost, .pst, .potm, .potx, .ppam, .ppsx, .ppsm, .pps, .pot, .pptm, .pptx, .ppt, .xltm, .xltx, .xlc, .xlm, .xlt, .xlw, .xlsb, .xlsm, .xlsx, .xls, .dotx, .dotm, .dot, .docm, .docb, .docx, .doc
The file extensions that the malware is targeting contain certain clusters of formats including:
  1. Commonly used office file extensions (.ppt, .doc, .docx, .xlsx, .sxi).
  2. Less common and nation-specific office formats (.sxw, .odt, .hwp).
  3. Archives, media files (.zip, .rar, .tar, .bz2, .mp4, .mkv)
  4. Emails and email databases (.eml, .msg, .ost, .pst, .edb).
  5. Database files (.sql, .accdb, .mdb, .dbf, .odb, .myd).
  6. Developers’ sourcecode and project files (.php, .java, .cpp, .pas, .asm).
  7. Encryption keys and certificates (.key, .pfx, .pem, .p12, .csr, .gpg, .aes).
  8. Graphic designers, artists and photographers files (.vsd, .odg, .raw, .nef, .svg, .psd).
  9. Virtual machine files (.vmx, .vmdk, .vdi).
The WannaCry dropper drops multiple “user manuals” on different languages:
Bulgarian, Chinese (simplified), Chinese (traditional), Croatian, Czech, Danish, Dutch, English, Filipino, Finnish, French, German, Greek, Indonesian, Italian, Japanese, Korean, Latvian, Norwegian, Polish, Portuguese, Romanian, Russian, Slovak, Spanish, Swedish, Turkish, Vietnamese


source : Securelist.com


Wednesday, 1 February 2017

Ransomware Mulai Memanfaatkan Media Sosial

      Apakah anda penguna Facebook atau LinkedIn, sebaiknya Anda mulai berhati-hati. Sebab, beberapa waktu lalu diketahui terdapat kerentanan (vulnerabilityin) berupa celah keamanan pada kedua social network tersebut. Kerentanan ini membuat PC akan mudah terinfeksi cukup dengan membuka file gambar. 


       Ransomware yang bernama Locky ini juga diketahui telah memiliki metode baru yang efektif dalam menginfeksi pengguna PC. Menurut perusahaan sekuriti Check Point, penyerang meng-upload kode berbahaya dengan memanfaatkan celah keamanan website dalam menangani (membuka) file gambar. Metode ini bisa memaksa korbannya untuk men-download file gambar melalui browser. Saat gambar dibuka, sistem PC mereka akan terinfeksi oleh malware jenis ransomware Locky.

       Seperti ransomware lainnya, Locky meng-encrypt file-file yang ada di PC korban (dokumen, video, audio, dan lain-lain) dan menuntut sejumlah pembayaran (biasanya dengan Bitcoin) kepada sang korban agar file bisa diakses kembali (decrypt). Locky mulai menyebar pada awal 2016 melalui email dan beberapa jenis file lainnya. Meski cara menghindari dari infeksinya relatif mudah, yakni dengan tidak membuka file gambar, metode ransomware dalam memilih website yang biasanya dipercaya sistem keamanannya (Facebook dan LinkedIn) patut diwaspadai oleh setiap pengguna.


       Sejauh ini, Facebook sudah mengetahui masalah tersebut dan menyalahkan ekstensi browser Chrome yang buruk sehingga mengirimkan pesan ke pengguna PC. Kini Facebook mengklaim telah memblokirnya. Benar tidaknya jawaban Facebook, Check Point memberikan saran penting bagi pengguna yang terlanjur mengklik gambar tersebut dan langsung di-download oleh browser. Pengguna dianjurkan untuk sama sekali tidak membuka file gambar tersebut, terutama file dengan ekstensi yang tidak umum.


Source : Chip magz Desember 2016