1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Jigsaw Ransomware becomes CryptoHitman with Porno Extension

Discussion in 'General Malware And Security' started by starbuck, May 12, 2016.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    The notorious Jigsaw Ransomware has rebranded itself as CryptoHitman and now uses the character from the popular Hitman video games and movies.
    In addition to adding the Hitman character to its locker screen, CryptoHitman also covers the lock screen with pornographic images that are definitely not safe for work
    .

    274f29726b781c59a542d9d7d9961dc1.jpg
    Blurred out Hitman Ransomware Locker Screen

    Like the previous Jigsaw ransomware infections, CryptoHitman will encrypt your data with AES encryption and demand a ransom payment before it will decrypt your files.
    In order to pay this ransom you will be required to send payment to cryptohitman@yandex.com.

    Unfortunately, this version will still delete your files every time you restart the process and when the timer runs down to zero.

    The only major differences is the new pornographic locker screen, the use of the Hitman character, the new .porno extension that is added to all encrypted files, and new filenames for the ransomware executables.
    Otherwise, this ransomware performs the same as the original Jigsaw Ransomware.

    A big thanks to Fletch Sec for sharing the sample!
    Last, but not least, the owners of the Hitman franchise are not affiliated to this ransomware at all!

    How to decrypt and remove the Jigsaw Ransomware

    Thankfully, DemonSlay335was able to modify his existing Jigsaw Ransomware decryptor to also decrypt files encrypted by CryptoHitman.
    To decrypt your files, the first thing that you should do is terminate the %LocalAppData%\Suerdf\suerdf.exe
    and %AppData%\Mogfh\mogfh.exe processes in Task Manager to prevent any further files from being deleted.
    You should then run MSConfig and disable the startup entry related to these executables.

    Once you have terminated the ransomware and disabled its startup, let's proceed with decrypting the files.
    The first step is to download and extract the Jigsaw Decryptor from the following URL:

    https://download.bleepingcomputer.com/demonslay335/JigSawDecrypter.zip

    Then double-click on the JigSawDecrypter.exe file to launch the program.
    When the program launches you will be greeted with a screen similar to the one below.

    6ac6740b75cea3e4c75f5baa1be12f26.png

    To decrypt your files simply select the directory and click on the Decrypt My Files button.
    If you wish to decrypt the whole drive, then you can select the C: drive itself.
    It is advised that you do not put a checkmark in the Delete Encrypted Files option until you have confirmed that the tool can properly decrypt your files.

    When it has finished decrypting your files, the screen will appear as below.

    f5eb58882f42689f971d77dd61310e0c.png

    Now that your files are decrypted, I suggest that you run an antivirus or anti-malware program to scan your computer for infections.



    Source & Credit:
    Lawrence Abrams
    http://www.bleepingcomputer.com/new...re-becomes-cryptohitman-with-porno-extension/
     
  2. Bill

    Bill Registered Members

    Joined:
    Oct 30, 2010
    Messages:
    601
    Location:
    Southeastern US
    Computer Brand or Motherboard:
    Asus P8Z77-V
    CPU:
    Intel i5 3570
    Memory:
    8GB Kingston DDR3 1600
    Hard Drive:
    Plextor SSD SATA 6 128 GB, WD Velociraptor 150g
    Graphics Card:
    eVGA GTX 550 TI
    Power Supply:
    Antec NeoPower 550w
    Good stuff Pete.
     
  3. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    You never know when you may need one of these decryptors.
    Let's hope they keep updating them.
     
  4. Kenny94

    Kenny94 Registered Members

    Joined:
    Jan 21, 2016
    Messages:
    419
    Location:
    SC
    Operating System:
    OS X
    Computer Brand or Motherboard:
    iPad Air, HP Chromebook and Compaq laptop with xp
    Here's the video with the tool in action@ 4.20 part of the video.


     

Share This Page