1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

New Cryptowall ransomware makes locked files even harder to recover

Discussion in 'Security Updates' started by starbuck, Nov 9, 2015.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    The new ransomware variant encrypts and scrambles file names, making it harder to know what to recover.

    9174c1c89d6a193018bcae804e9644cf.png

    The ransomware, which upon install encrypts files making it almost impossible to regain access, now scrambles file names making it even harder for victims to know which files are which. System restore points are also erased, taking away the option of returning to a previously saved state.

    Adding insult to injury, the malware also mocks the user, congratulating the user for becoming [sic] "part of large community," according to BleepingComputer, which first detailed the changes.

    The ransomware continues to use bitcoin as the means of payment, which like in previous versions is handled by a centralized Tor-based command-and-control server to store decryption keys, making the attackers almost impossible to trace.

    Users are tricked into opening a zipped attachment from a spam campaign, which contains a malicious file, triggering an executable payload.

    Ransomware hits thousands every week, and costs users $18 million in losses, according to estimates from the FBI.

    While Cryptowall remains by far one of the most common families of the malware, its success has given rise to new families and variants.

    But not all malware is created equally, nor is coded correctly, which in some cases can cause devastating data loss.

    New ransomware discovered late last month uses a single same master encryption key to encrypt files, making it easier for victims to share keys and regain access to files without paying the ransom. But analysis showed that badly-written code would destroy a victim's data because, when the files were encrypted, the key wasn't saved.

    Storing a backup can mitigate the damage done by file-encrypting ransomware.


    Source:
    http://www.zdnet.com/article/new-ba...are-destroys-data-by-mistake/#ftag=RSSbaffb68
     

Share This Page