1、研究者发现勒索软件新变种CryptoLuck
标题:CryptoLuck Ransomware Emerges
作者信息:November 16, 2016 By Ionut Arghire
//BEGIN
A new ransomware family spotted for the first time recently is already being distributed via an exploit kit (EK).
Dubbed CryptoLuck, the new ransomware variant was discovered by "Kafeine", a Proofpoint researcher and maintainer of the Malware don't need Coffee blog. Noteworthy about the malware is that it abuses the legitimate GoogleUpdate.exe executable and leverages DLL hijacking to infect computers, in addition to asking for a 2.1 Bitcoin (around $1,500) ransom to be paid within 72 hours.
安全专家又新近发现了一种勒索软件家族,名称为CryptoLuck(其实没什么luck的,不过是因为被加密的文件的扩展名有感染ID和单词luck而已),其主要特点是利用漏洞利用包EK传播,并利用合法的Google升级程序GoogleUpdate.exe同时劫持DLL进行传播感染。勒索的金额是大约1500美金才能提供解密钥匙,同时必须在3天内支付,否则会更贵。
//END
The ransomware appends the .[victim_id]_luck extension to the encrypted files and security researchers say that the threat targets a couple of hundreds of file extensions to encrypt. However, the malware skips files that contain specific strings: Windows, Program Files, Program Files (x86), ProgramData, AppData, Application Data, Temporary Internet Files, Temp, Games, nvidia, intel, $Recycle.Bin, and Cookies.
As soon as the encryption process has been completed, the malware displays a ransom note which provides users with detailed instructions on how to download the decryptor and make the ransom payment.
A Decryption Wizard walks the victims through making the payment and also waits for the operation to be completed, after which it informs the victim that the affected files will be automatically decrypted.
该勒索软件除了不侵害系统目录下的文件,几乎无差别的侵害其他所有用户有用的文件。这些不侵害的目录有13个:Windows, Program Files, Program Files (x86), ProgramData, AppData, Application Data, Temporary Internet Files, Temp, Games, nvidia, intel, $Recycle.Bin以及 Cookies.被加密的文件的扩展名会被增加一个字符串,这个字符串由一个唯一的ID数字加单词luck组成。一旦加密过程完成,那么该恶意代码会显示一个提示,告知受害者如何找回其原始的文件,当然主要其实就是解密方法。
//下载:
CryptoLuck Technical Analysis.pdf
(497.83 KB, 下载次数: 251)
文件名:CryptoLuck Technical Analysis.pdf
文件大小:509,775 bytes
MD5 : F4DA84B654AC7E14DF2C7091BB992CDF
点评:勒索软件又占据榜首了。对付勒索软件建议备份备份再备份。 |