2、勒索软件Locky新变种使用新的加密文件扩展名
标题:Locky Adds Support for a New "S**T" Extension
New spam campaign has made victims all over the world
作者信息:Oct 24, 2016 21:35 GMT By Catalin Cimpanu
//BEGIN
Security researcher MalwareHunterTeam tells Softpedia that the infamous Locky ransomware has returned today with a new spam campaign that's spreading a new version of the ransomware.
研究人员发现臭名昭著的勒索软件Locky最近又出现了新的变种了。
//END
For example, a file named photo.png would become [random_characters].shit. Previously, Locky had used extensions such as LOCKY, ZEPTO, and ODIN.
As for the random file names, MalwareHunterTeam said the format is "8-4-4-4-12.shit, where the first 8-4-4 characters are unique for infection, and the last 4-12 is unique for the file."
一旦感染了该勒索软件,受害文件的文件名会变成随机数,扩展名则变成了shit.这与以前的版本不同,以前的版本出现过三种不同的扩展名:LOCKY,ZEPTO以及ODIN等。
至于这里的随机数文件名,也有一些规律可循:采用的是8-4-4-4-12.shit的格式。其中前三部分8-4-4是感染标注;4-12是文件本身的标注。
点评:对付勒索软件,备份备份再备份。 |