joewanny
23-09-2015, 22:52
Buonasera a tutti.
Il computer di un mio cliente ha contratto un virus che gli ha criptato moltissimi files in un disco di rete condiviso, rinominandoli con estensione .0x0
In ogni cartella in cui ci sono files criptati inoltre sono comparsi due documenti con i nomi VIRUSATTACK.txt e secret.key.
Vi riporto il contenuto del file di testo:
Hello. All your files have been encrypted using our private key. There is no way to recover them without our assistance. If you want to get your files back, you must be ready to pay for them. If you are ready to pay, then get in touch with us using a secure and anonymous p2p messenger. We have to use a messenger, because standard emails get blocked quickly and if our email gets blocked your files will be lost forever. So…
Go to http://bitmessage.org/, download and run Bitmessage. Click ‘Your Identities’ tab, then click ‘New’, then click ‘OK’. Then click ‘Send’ tab.
TO: BM-2cUKkir7WzC1WoZCtZJpzzHqNuQ9aW31Gk
SUBJECT: name of your PC.
MESSAGE: Hi, I’m ready to pay.
Click ‘Send’ button.
You are done.
To get the fastest reply from us with all further instructions, please keep Bitmessage running on your computer all the time, if possible. If you cooperate and follow the instructions, you will get all your files back intact and very, very soon. Thank you.
Il contenuto del secondo files è una lunga stringa alfanumerica che presumo essere la chiave pubblica della criptazione.
Qualcuno ha già avuto a che fare con questo virus?
Io ho fatto una ricerca su google e su vari forum e non ho trovato nulla.
Ho anche fatto una scansione antivirus approfondita di tutti i pc della lan con AVG Business e nessuno ha segnalato virus.
E' una variante così nuova da non venire rilevata?
Grazie per le eventuali risposte, vi farò sapere degli sviluppi.
Il computer di un mio cliente ha contratto un virus che gli ha criptato moltissimi files in un disco di rete condiviso, rinominandoli con estensione .0x0
In ogni cartella in cui ci sono files criptati inoltre sono comparsi due documenti con i nomi VIRUSATTACK.txt e secret.key.
Vi riporto il contenuto del file di testo:
Hello. All your files have been encrypted using our private key. There is no way to recover them without our assistance. If you want to get your files back, you must be ready to pay for them. If you are ready to pay, then get in touch with us using a secure and anonymous p2p messenger. We have to use a messenger, because standard emails get blocked quickly and if our email gets blocked your files will be lost forever. So…
Go to http://bitmessage.org/, download and run Bitmessage. Click ‘Your Identities’ tab, then click ‘New’, then click ‘OK’. Then click ‘Send’ tab.
TO: BM-2cUKkir7WzC1WoZCtZJpzzHqNuQ9aW31Gk
SUBJECT: name of your PC.
MESSAGE: Hi, I’m ready to pay.
Click ‘Send’ button.
You are done.
To get the fastest reply from us with all further instructions, please keep Bitmessage running on your computer all the time, if possible. If you cooperate and follow the instructions, you will get all your files back intact and very, very soon. Thank you.
Il contenuto del secondo files è una lunga stringa alfanumerica che presumo essere la chiave pubblica della criptazione.
Qualcuno ha già avuto a che fare con questo virus?
Io ho fatto una ricerca su google e su vari forum e non ho trovato nulla.
Ho anche fatto una scansione antivirus approfondita di tutti i pc della lan con AVG Business e nessuno ha segnalato virus.
E' una variante così nuova da non venire rilevata?
Grazie per le eventuali risposte, vi farò sapere degli sviluppi.