|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Junior Member
Iscritto dal: May 2015
Messaggi: 3
|
Nuova variante di CTB locker - settembre 2015
Buonasera a tutti.
Il computer di un mio cliente ha contratto un virus che gli ha criptato moltissimi files in un disco di rete condiviso, rinominandoli con estensione .0x0 In ogni cartella in cui ci sono files criptati inoltre sono comparsi due documenti con i nomi VIRUSATTACK.txt e secret.key. Vi riporto il contenuto del file di testo: Hello. All your files have been encrypted using our private key. There is no way to recover them without our assistance. If you want to get your files back, you must be ready to pay for them. If you are ready to pay, then get in touch with us using a secure and anonymous p2p messenger. We have to use a messenger, because standard emails get blocked quickly and if our email gets blocked your files will be lost forever. So… Go to http://bitmessage.org/, download and run Bitmessage. Click ‘Your Identities’ tab, then click ‘New’, then click ‘OK’. Then click ‘Send’ tab. TO: BM-2cUKkir7WzC1WoZCtZJpzzHqNuQ9aW31Gk SUBJECT: name of your PC. MESSAGE: Hi, I’m ready to pay. Click ‘Send’ button. You are done. To get the fastest reply from us with all further instructions, please keep Bitmessage running on your computer all the time, if possible. If you cooperate and follow the instructions, you will get all your files back intact and very, very soon. Thank you. Il contenuto del secondo files è una lunga stringa alfanumerica che presumo essere la chiave pubblica della criptazione. Qualcuno ha già avuto a che fare con questo virus? Io ho fatto una ricerca su google e su vari forum e non ho trovato nulla. Ho anche fatto una scansione antivirus approfondita di tutti i pc della lan con AVG Business e nessuno ha segnalato virus. E' una variante così nuova da non venire rilevata? Grazie per le eventuali risposte, vi farò sapere degli sviluppi. |
|
|
|
|
#2 |
|
Senior Member
Iscritto dal: Jan 2010
Messaggi: 37128
|
A me risulta che anche precedenti versioni de questo malware non sempre fossero rilevate dall'AV. Questo è un nuovo genere di malware piuttosto anomalo rispetto ai malware classici. Per quanti riguarda i file criptati, sono persi.
|
|
|
|
|
#3 |
|
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
__________________
Try again and you will be luckier.
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 15:30.


















