skip to main | skip to sidebar

Media Informasi

Pages

  • Home
  • Download

Locky Ransomware switches to THOR Extension after being a Bad Malware

Thursday, November 17, 2016


Locky Ransomware switches to THOR Extension after being a Bad Malware; New variants of Locky are being released at a rapid rate lately. Yesterday, we had a new variant that appends the .SH*T extension to encrypted files and today they switched to using the .THOR extension. Maybe Locky had its mouth washed out with soap for cursing? Regardless of the reasons for the switch, I am happy as I won't have posts with curse words all over the forums.


Encrypted Public Sample Pictures Folder
Encrypted Public Sample Pictures Folder

The Thor Locky variant being distributed via SPAM Campaigns

This new variant is currently being distributed through a variety of SPAM campaigns with VBS, JS, and other attachments. One SPAM campaign that I have seen has a subject line of Budget forecast and contains a ZIP attachment called budget_xls_[random_chars].zip.


Budget Forecast Locky SPAM Email
Budget Forecast Locky SPAM Email
This budget_xls zip file will contain a VBS script with a name like budget A32aD85 xls.vbs as shown below.


Locky Installer
Locky Installer

Locky continues to use a DLL Installer

When the Locky SPAM attachments are executed, they will download an encrypted DLL, decrypt it on the victim's computer, and then execute it using Rundll32.exe to encrypt a victim's files.


Executing the DLL via Rundll32
Executing the DLL via Rundll32
The DLLs are currently being executed with the following arguments:
C:\Windows\SysWOW64\rundll32.exe %Temp%\MWGUBR~1.dll,EnhancedStoragePasswordConfig 147
Once executed it will scan for targeted file types and encrypt them to a scrambled name with the .thor exension. For example, a file called accounting.xlsx could be renamed to 024BCD33-41D1-ACD3-3EEA-84083E322DFA.thor. The format for this naming scheme is first_8_hexadecimal_chars_of_id]-[next_4_hexadecimal_chars_of_id]-[next_4_hexadecimal_chars_of_id]-[4_hexadecimal_chars]-[12_hexadecimal_chars].thor.

It is not possible to decrypt the Locky Ransomware Thor Variant

Unfortunately, there is still no realistic way to decrypt the Locky Ransomware regardless of the extension.
At this time the only way to recover encrypted files is via a backup, or if you are incredibly lucky, through Shadow Volume Copies. Though Locky does attempt to remove Shadow Volume Copies, in rare cases ransomware infections fail to do so for whatever reason. Due to this, if you do not have a viable backup, I always suggest people try as a last resort to restore encrypted files from Shadow Volume Copies as well.

Source :  http://www.bleepingcomputer.com/news/security/locky-ransomware-switches-to-thor-extension-after-being-a-bad-malware/
Posted by tiyonih at 10:18:00 AM
Labels: Berita Terkini encrypt Informasi teknologi Ransomware software virus
Facebook Twitter

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Kabar Populer

Loading...

Statistik

web statistics

Advertisement

Toko jual popok dan susu online

Most Popular

  • Penipuan Transaksi Oleh Oknum Menggunakan Mandiri E-Cash
    Penipuan Menggunakan Mandiri E-Cash; Berhubung ternyata banyak yang jadi korban, maka dibawah ini adalah ringkasan CIRI-CIRI PENIPUAN:...
  • Download Windows Movie Maker 6.0 Full Version 2014
    Download Windows Movie Maker 6.0 Full Version 2014 |   Pada artikel kali ini admin akan share software yang tentunya mungkin berguna unt...
  • MAKANAN SEHAT UNTUK IBU HAMIL
    MAKANAN SEHAT UNTUK IBU HAMIL 1. Makanan sehat untuk ibu hamil harus mengandung DHA Asam dokosaheksaenoat (juga sering dikenal sebag...
  • Catatan Brutal Bule Prancis Pembunuh Polisi di Bali
    Amokrane Sabet – Pria berusia 49 tahun berkebangsaan Prancis petarung Mixed Martial Arts (MMA) telah membuat resah warga Desa Beraw...
  • 11 hotel tengah hutan di Bandung yang cocok untuk kabur dari bisingnya kota
    villa bandung : Mau weekend getaway yang singkat, atau liburan yang lumayan sedikit lebih lama, kamu akan menemukan suasana sepi yang ...
  • Microsoft Office 2016 VL ProPlus English (x86-x64)
    Release Info - Language: English (en-US) - Channel: Volume License - Version: 16.0.4456.1003 - Architectures: x86/x64 - Proofing Too...
  • Konfigurasi Switch Raisecom
    ------------------------------------- Konfigurasi Melalui Console ------------------------------------- Masuk Melalui Hyper Te...
  • Step by step membuat Owncloud Server dengan Windows Server 2008 R2
    kali ini saya membuat tutorial OwnCloud Server di Windows Server 2008 R2 . Dan OwnCloud Server ini sangat bermanfaat bagi kita untuk meny...
  • Cara install appstore yang versi ios 6.1.6 ipod touch 4
    Cara install appstore yang versi ios 6.1.6 ipod touch 4 Ada sebagian app yg hanya bisa diinstal langsung dari App Store bawaan iPhon...
  • The Password does not Meet The Password Policy Requirements
    window server 2003 the password does not meet the password policy requirements The Password does not Meet The Password Poli...

Categories

  • Informasi teknologi (47)
  • Berita Terkini (43)
  • share (23)
  • Informasi (17)
  • like (15)
  • berita (12)
  • software (12)
  • virus (12)
  • Ransomware (10)
  • Hiburan (9)
  • comment (9)
  • long weekend (9)
  • cryptowall (7)
  • hack (7)
  • encrypt (6)
  • tips&trik (6)
  • cloud (5)
  • live (5)
  • whatsapp (5)
  • facebook (4)
  • Film (3)
  • Olah Raga (3)
  • bisnis online (3)
  • google (3)
  • youtube (3)
  • Cloud File Server (2)
  • berita ekonomi (2)
  • google translate (2)
  • kesehatan (2)
  • G30S (1)
  • PKI (1)
  • RSS Feed (1)
  • Usaha (1)
  • Windows (1)
  • asus (1)
  • bus (1)
  • cinema (1)
  • hamil (1)
  • honda (1)
  • horor (1)
  • jadwal sholat (1)
  • otomotif (1)
  • owncloud (1)
  • sejarah (1)
  • spyware (1)
  • telolet (1)
  • tips&rick (1)
  • translate (1)
  • uang palsu (1)

About Me

tiyonih
View my complete profile

Followers

 
Copyright © 2016. Media Informasi.
Design by Herdiansyah Hamzah. & Distributed by Free Blogger Templates
Creative Commons License