New ransomware detection not only encrypts files but also helps 'clean up' the system
Rxomware vxCrypter is probably the first ransomware in the world that not only encrypts the victim's data but also helps clean up their computers by deleting duplicate files on the system.
Last week, security researchers at BleepingComputer discovered a new ransomware called vxCrypter is currently being developed and spread globally. This is a ransomware .NET and is based on an old ransomware that has never been distributed, called vxLock.
The list of nearly 600 MAC addresses was targeted in the recent hacking of millions of ASUS computer users
When first experimenting with this ransomware software, the researchers found that in addition to encrypting system data like the usual way that extortion codes often do, it also deletes all files. duplicate in the directory and leave only one file, as illustrated in the images below. According to experts, it is likely that this is just an error in the encryption process because as mentioned, this ransomware software is still in the development stage, so if something goes wrong It is understandable.
- The alarming increase in the number of attacks targeted at IoT devices
After conducting some necessary tests, security researcher Michael Gillespie said that deleting the file is intentional because ransomware is actually deleting duplicate files and not deleting them. Moreover, this is also the first ransomware software in the world to be recorded with this strange behavior.
When analyzing ransomware, Michael Gillespie noticed that it would track the SHA256 hash functions of each encrypted file. Because ransomware has encrypted many different files on the system, so if it encounters the same SHA256 hash function (duplicate), it will delete the file immediately instead of decoding.
- Endpoint Detection and Response threats, an emerging security technology
It should be noted, however, that this ransomware only deletes duplicate files that have tail extensions that were originally targeted for encryption, including:
.txt, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .sqlite, .odt, .jpg, .jpeg, .bmp, .gif, .png, .csv, .sql, .mdb , .sln, .php, .asp, .aspx, .html, .xml, .psd, .xsd, .cpp, .c, .h, .hpp, .htm, .py, .reg, .rb,. pl, .zip, .rar, .tgz, .key, .jsp, .db, .sqlite3, .sqlitedb, .bat, .bak, .7z, .avi, .fla, .flv, .java, .mpeg, .pem, .wmv, .tar, .tgz, .tiff, .tif
For files in a format other than the above list, such as .exe or .dll, the duplicate file will still be preserved.
Now researchers have not been able to confirm exactly why ransomware vxCrypter does this, the most reasonable assumption now is that deleting duplicate files is one way to help malicious code speed up the data encryption. system. Besides, vxCrypter's behavior is also a warning that we must be really wary in the context that attackers continue to develop malware that contains many different behaviors to increase performance. causing damage to malicious code.
You should read it
- Lukitus Guide to preventing extortion malicious code
- ShieldFS can stop and reverse the effects of extortion code
- Ryuk Ransomware has added 'selective' encryption capabilities.
- Discovered new ransomware on Mac computers
- GandCrab blackmail extinguished after earning $ 2.5 billion worldwide
- Ako ransomware is raging all over the world, what do you know about this ransomware?
- List of the 3 most dangerous and scary Ransomware viruses
- Ransomware can encrypt cloud data
May be interested
- How to remove Moba ransomware from the operating systemmoba is a malware, belonging to the djvu ransomware family. these malware-infected systems are encrypted data and receive a ransom request to obtain decryption tools / software.
- Ransomware can encrypt cloud dataransomware is as small as a grain of sand, they are everywhere around us. and they can encrypt hard drive attacks but also attack other system drives, and cloud drives don't get out of sight.
- DoubleLocker - new ransomware has the ability to encrypt data and change Android device PINsecurity researchers at eset have discovered a new type of android ransomware called doublelocker, which not only encrypts user data but also changes the device's pin.
- Intrusion detection system (IDS) (Part 1)ids (intrusion detection systems) is a device or software that monitors network traffic, suspicious behaviors and alerts for system administrators.
- How to Clean Windows in 10 Minutes That Anyone Can Dogetting your pc back to good shape doesn't have to take all day. with just a few quick steps, you can have your pc running like the day you bought it.
- Download Total PC Cleaner - a tool to help clean junk files and optimize Windows 10 without harming your computer, for freetotal pc cleaner is a uwp application for windows 10 that helps clean up junk files on your computer and optimize system performance. this application is completely free, easy to use and without ads.
- Strange ransomware detection only attacks the richother ransomware often spread to all victims if possible, but the new ransomware is different, it selectively infects.
- Ransomware can attack the CPU, not just the operating system: How to prevent it?ransomware is a serious problem in its current state and is only going to get worse. any security programs and measures will be rendered useless when ransomware attacks the cpu.
- Matrix Ransomware is back under the distribution of RIG Exploit Kitsecurity researcher jérôme segura of malwarebytes has discovered matrix ransomware being distributed through rig exploit kit on malicious display sites.
- Can a VPN Protect You From Ransomware?ransomware is a worrisome online threat. if it's installed on your computer, you not only risk paying a ransom to get your files back, but you also potentially won't get them back even after paying.