Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

New Variant of Ransomware Arena Crysis Appeared

Researcher Michael Gillespie has discovered a new variant of ransomware Crysis / Dharma that adds the. arena extension to the encrypted file.

Table of Contents

Researcher Michael Gillespie has discovered a new variant of ransomware Crysis / Dharma that adds the. arena extension to the encrypted file.

New Variant of Ransomware Arena Crysis Appeared Overview

When installed, it scans the computer for certain types of files and encrypts them. When encrypting the file, it will add the extension in . id- [id]. [Email]. arena format. For example, a file named test. jpg will be encrypted and renamed to test. jpg. id-BCBEF350. [Chivas@aolonline. top]. arena.

Remember that this ransomware will encrypt the network drive mapped (map) and the shared network has not been mapped. So make sure you have the shared network locked so that those who really need access have the right.

Below is an example of an encrypted directory.

Below is an example of an encrypted directory The folder with the files has been encrypted by Crysis

The file is encrypted with the variant of Crysis Arena Ransomware

When encrypting the file, it will also remove all copies, so you cannot restore it. It will delete them by running vssadmin delete shadows / all / quiet.

The Crysis Arena variant will also create 2 more extortion notes. One is the info. hta file that is run by autorun. And one is a note named FILES ENCRYPTED. txt.

The Crysis Arena variant will also create 2 more extortion notes Note on the info. hta file of extortion code The Crysis Arena variant will also create 2 more extortion notes, example 2 Note on the TXT file

Both of these notes contain instructions to contact chivas@aolonline. top to guide payment.

Finally, the blackmail code will set itself to automatically start when you log into the machine. This allows it to encrypt newly created files since the last execution.

Unable to Decode the Crysis Arena Extortion Code

At this point, the malicious file Crysis Ransomware will not be able to decrypt (without losing money). The only way to recover is to backup or if you are lucky, via Shadow Volume Copies. Although Crysis tries to delete Shadow Volume Copies but in a few cases, it can't do that. Therefore, recovering encrypted files from Shadow Volume Copies is always suggested as the last way to save.

How to Protect Against Crysis?

To protect yourself from Crysis or any other ransomware, create your own habits of using computers and security software. First, always back up your data with reliable tools to prevent it when needed. Security software that can detect malicious code like Emsisoft Anti-Malware or Malwarebytes may also be useful.

Finally, don't forget to create a habit of keeping safe when using a computer like:

  • Data backup.
  • Do not open the attachment without knowing who sent it.
  • Do not open the attachment until it is confirmed that the person sent it.
  • Scan files with virus detection tools like VIrus Total.
  • Be sure to update Windows as soon as they are published. Update programs, especially Java, Flash and Adobe Reader. Older programs that contain security vulnerabilities are often exploited, so always use the latest version.
  • Be sure to install security software.
  • Use passwords that are difficult to guess and do not use the same password for multiple pages.
  • If using Remote Desktop Services, do not connect directly to the Internet but connect via VPN.

IOC information about Crysis Arena Ransomware

Hash

ARENA SHA256: a683494fc0d017fd3b4638f8b84caaaac145cc28bc211bd7361723368b4bb21e

Note on file FILES ENCRYPTED. TXT

Có d? li?u b?n ?ã ???c khoá US You want to return? write email chivas@aolonline. top

Notes on INFO. hta file

T?t c? t?p tin b?n ?ã ???c xác ??nh! T?t c? t?p tin b?n ?ã ???c xác ??nh due to m?t v?n ?? b?o m?t v?i PC. N?u b?n mu?n ph?c h?i them, ghi vào chúng vào email chivas@aolonline. top ?ang ghi ID này trong danh sách c?a thông báo c?a b?n [id] Trong vi?c có không có quy?n trong 24 th?i gian us ghi vào s?ese e-mails: chivas@aolonline. top You have to pay for decryption in Bitcoins. Hãy thay ??i giá trên làm th? nào b?n ghi vào Us. After payment we will send you the decryption tool that will decrypt all your files. Free decryption as guarantee Before paying b?n th? ??ng nh?p US vào 5 t?p tin cho free decryption. S? kích c? c?a t?p tin ph?i là ít h?n 10Mb (không ph?i ???c t?o), và t?p tin nên không ch?a thông tin giá tr?. (databases, backups, large excel sheets, etc.) How to obtain Bitcoins Easiest way to buy bitcoins is LocalBitcoins site. B?n c?n ph?i ??ng nh?p, hãy ch?n 'Buy bitcoins', https://localbitcoins. com/buy_bitcoins B?n có th? tìm các ??a ch? khác c?n mua Bitcoins and beginners guide here: http://www. coindesk. com/information/how-can-i-buy-bitcoins/ Attention! Không th? chuy?n ??i t?p tin t?p tin. Không th? th? decrypt d? li?u v?i ph?n m?m khác, nó có th? có c? s? d? li?u loss. Decryption c?a t?p tin c?a b?n v?i tr? giúp 3 bên ngoài có th? t?o giá trong (chúng thêm chúng ?? chúng) ho?c b?n có th? là m?t ng??i victim c?a scam.

Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.

FAQ

Why does new Variant of Ransomware Arena Crysis Appeared matter?

Researcher Michael Gillespie has discovered a new variant of ransomware Crysis / Dharma that adds the. arena extension to the encrypted file.

Who may be affected by this issue?

The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.

How can users reduce the risk?

Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.