Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Avast Releases Three New Decryption Tools to Fight Ransomware.
#1
Avast Releases Three New Decryption Tools to Fight Ransomware
There are now 14 anti-ransomware tools available from Avast

With the threat now posed by ransomware, cyber security firm Avast has released three more decryption tools to help victims, reaching a total of 14 such tools.

“In the past year more than 200 new strains of ransomware were discovered, it’s growth of in-the-wild samples two-folded, but the good news is that hundreds of millions of Avast and AVG users were protected against this popular threat,” reads a blog post signed by Jakub Kroustek, reverse engineer and malware analyst at Avast.

The three new decryption tools address three different ransomware strains – HiddenTear, Jigsaw and Stampado/Philadelphia. Some solutions for these particular strains are already available, coming from other security researchers. Avast decided, however, that it is always best to have multiple options.

That’s because these three strains are particularly active and frequently encountered, especially in the past few months. Since the used encryption keys update often, so must the decryption tools. In the end, whether it’s Avast’s tools or those made by other security researchers that work against the ransomware, it’s all for the same purpose.

“Last but not least, we were able to significantly speed-up the decryption time, more precisely the password brute-force process, so e.g. some of the HiddenTear variants will be decrypted within minutes instead of days. The best results are achieved when decrypting files directly from the infected machine,” Kroustek writes.

Decrypting HiddenTear

HiddenTear has been around for a while and the code is actually hosted on GitHub. Given the fact that it is so present, many hackers have gone and tweaked the code and starting using it. Encrypted files have a wide range of extensions: .locked, .34xxx, .bloccato, .BUGSECCCC, .Hollycrypt, .lock, .saeid, .unlockit, .razy, .mecpt, .monstro, .lok, .암호화됨, .8lock8, .fucked, .flyper, .kratos, .krypted, .CAZZO, .doomed. and more.

After all the files are encrypted, a text file will appear on the user’s desktop.

Decrypting Jigsaw

Jigsaw was first spotted in the wild in March 2016, and many of its strains use the picture of the Jigsaw Killer from the same-name movie in the ransom screen.

Files encrypted after the computer was infected with Jigsaw have

Encrypted files will have one of the following extensions: .kkk, .btc, .gws, .J, .encrypted, .porno, .payransom, .pornoransom, .epic, .xyz, .versiegelt, .encrypted, .payb, .pays, .payms, .paymds, .paymts, .paymst, .payrms, .payrmts, .paymrts, .paybtcs, .fun, .hush.

Keeping up with the movie script, the malware will delete a file per hour if you don’t pay up.

Decrypting Stampado

This particular ransomware has been around since August 2016, and it’s being sold on the dark web. Multiple versions have been circulating on the Internet, one of them is called Philadelphia. Most often than not, Stampado adds the .locked extension to the encrypted files.

Stampado will delete a new file every 6 hours unless you pay the ransom.

Check out Avast’s list of anti-ransomware tools and see if you can find one to help you out.
[Image: LKWcvctl.jpg]

Source: http://news.softpedia.com/news/avast-rel...2534.shtml
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  RATs, rootkits, and ransomware (oh my!) AVAST mrtrout 0 870 10-08-2023 , 10:53 PM
Last Post: mrtrout
  AstraLocker ransomware shuts down and releases decryptors mrtrout 0 481 07-05-2022 , 03:28 AM
Last Post: mrtrout
  Evernym joins Avast Pioneers of self-sovereign identity join Avast mrtrout 0 613 12-10-2021 , 10:54 AM
Last Post: mrtrout
  Top 2021 threats include ransomware, pandemic-related scams, and fleeceware (AVAST) mrtrout 0 1,180 12-10-2021 , 10:52 AM
Last Post: mrtrout
  Ragnarok ransomware operation shuts down and releases free decrypter mrtrout 0 558 08-27-2021 , 06:45 AM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)