Saw ransomware lately that uses RSA encryption & renames files w\ ".nobackup" extension? @Kafeine @erikloman @malwaremustdie @malekal_morte
-
-
Replying to @MalwareMustDie
@bartblaze it sounds familiar, i will look into a few samples i still have@MalwareMustDie@kafeine @erikloman@malekal_morte1 reply 0 retweets 0 likes -
Replying to @CassielMocoton
@bartblaze any chance of having a file 'how to decrypt" ? if so you got an gpcode ...@kafeine@MalwareMustDie@erikloman@malekal_morte2 replies 0 retweets 0 likes -
Replying to @CassielMocoton
@MalwareMustDie AFAIK it encrypts the files w\ AES, but the encryption key itself w\ RSA@kafeine@erikloman@malekal_morte@CassielMocoton2 replies 0 retweets 1 like -
Replying to @bartblaze
@bartblaze if not mistaken it used RC4 for the files and encrypted the key with RSA1024, it might be a newer version though.#malwaremustdie1 reply 0 retweets 0 likes -
Replying to @CassielMocoton
@CassielMocoton Yeah, it might be a new(er) version. Just heard this from a friend who has this & wanted to gather some more info forehand.1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze don't know if you got my DM, try photorec to recover files. Still chances are pretty low and the faster you try the better1 reply 0 retweets 0 likes -
Replying to @CassielMocoton
@CassielMocoton I did and was already familiar with PhotoRec, has indeed helped me in the past before ;-)1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@CassielMocoton Friends I got this sample http://www.nyxbone.com/malware/gpcode.html …, someone gave me a (supposedly) new version,I don’t taste it yet2 replies 0 retweets 0 likes
@nyxbone @CassielMocoton Thanks, that's indeed an old version. Can you DM me the new sample you have if possible? Thanks!
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.