ICYMI: Nemucod ransomware information:
https://bartblaze.blogspot.com/2016/04/nemucod-ransomware-information.html … (Thanks @hahn_katja for a slight correction).
#Nemucod #ransomware
-
-
Replying to @bartblaze
@bartblaze@hahn_katja For me the dropped files were 4284bb11a07c.exe (7zip), a0.exe, and a085e1.exe.1 reply 0 retweets 1 like -
Replying to @BleepinComputer
@BleepinComputer@hahn_katja Is that from the most recent spam run (April) or March?2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@hahn_katja Also its the one that uses 7Zip1 reply 0 retweets 1 like -
Replying to @BleepinComputer
@BleepinComputer@hahn_katja Right. Was late yesterday when checking, but I when you catch the encrypting in the act, you can get the key.2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@hahn_katja Yup saw that as well. a2.exe was created in %temp% after the other files were executed.1 reply 0 retweets 1 like
Replying to @BleepinComputer
@BleepinComputer @hahn_katja Indeed. Do you have the hashes for your samples by any chance? Thanks!
7:07 AM - 21 Apr 2016
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.