Open top menu
Rabu, 28 September 2016

With all the buzz around tonight's Presidential Debate between Hillary Clinton and Donald Trump, I decided to see if I could find any malware based around these polarizing candidates. Though I did not find anything related to Hillary Clinton, I did stumble upon a development version of the Donald Trump Ransomware.
donald_trump_ransomware
The Donald Trump Ransomware is currently in development and as it was first compiled over a month ago, there is a good chance that it will never be actively distributed. Though the ransomware does contain functions to encrypt files using AES, in its current form it does not actually encrypt anything.
Instead it will look for files in the encrypt folder and base64 encode the file names and then append the .ENCRYPTED extension to any files that match certain file extensions. The extensions targeted by this program are:
.zip, .mp3, .7z, .rar, .wma, .avi, .wmv, .csv, .tax, .sidn, .itl, .mdbackup, .menu, .icarus, .litemod, .sav, .lvl, .raw, .flv, .m3u, .xxx, .pak, .jpg, .png, .docx, .doc, .ppt, .odt, .csv, .jpeg, .psd, .rtf, .cfg,  Minecraft,  alts.json, .wolfram, .dat, .dat_mcr, .mca, .Ink, .pub, .pptx, .php, .html, .yml, .sk, .txt, .mp4, .vb, .swf, .ico, .xcf,  bukkit.jar, .log, .sln, .ini, .dll, .xml, .tex, .assets, .resource, .java, .js, .css, .gif, 
In this version you can simply click on the Unlock button to have the files renamed to their original filenames.
While, I did not find any serious infections corresponding to these candidates, I urge everyone to be extra careful with any email attachments they receive during the election. It is very common for malware developers to send malware attachments disguised as content related to the current news.

Tagged
Different Themes
Written by Lovely

Aenean quis feugiat elit. Quisque ultricies sollicitudin ante ut venenatis. Nulla dapibus placerat faucibus. Aenean quis leo non neque ultrices scelerisque. Nullam nec vulputate velit. Etiam fermentum turpis at magna tristique interdum.

Posting Lebih Baru
This is the last post.

0 komentar