Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le février 14, 2016, 09:50:50

Titre: [BC] NanoLocker Ransomware can be Decrypted if Caught Early
Posté par: chantal11 le février 14, 2016, 09:50:50
Bonjour,

Une fiche BleepingComputer sur le Ransomware NanoLocker

NanoLocker Ransomware can be Decrypted if Caught Early (http://www.bleepingcomputer.com/news/security/nanolocker-ransomware-can-be-decrypted-if-caught-early/)

Citer
Last week a security researcher who goes by the name of Adam performed a very detailed and easy to read analysis of a new ransomware called NanoLocker. At the time of his analysis there was only a brief write-up on Symantec's site that showed some basic information about the ransomware.

When he analyzed the ransomware, though, he found that it contained some interesting features including how it communicates with the Command & Control server and a flaw in the way it temporarily stores the AES key. This flaw can the be used to decrypt a victim's files in the right circumstances.

Citer
Decrypting NanoLocker

As already stated, there is no weakness in the encryption algorithm that allows us to decrypt NanoLocker encrypted files.  Instead, a victim would have had to shutdown the computer or terminate the ransomware before it finished encrypting in order for us to retrieve the unencrypted encryption key. For those who were able to retrieve the key, Adam has created a decryptor that can import this key and decrypt the encrypted files.

Adam's decryptor needs to be run from the Windows command line and unfortunately can only decrypt one file at a time.  For those who want to add more features to Adam's decryptor, he has posted the full source code on GitHub. A list of all encrypted files can be found in the %LocalAppData%\lansrv.ini file.