Security-X
Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le février 17, 2016, 19:11:58
-
Bonjour,
Une fiche Malekal sur le nouveau Ransomware Locky
Locky Ransomware (http://www.malekal.com/locky-ransomware/)
Une nouvelle campagne d’emails malicieux contenant des pièces jointes Invoice au format Word a actuellement lieu.
Cette campagne est assez similaire au précédente campagne poussant le Trojan Banker Dridex, aujourd’hui, il s’agit de pousser un nouveau Crypto-ransomware du nom de Locky.
A l’heure actuelle, il n’y a pas de solution pour récupérer les documents chiffrés en .locky
-
Bonjour,
Une fiche BleepingComputer sur le Ransomware Locky
Necurs Botnet returns with new Locky Ransomware Campaign (http://www.bleepingcomputer.com/news/security/necurs-botnet-returns-with-new-locky-ransomware-campaign/)
In the beginning of June, the Necurs botnet went offline, which also caused its Dridex and Locky malware campaigns to drop off as well. With TeslaCrypt halting operations and Locky no longer being heavily distributed, this void was quickly filled by the CryptXXX and Crysis ransomware infections.
On Monday, ProofPoint noticed a multi-million Locky email campaign, which appears to be originating from the Necurs botnet. At this time, researchers still do not know what caused Necurs to go offline, but CryptXXX will definitely have a run for its money now.
According to ProofPoint, this new Locky campaign uses emails with the subject Re: and attachments titled services_[name]_[6 random digits].zip, [name]_addition_[6 random digits].zip, or [name]_invoice_[6 random digits].zip. The zip files contained JavaScript files named addition-[random digits].js. An example of one of these emails, courtesy of ProofPoint, can be seen below.