Auteur Sujet: RAA Ransomware  (Lu 8344 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
RAA Ransomware
« le: juin 15, 2016, 14:28:30 »
Bonjour,

Une fiche BleepingComputer sur ce nouveau Ransomware RAA

The new RAA Ransomware is created entirely using Javascript

Citer
A new ransomware was discovered by security researchers @JAMES_MHT and @benkow_ called RAA that is made 100% from JavaScript.  In the past we had seen a ransomware called Ransom32 that was created using NodeJS and packaged inside an executable. RAA is different, because it is is not delivered via an executable, but rather is a standard JS file.

By default, the standard implementation of JavaScript does not include any advanced cryptography functions. To get around this, the RAA developers utilized the CryptoJS library so that AES encryption could be used to encrypt the files.

RAA is currently being distributed via emails as attachments that pretend to be doc files and have names like mgJaXnwanxlS_doc_.js.  When the JS file is opened it will encrypt the computer and then demand a ransom of ~$250 USD to get the files back. To make matters worse, it will also extract the embedded password stealing malware called Pony from the JS file and install it onto the onto the victim's computer. More information about the embedded Pony malware can be found here.

Citer
When a file has been encrypted, it will append the .locked extension to the filename.

Citer
At this point there is no way to decrypt the files for free. If anything is discovered in the future, this article will be updated.
 

Hors ligne Tawal

  • Archives
  • Power Members
  • *
  • Messages: 1009
  • Le savoir n'a d'intérêt que si on le transmet.
Re : RAA Ransomware
« Réponse #1 le: juin 15, 2016, 18:49:00 »
Bonjour,

4. Get the key and the program to decrypt the files.
5. Take measures to prevent similar situations in the future.

Rhooo  :AAG
Puisque la science n'est pas infuse, elle se diffuse !

Tags: