Auteur Sujet: Locky Ransomware  (Lu 8318 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Locky Ransomware
« le: février 17, 2016, 19:11:58 »
Bonjour,

Une fiche Malekal sur le nouveau Ransomware Locky

Locky Ransomware

Citer
Une nouvelle campagne d’emails malicieux contenant des pièces jointes Invoice au format Word a actuellement lieu.
Cette campagne est assez similaire au précédente campagne poussant le Trojan Banker Dridex, aujourd’hui, il s’agit de pousser un nouveau Crypto-ransomware du nom de Locky.

Citer
A l’heure actuelle, il n’y a pas de solution pour récupérer les documents chiffrés en .locky
« Modifié: juin 24, 2016, 08:25:15 par chantal11 »
 

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Re : Locky Ransomware
« Réponse #1 le: juin 24, 2016, 08:27:24 »
Bonjour,

Une fiche BleepingComputer sur le Ransomware Locky

Necurs Botnet returns with new Locky Ransomware Campaign

Citer
In the beginning of June, the Necurs botnet went offline, which also caused its Dridex and Locky malware campaigns to drop off as well. With TeslaCrypt halting operations and Locky no longer being heavily distributed, this void was quickly filled by the CryptXXX and Crysis ransomware infections.

On Monday, ProofPoint noticed a multi-million Locky email campaign, which appears to be originating from the Necurs botnet.  At this time, researchers still do not know what caused Necurs to go offline, but CryptXXX will definitely have a run for its money now.

According to ProofPoint, this new Locky campaign uses emails with the subject Re:  and attachments titled services_[name]_[6 random digits].zip, [name]_addition_[6 random digits].zip,  or [name]_invoice_[6 random digits].zip. The zip files contained JavaScript files named addition-[random digits].js. An example of one of these emails, courtesy of ProofPoint, can be seen below.
 

Tags: