Auteur Sujet: Ded Cryptor Ransomware  (Lu 8795 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Ded Cryptor Ransomware
« le: juin 18, 2016, 08:26:45 »
Bonjour,

Une fiche BleepingComputer sur ce nouveau Ransomware Ded Cryptor

The Ded Cryptor Ransomware thinks you have been Naughty this Year

Citer
A new EDA2 ransomware was discovered by Michael Gillespie called Ded Cryptor. This ransomware has been around for quite a while and targets both Russian and English speaking victims. When installed, the victims desktop will be changed to show an evil looking Santa having a good time while it encrypts your files.



Ded Cryptor will change the wallpaper of the Windows desktop to an image that contains the ransom amount and the email address, dedcrypt@sigaint.org, which the victim is told to email for payment instructions.

Though EDA2 ransomware have been commonly seen in the past, this particular variant removed the method that we could use to retrieve the keys. Furthermore, it also contains an unused namespace called DarthEncrypt, which appears to be the malware developer's attempt to create a new encryption method for the EDA2 ransomware.
How Ded Cryptor Encrypts your Files

At this point, it is currently unknown how Ded Cryptor is distributed. Once installed, it will generate an AES password and then only encrypt the victim's %UserProfile% folder.  When it encrypts a file it will append the .ded extension to it. This means that a file called test.jpg, will be renamed to test.jpg.ded when encrypted

Citer
Unfortunately, at this time there is no way to decrypt Ded Cryptor files for free.
 

Tags: