Page 1 of 1

Ransomware - Beware

Posted: Sat Jun 03, 2006 4:43 am
by moongirl
Trojan Freezes Computer, Demands Ransom

Malware threatens to delete files unless payment is sent via Western Union.

Jeremy Kirk, IDG News Service
Thursday, April 27, 2006


A new kind of malware circulating on the Internet freezes a computer and then asks for a ransom paid through the Western Union Holdings money transfer service.

A sample of the Trojan horse virus was sent to Sophos, a security vendor, said Graham Cluley, senior technology consultant. The malware, which Sophos named Troj/Ransom-A, is one of only a few viruses so far that have asked for a ransom in exchange for releasing control of a computer, Cluley said.

The new Trojan falls into a class of viruses described as "ransomware." The schemes had been seen in Russia, but the first one appeared in English just last month.

"It is a new kind of malware with a particularly nasty payload," Cluley said.

It's unclear how the Trojan is being spread, although Sophos is investigating, Cluley said. Viruses can be spread in several ways, including through spam or a so-called drive-by download that exploits a browser vulnerability when a user visits a malicious Web site.

PC Frozen, Files at Risk

Once run, the Trojan freezes the computer, displaying a message saying files are being deleted every 30 minutes. It then gives instructions on how to send $10.99 via Western Union to free the computer.

Hitting the control, alt, and delete keys will not affect the bug, the virus writer warns. Sophos provides further details at its Web site.

The virus writer even offers tech support, Cluley said. If the method of unlocking the computer doesn't work after the money is sent, the virus writer promises to research the problem and includes an e-mail address.

Last month, a Trojan emerged that encrypts a user's documents and then leaves a file demanding $300 in exchange for the password to access the information. Victims were instructed to send money to one of 99 accounts run by e-gold, a company that runs a money transfer site.

The password, however, was contained on the infected computer. Sophos cracked it and publicly released it.
http://www.pcworld.com/news/article/0,aid,125569,00.asp
Virus Encrypts Data, Demands Ransom

Trojan horse asks you to pay $300 to regain access to your documents.

Jeremy Kirk, IDG News Service
Thursday, March 16, 2006


A virus that encrypts documents and demands a ransom to get them back is circulating on the Internet, but at least one security company has released the password needed to recover the files.

The Trojan horse virus encrypts the contents of a user's Word documents, databases, or spreadsheets, and then leaves a file demanding $300 in exchange for the password to access the information, said Graham Cluley, senior technology consultant with security company Sophos. A text file directs victims to transfer money to one of 99 accounts run by e-gold, a company that runs a money transfer site.

Similar "ransomware" schemes have been traced back to Russia, and occurrences of this type of attack appear to be growing, Cluley said. This latest one is notable because it is the first attempt in English, Cluley said.

It's unclear how the virus is spreading. It doesn't appear to have been widely sent via spam e-mails, Cluley said, so it may be embedded in a Web page and spread through a so-called drive-by install, a method that doesn't require users to actively click on and download an attachment.

Password Found

After encrypting the data, the Trojan deletes itself. However, the password to unlock the data is actually contained in the Trojan and is used in the process of encrypting the files. Technicians at Sophos extracted the password, which is made to look like a file path name--C:\Program Files\Microsoft Visual Studio\VC98.

The authors may have used the file path name in order to disguise it so that it doesn't look like the password, Cluley said.

Sophos has heard indirectly of some infections, but the virus does not appear to be widespread, Cluley said.

Separately, Sophos has detected another virus that uses a current news event--the death of suspected war criminal Slobodan Milosevic--to dupe users into opening a malicious attachment. The spam message claims to have a photo containing secret evidence about the death of the former Yugoslav President, who was on trial at The Hague. His sudden death on Saturday prompted an investigation after he had complained of inadequate medical treatment.

The viral message claims to have been scanned by "Kaspercky Antivirus," a misspelling of security vendor Kaspersky Lab. E-mail messages often contain a notice asserting the message has been scanned for malware.

The use of current news events to prompt curiosity is a well-used ploy by virus writers. The virus contained in the Milosevic attachment tries to download other malicious programs and could give an attacker control over the computer, Cluley said.
http://www.pcworld.com/news/article/0,aid,125108,00.asp

RANSOMWARE - Some culprits and where they may be found.

TROJ_PGPCODER.A (web browsing)
TROJ_RANSOM.A (spam)
TROJ_CRYZIP.A (adult sites)
TROJ_ARHIVEUS.A (adult sites)

Posted: Tue Jun 06, 2006 3:02 am
by moongirl
Sophos Cracks Archiveus Ransomware Code
06/02/06 11:10 AM PT | TechNewsWorld

Sophos has cracked the code to unlock files held hostage by Archiveus ransomware. The security software firm warned users on...

Cracking the Code Sophos experts have determined the password used to encrypt users' data. The password is deliberately made long and complicated by the hackers to discourage people from trying to crack it, Cluley explained. Sophos determined that this is the password: mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw.
Read full article:
http://www.technewsworld.com/perl/story/50881.html

Posted: Tue Jun 06, 2006 1:01 pm
by nesman
I think it's funny. Sophos cracked the password and made it publicly available.

Sure, you crack a virus, and you're a hero. You crack a dvd encryption, and they come and get you. ;)