Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Cars & Coffee Killer
 
legion's Avatar
 
Join Date: Sep 2004
Location: State of Failure
Posts: 32,246
CryptoLocker Reverse Engineered: Score One For the Good Guys

I can tell you for a fact, based on my line of work, that many small businesses whose focus is not on IT were completely crippled by this virus until they paid the ransom. For them, $300 was far less than losing a day of work.

Whitehats recover, release keys to CryptoLocker ransomware | Ars Technica

Quote:
Whitehat hackers have struck back at the operators of the pernicious CryptoLocker ransom trojan that has held hundreds of thousands of hard drives hostage.

Ransomware comes of age with unbreakable crypto, anonymous payments.
Through a partnership that included researchers from FOX-IT and FireEye, researchers managed to recover the private encryption keys that CryptoLocker uses to lock victims' personal computer files until they pay a $300 ransom. They also reverse engineered the binary code at the heart of the malicious program. The result: a website that allows victims to recover the key for their individual content.

To use the free service, victims must upload one of the files encrypted by CryptoLocker along with the e-mail address where they want the secret key delivered. Both FOX-IT and FireEye are reputable security companies, but readers are nonetheless advised to upload only non-sensitive files that contain no personal information.

This latest blow against CryptoLocker comes two months after law enforcement agencies around the world disrupted a sprawling botnet that helped distribute CryptoLocker and other malware. Dubbed "Operation Tovar," the legal action largely neutralized the malicious network and the fallback mechanisms used to keep malware infections in place on 500,000 to one million computers.

In a blog post published Wednesday, FireEye researchers wrote:

Operation Tovar made a clear impact on the distribution of and infection of machines by CryptoLocker. However, there have been no known avenues available designed to help users get their encrypted files back without making significant payments to those responsible for infecting machines in the first place. While the remediation of infected machines can be somewhat difficult, hopefully with the help of https://www.decryptCryptoLocker.com and Decryptolocker.exe, we can help you get back some of the valuable files that may still be encrypted.

As always, to help prevent a threat like this from affecting you and your data, ensure you backup your data. Ideally, this would be done in at least two locations: One would be on premises (such as an external hard drive), and the other would be off premises (such as cloud storage).

According to the BBC, an analysis of the data seized by the whitehat hackers indicated that 1.3 percent of CryptoLocker victims paid the ransom to decrypt their personal data. That figure means the operators may have generated revenue as high as $3 million

__________________
Some Porsches long ago...then a wankle...
5 liters of VVT fury now
-Chris

"There is freedom in risk, just as there is oppression in security."
Old 08-06-2014, 09:13 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 84,790
Garage
Cool.

Now if they could just track down the bad guys and encrypt them in into jail. That will not likely happen but at least that one threat is removed.
__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 08-06-2014, 09:24 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Control Group
 
Tobra's Avatar
 
Join Date: Aug 2005
Location: Carmichael, CA
Posts: 53,469
Garage
Seems like they could track the ransom money and go get those MFers
__________________
She was the kindest person I ever met
Old 08-06-2014, 12:12 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
Join Date: Oct 2012
Posts: 9,712
Garage
Quote:
Originally Posted by Tobra View Post
Seems like they could track the ransom money and go get those MFers
Tracking money CAN be quite difficult, if the recipient is intelligent.
__________________
Guy
'87 944 (first porsche/project car)
Old 08-06-2014, 12:56 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Registered
 
Join Date: Aug 1999
Location: port st lucie/stuart florida
Posts: 366
I had to reformat my laptop from this virus. I know a few other business owners who just paid the ransom
Old 08-09-2014, 09:00 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Dog-faced pony soldier
 
Porsche-O-Phile's Avatar
 
Join Date: Feb 2004
Location: A Rock Surrounded by a Whole lot of Water
Posts: 34,187
Garage
CryptoLocker Reverse Engineered: Score One For the Good Guys

This is just the beginning. Wait until a version starts hitting peoples' smart phones. Most people (including me) can't live without them and most probably don't bother to back up regularly. Cha-ching!

Guarantee there will be many, many more knock-offs of this coming down the road.

__________________
A car, a 911, a motorbike and a few surfboards

Black Cars Matter
Old 08-10-2014, 02:57 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
Reply


 


All times are GMT -8. The time now is 12:36 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.