The HDDCryptor ransomware locks the hard disk boot

The have detected a new ransomware group with the HDDCryptor, which attacks the hard disk's MBR (Master Boot Record) and prevents computers from booting after encrypting its files.

Ransomware HDDCryptor

That's it HDDCryptor (or Mamba) appeared around January of 2016, according to a topic in Bleeping Computer forum, where users reported being infected.

Based on the reports so far, it appears that a recent one campaign has delivered a new version of HDDCryptor to users around the world. The first to (re)discover HDDCryptor was Renato Marinho, a security researcher working for Morphus Labs.

Η σύνθεση του HDDCryptor είναι κάμποσα εκτελέσιμα αρχεία, όλα στριμωγμένα σε ένα. Το κακόβουλο λογισμικό πρώτα σαρώνει το τοπικό δίκτυο για μονάδες δίσκου δικτύου. Στη συνέχεια, χρησιμοποιεί ένα δωρεάν εργαλείο που ονομάζεται Network Recovery για να αναζητήσει και να σβήσει τα διαπιστευτήρια για κοινόχρηστους φακέλους δικτύου. Η διαδικασία συνεχίζεται με τη δρομολόγηση ένα άλλου εργαλείου ανοικτού κώδικα που ονομάζεται DiskCryptor το οποίο κρυπτογραφεί τα αρχεία του χρήστη που βρέθηκαν σε διαμερίσματα του σκληρού δίσκου. Αυτό το εργαλείο στη συνέχεια χρησιμοποιείται σε συνδυασμό με την προηγούμενη σάρωση και τους κωδικούς s, to connect to the network drives and encrypt the data.

Finally, HDDCrypter rewrites the MBR of the disk with a custom boot loader and restarts the computer, which eventually stops in a message asking for a ransom.

Users are encouraged to contact the author of the ransomware via email, where they will receive the Bitcoin address to pay the ransom. Fraudsters ask 1 Bitcoin (about $ 610).

ransomware-locks-hard-drive-boot-records

According to money found at one of the Bitcoin addresses mentioned in these emails, at least four people seem to have paid ransom so far, but probably there are many more since the scammers use different Bitcoin addresses.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).