The HDDCryptor ransomware locks the hard disk boot

Researchers have identified a new group of ransomware called HDDCryptor, which attacks the MBR of the Master Boot Record and prevents computers from booting after encrypting their files.

Ransomware HDDCryptor

That's it HDDCryptor (or Mamba) appeared around January of 2016, according to a topic in Bleeping Computer forum, where users reported being infected.

Based on the reports so far, it appears that a recent malware campaign has delivered a new version of HDDCryptor to users around the world. The first to (re) detect the HDDCryptor was Renato Marinho, a security researcher working for Morphus Labs.

Η σύνθεση του HDDCryptor είναι κάμποσα εκτελέσιμα αρχεία, όλα στριμωγμένα σε ένα. Το κακόβουλο λογισμικό πρώτα σαρώνει το τοπικό δίκτυο για μονάδες δίσκου δικτύου. Στη συνέχεια, χρησιμοποιεί ένα δωρεάν εργαλείο που ονομάζεται Network Password για να αναζητήσει και να σβήσει τα διαπιστευτήρια για κοινόχρηστους φακέλους δικτύου. Η συνεχίζεται με τη δρομολόγηση ένα άλλου εργαλείου ανοικτού κώδικα που ονομάζεται DiskCryptor το οποίο κρυπτογραφεί τα αρχεία του χρήστη που βρέθηκαν σε διαμερίσματα του σκληρού δίσκου. Αυτό το εργαλείο στη συνέχεια χρησιμοποιείται σε συνδυασμό με την προηγούμενη σάρωση και τους access, to connect to the network drives and encrypt the data.

Finally, HDDCrypter rewrites the MBR of the disk with a custom boot loader and restarts the computer, which eventually stops in a message asking for a ransom.

Users are encouraged to contact the ransomware author via , where they will receive the Bitcoin address to pay the ransom. Scammers ask for 1 Bitcoin (about $610).

ransomware-locks-hard-drive-boot-records

According to money found at one of the Bitcoin addresses mentioned in these emails, at least four people seem to have paid ransom so far, but probably there are many more since the scammers use different Bitcoin addresses.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).