Monday, November 18, 2024
HomeComputer SecurityNew Ransomware Attack Failed to Decrypt Files Even After Ransom Paid Due...

New Ransomware Attack Failed to Decrypt Files Even After Ransom Paid Due to Hackers Coding Error

Published on

A Brand new ransomware attack widely distributed and infect the users based on their geolocation by checking the infected device IP address.

Malware authors designed this ransomware to avoid encrypting files for specific countries such as Russia, Belarus, and Kazakhstan.

If the Windows users infected by this Ransomware, it tries to find the device location whether the victim belongs to Russia else if the Russia regional parameters are set in the system preferences to avoid the encryption.

- Advertisement - SIEM as a Service

Due to the Malware authors coding error, it encrypts the files regardless of the device location even the victims belongs to encryption whitelisted countries.

This ransomware discovered Trojan.Encoder.25129 by Dr.Web security experts and cybercriminals claims that victims can restore the encrypted files but their code errors make impossible to decrypting the infected files that corrupted by an encoder.

Also Read: RansomwareAttack Response and Mitigation Checklist

How does this Ransomware Attack works

This ransomware mainly distributed through Social media that contains a malicious Payload and also it distributed through network shares.

Spam Emails is another distribution medium that contains embedded links and attached malicious files that carried the payload eventually infect the victim when victims open and execute it.

Initially, it using Windows Task Manager to installs itself and start its encryption process on the specific folders.This ransomware is not capable of encrypting the files that exceed 30,000,000 bytes (about 28.6 MB).

According to D.Web report,  Once the encryption is over, the “123” value is written into the %ProgramData%\\trig file. The Trojan then sends a request to the iplogger website. The website address is hardcoded into the program’s body. The malicious program then displays a window with ransom demands.

It using AES-256 algorithm to encrypt the files later it adds “.tron”  file extension in each files the once this ransomware complete its encryption process.

cybercriminals demand differs from 0.007305 to 0.04 Btc and also this ransomware provides 10 days deadline to pay the ransom amount if the time will exceed the victims have no longer access to their files.

IOC – SHA1:

  • de74dd60ba3448b072f03ad80001f6a903f60b60
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Rise Of Ransomware-As-A-Service Leads To Decline Of Custom Tools

Ransomware-as-a-Service (RaaS) platforms have revolutionized the ransomware market.Unlike traditional standalone ransomware sales, RaaS...

A Massive Hacking Toolkit From “You Dun” Threat Group Developed To Lauch Massive Cyber Attack

The "You Dun" hacking group exploited vulnerable Zhiyuan OA software using SQL injection, leveraging...