Friday, February 21, 2025
HomeRansomwareThe Ransomware can Launch a DDOS attack - FireCrypt

The Ransomware can Launch a DDOS attack – FireCrypt

Published on

SIEM as a Service

Follow Us on Google News

Ransomware

Ransomware is a kind of malware that keeps or cutoff user’s from getting their System, either by locking the system’s screen or by locking the user’s files unless ransom is paid.     To read more about Ransomware.

A ransomware family named FireCrypt will scramble the client’s documents, additionally attempt to dispatch an extremely weak DDoS assault on a URL hardcoded in its source code.

FireCrypt’s manufacturer named BleedGreen (seen underneath) and permits the FireCrypt creator to produce an exceptional ransomware executable, give it a custom name, and use a customized record symbol.

Contrasted with other ransomware developers, this is a low-end application.

Comparative manufacturers more often than not let law breakers to alter a more extensive arrangement of choices, such as, the Bitcoin deliver where to get installments, the payment request esteem, contact email address, and the sky is the limit from there.

The Ransomware can Launch a DDOS attack - FireCrypt
The Ransomware can Launch a DDOS attack - FireCrypt
The Ransomware can Launch a DDOS attack - FireCrypt

This threat was discovered today by MalwareHunterTeam and first posted in Bleeping Computer.

The strategy is regularly used by malware engineers to make alleged “polymorphic malware” that is harder to recognize by standard antivirus programming.

As indicated by MalwareHunterTeam, “the manufacturer is extremely fundamental, so this shouldn’t help anything against genuine AVs.”

Firecrypt pathology procedure

The FireCrypt contamination prepare relies on the ransomware’s merchant’s capacity to trap clients in propelling the EXE record they just created.

When this happens, FireCrypt will terminate the PC’s Task Manager (taskmgr.exe) and start to encrypt a rundown of 20 document files.

FireCrypt encrypts records with the AES-256 encryption calculation.

All encrypted files will have their original file name and extension appended with “.firecrypt”.

Once the document encryption prepares closes, FireCrypt drops its payment note on the client’s Desktop.

The DDoS work that fills your hard drive with garbage records

Subsequent to dropping the payment note, FireCrypt doesn’t stop its noxious conduct. Its source code has a capacity that persistently interfaces with a URL, downloads its files and save into the hard disk.

%Temp% folder, named [random_chars]-[connect_number].html

Current versions of the FireCrypt ransomware will download the content of http://www.pta.gov.pk/index.php, which is the official portal of Pakistan’s Telecommunication Authority.

The Ransomware can Launch a DDOS attack - FireCrypt

The FireCrypt creator calls this element as a “DDoSer,” however this would be an extend. The crook would have to infect thousands of victims before launching a DDoS attack large enough to cause any problems to the Authority’s website.

Victims infected with this threat that is unable or unwilling to pay the $500 ransom demand should keep a copy of their encrypted files around, as a decrypter might be possibly released in the future.

Targeted file extensions:

.txt, .jpg, .png, .doc, .docx, .csv, .sql, .mdb, .sln, .php, .asp, .aspx, .html, .htm, .csx, .psd, .aep, .mp3, .pdf, .torrent

General Methods to prevent Ransomware

1.Backup data.
2.Disable files running from AppData/LocalAppData folders.
3.Filter EXEs in the email.
4.Patch or Update your software.
5.Use the Cryptolocker Prevention Kit.
6.Use a reputable security suite.
7.CIA cycle(Confidentiality, integrity, and availability)
8.Utilize System Restore to recover the computer.
9.Disconnect Internet connection immediately.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

CL0P Ransomware Launches Large-Scale Attacks on Telecom and Healthcare Sectors

The notorious CL0P ransomware group has intensified its operations in early 2025, targeting critical...

Ransomware Trends 2025 – What’s new

As of February 2025, ransomware remains a formidable cyber threat, evolving in complexity and...

ShadowPad Malware Upgraded to Deliver Ransomware in Targeted Attacks

Security researchers have uncovered a significant evolution in the ShadowPad malware family, which is...