±Recent Visitors

Recent Visitors to Com-Central!

±User Info-big


Welcome Anonymous

Nickname
Password

Membership:
Latest: HighestAce
New Today: 0
New Yesterday: 0
Overall: 6648

People Online:
Members: 0
Visitors: 287
Total: 287
Who Is Where:
 Visitors:
01: News
02: Community Forums
03: Community Forums
04: Downloads
05: CPGlang
06: Community Forums
07: Downloads
08: Home
09: Community Forums
10: Home
11: Community Forums
12: Community Forums
13: Community Forums
14: Community Forums
15: Downloads
16: Community Forums
17: Home
18: Member Screenshots
19: Home
20: Community Forums
21: Downloads
22: News Archive
23: Community Forums
24: Home
25: CPGlang
26: CPGlang
27: Home
28: Downloads
29: CPGlang
30: Community Forums
31: Home
32: Downloads
33: Community Forums
34: Community Forums
35: Downloads
36: Community Forums
37: Community Forums
38: Home
39: Home
40: Community Forums
41: Home
42: Community Forums
43: CPGlang
44: Member Screenshots
45: Community Forums
46: Community Forums
47: Community Forums
48: Home
49: Photo Gallery
50: Community Forums
51: News Archive
52: Home
53: Downloads
54: Community Forums
55: Downloads
56: Community Forums
57: Statistics
58: Member Screenshots
59: Photo Gallery
60: Downloads
61: Statistics
62: Community Forums
63: Downloads
64: Community Forums
65: Community Forums
66: Community Forums
67: Community Forums
68: Community Forums
69: Members List
70: Community Forums
71: Home
72: Home
73: Community Forums
74: Community Forums
75: Downloads
76: Member Screenshots
77: Home
78: Downloads
79: CPGlang
80: Community Forums
81: Community Forums
82: Home
83: Home
84: Home
85: Home
86: Home
87: Home
88: Home
89: Home
90: Home
91: Home
92: Home
93: Home
94: Home
95: Home
96: Home
97: Home
98: Home
99: Home
100: Home
101: Home
102: Home
103: Home
104: Home
105: Home
106: Home
107: Home
108: Home
109: Home
110: Home
111: Home
112: Home
113: Home
114: Home
115: Home
116: Home
117: Home
118: Home
119: Home
120: Home
121: Photo Gallery
122: CPGlang
123: Community Forums
124: Community Forums
125: Community Forums
126: Photo Gallery
127: Home
128: Downloads
129: Downloads
130: Community Forums
131: Community Forums
132: Home
133: CPGlang
134: Community Forums
135: Community Forums
136: Photo Gallery
137: Downloads
138: CPGlang
139: Downloads
140: Home
141: CPGlang
142: Community Forums
143: Home
144: Community Forums
145: Community Forums
146: Home
147: Home
148: Community Forums
149: Home
150: Home
151: Home
152: Home
153: Home
154: Home
155: Photo Gallery
156: Downloads
157: Community Forums
158: CPGlang
159: Photo Gallery
160: Home
161: CPGlang
162: Community Forums
163: Photo Gallery
164: Community Forums
165: CPGlang
166: Home
167: Community Forums
168: Community Forums
169: Community Forums
170: Member Screenshots
171: Community Forums
172: Home
173: Community Forums
174: Community Forums
175: Member Screenshots
176: Home
177: Photo Gallery
178: Home
179: Photo Gallery
180: Community Forums
181: Photo Gallery
182: Photo Gallery
183: CPGlang
184: Community Forums
185: Home
186: Community Forums
187: Home
188: Downloads
189: CPGlang
190: Statistics
191: Community Forums
192: Home
193: Your Account
194: Community Forums
195: Downloads
196: Community Forums
197: Home
198: Home
199: Home
200: Home
201: Home
202: Home
203: Home
204: Home
205: CPGlang
206: Member Screenshots
207: Home
208: Home
209: Home
210: Home
211: Home
212: Home
213: Home
214: Home
215: Home
216: Home
217: Home
218: Home
219: Home
220: Home
221: Home
222: Home
223: Home
224: Home
225: Downloads
226: Home
227: CPGlang
228: Home
229: Home
230: Home
231: Home
232: Home
233: Home
234: Home
235: Home
236: Community Forums
237: Home
238: Home
239: Home
240: Home
241: Home
242: Home
243: Home
244: Home
245: Home
246: Home
247: Home
248: Home
249: Home
250: Home
251: Home
252: Home
253: Home
254: Home
255: Home
256: Home
257: Home
258: Home
259: Community Forums
260: Member Screenshots
261: Home
262: Home
263: Home
264: News
265: Member Screenshots
266: CPGlang
267: Community Forums
268: Community Forums
269: Community Forums
270: Your Account
271: Downloads
272: Photo Gallery
273: Member Screenshots
274: Community Forums
275: Statistics
276: Community Forums
277: Statistics
278: Community Forums
279: News Archive
280: Statistics
281: Photo Gallery
282: Community Forums
283: Downloads
284: Photo Gallery
285: Statistics
286: Members List
287: Statistics

Staff Online:

No staff members are online!
Trojan Cryzip extorts decryption fee :: Archived
This is a forum for Software related items such as OS', Virus notices, cool or free programs, etc. Gaming software should go in the gaming folder pertaining to the current info.
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ›  Software

Topic Archived View previous topic :: View next topic  
Author Message
Uhu_Rodion
Janitor

Offline Offline
Joined: Nov 14, 2004
Posts: 1437
Location: L'Aquila, Italy
PostPosted: Tue Mar 14, 2006 9:05 pm
Post subject: Trojan Cryzip extorts decryption fee

"A Trojan making the rounds encrypts victims' files and demands a $300 payment to have them decrypted and unlocked, according to a report by security firm Lurhq Threat Intelligence Group."

This so-called "ransomware" Trojan, dubbed Cryzip, is the second of its type to emerge in the past 10 months, following the PGPcoder Trojan. It also is the third such Trojan to appear since 1989.

Lurhq researchers noted Tuesday that the appearance within a year of two encryption Trojans may indicate they are part an emerging trend in malicious software.

"Last year, we saw the PGPcoder, and anything that shows itself to be a viable way to make money, usually people start jumping on the bandwagon after that," said Joe Stewart, senior security researcher for Lurhq.

The Cryzip Trojan will search for files, such as source code or database files, on infected systems. It then uses a commercial zip library to store the encrypted files. Security researchers, however, have yet to determine how the Trojan is distributed, noting it could come from a number of sources, including malicious Web sites, or enter through a previously created backdoor on a virus-infested computer.

The Trojan will overwrite the victims' text and then delete it, leaving only encrypted material that contains the original file name and _CRYPT_.ZIP.

"Unlike the PGPcoder that used a trivial encryption scheme, the zip encryption is stronger. It's harder to go through a list of possible (encryption) keys to get the information back," Stewart said. "But a brute-force attack is still possible, if a user has a copy of the original file. It can be reversed-engineered with a copy of the Trojan."

Cryzip has yet to become a widespread problem. Lurhq said it is aware of only about two dozen infection cases. Increasingly, malicious software writers are becoming more interested in launching low-level attacks in the hopes that it will take longer for security companies to notice their presence and develop a defense.

Users may also be less willing to seek help if it involves disclosing where they might have come across the threat.

The Cryzip writer, who uses an E-Gold account for collecting ransom payments, tells the victims: "Your computer catched our software while browsing illegal porn pages, all your documents, text files, databases was archived with long enough password. You cannot guess the password for your archived files--password length is more than 10 symbols that makes all password recovery programs fail to bruteforce it."

The Trojan writer then goes on to demand that a $300 payment be sent electronically to the E-Gold account.

Stewart advises users to frequently back up their important files, not only to minimize the damage if their system crashes but to reduce damage from an encryption attack.


-> news.zdnet.com/2100-10...ag=nl.e589


Marco
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
Shades
Forum Tree-Rat

Offline Offline
Joined: Mar 07, 2005
Posts: 6475
Location: 3rd Branch up, 'Ye Olde Oak', Green Wood.
PostPosted: Wed Mar 15, 2006 12:39 pm
Post subject: Re: Trojan Cryzip extorts decryption fee

Hang on... if there's an account, it's trackable.
And who's gonna make any online payments to someone writing this stuff anyway?
Geeze talk about unsafe.

_________________
Skwerl's place.

Com-Central's cutest, fluffiest, twitchiest, tail.
CPU > Intel i9-9900k (o/c 4.9GHz); COOLING > BeQuiet! Dark Rock Pro 4;
MOBO > ASUS PRIME Z390-A; RAM > 2x32GB Corsair LPX 2666MHz;
GPU > Gigabyte GEFORCE GTX650Ti PCI-e 3.0 2Gb GDDR5;
AUDIO > Creative X-Fi Xtreme Music (plus - Universal Audio UAD2 Quad Custom accelerator);
HDD > 3x1TB+ M.2. SSDs; LCD > DELL - S2419HGF (1920x1080);
PSU > 650W be quiet Straight Power 11 - 80+ Gold;
CASE > BeQuiet! SILENT BASE 601; OS > Windows 11 Home Advanced (64-bit).
Back to top
View user's profile Visit poster's website ICQ Number
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ›  Software
Page 1 of 1
All times are GMT - 6 Hours

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.