new version of GandCrab Ransomware  - Gandcrab Ransomware 1 - New Version of GandCrab Ransomware Appends 5 Character Extension

A new of GandCrab Ransomware released, as like the previous it was not distributed through exploit kits. The distribution method of GandCrab v5 is currently unknown, the new appends a random on the encrypted files and creates HTML ransom note.

Gandcrab Ransomware is a widespread Ransomware, nowadays it evolves with newly updated futures under constant development to target various countries.

According to Bleeping Computer analysis, the new version of GandCrab scan for all the computer and all the associated networks shares for files to encrypt.

Once it has the files it encrypts and then appends a random 5 character extension, “when I tested the ransomware it appended the .lntps extension to the encrypted file’s name, for example, test.doc has been encrypted and renamed to test.doc.lntps” wrote Lawrence Abrams.

- Gandcrab v5 1 - New Version of GandCrab Ransomware Appends 5 Character Extension
Credits: Bleeping Computer

After the encryption process, it creates an HTML ransom notes that shows files, documents, photos are encrypted and asks victim’s to pay the ransom to unlock the files.

Also, it contains instruction on how to reach the TOR payment site http://gandcrabmfe6mnef[.]onion and how to make the payment to buy grandcarb Decryptor to decrypt the encrypted files.

- Gandcrab v5 2 - New Version of GandCrab Ransomware Appends 5 Character Extension
Credits: Bleeping Computer

The ransom amount to be paid is $1200 through cryptocurrency DSH or Bitcoin, and the actors allowing 1 file to decrypt for free to show they can decrypt the encrypted files.

Ransomware is one of the fast Growing threat in worldwide and its considered as a leader of the Global cyber attack, in the first quarter of we came through only less number of ransomware attacks, but in the second quarter of and the ransomware returns back with new versions of GandCrab, Sigma, and GlobeImposter campaigns.

Related

Gandcrab Ransomware Attack Windows Users via Compromised Websites

Hackers Launching GandCrab Ransomware via New Fallout Exploit Kit using Malvertising Campaign

GandCrab Ransomware Attack via Compromised Websites using SMB Exploit Spreader





Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here