Posted 03 February 2015 - 11:28 AM
Posted 03 February 2015 - 11:45 AM
Should not be any autostarts
Autostart entries have been removed, as has the file dropped within the Startup folder.
However, some odd things... the CryptoWall 3.0 executable that resides on the machine, while it could be spoofed, has a Created and Access timestamp of "1/22/15 1:48pm". There are several ransom notes that were dropped on 1/17/2015. However, the registry key that is added by CryptoWall 3.0, containing ransom note text as well as the list of encrypted files were last modified on 1:48pm and 9:14pm respectively, both on 1/22/15.
The path of the executable with, what appears to be the CryptoWall 3.0 payload, is consistent with other CryptoWall infections... C:\<random>\<random>.exe
Grinler, have you received a submission of a CryptoWall 3.0 binary yet? If not, would you like me to submit it for review?
EDIT: I can also provide the sandbox analysis reports (WildFire, Joe Sandbox) if needed.
Edited by White Hat Mike, 03 February 2015 - 11:46 AM.
Information Security Engineer | Penetration Tester | Forensic Analyst
CipherTechs.com
Posted 03 February 2015 - 11:51 AM
Posted 03 February 2015 - 11:53 AM
That's alright. Thanks for the offer.
Have a ton of emI used one when I wrote this article
Alright, no worries. Wasn't sure if there were many 3.0 binaries submitted yet.
I posted a summary of analysis in the other thread. Your articles, as always, are very helpful and in-depth, but I do think some stuff can be slightly tweaked and/or added... but hey, let's just focus on developing new methods of prevention. ![]()
Edited by White Hat Mike, 03 February 2015 - 11:54 AM.
Information Security Engineer | Penetration Tester | Forensic Analyst
CipherTechs.com
Posted 13 February 2015 - 06:18 AM
Um i might know a website but i think it will be risky too risky i think last year i was at school trying to download samples of viruses to test what it did against my pc
the website is vx-archiv.at and i dont think it has cryptolocker on it ill try search on my main pc right now first i need the virus signature like example: Trojan.XXXXXX.XX
Would anyone help?
Robert James Crawley Klopp
Posted 14 February 2015 - 01:21 AM
AnyBody Got a Sample ive got an old one of my pc and i want to infect it and have a look at it
Robert James Crawley Klopp
Posted 18 February 2015 - 04:48 PM
So is there way now to fix the virus i got it sadly and it ecrptyed all my photo music and some word documents im really sad and scared i ran 2 scans on my anti virus malwarebytes and eset scan they took off the virus i think because they found alot of bad things in my appdata temp and i deleted them and i think its off my pc now but all my things are ecrypted is there a way to fix it now pls help im scared idk why
Posted 18 February 2015 - 04:51 PM
So is there way now to fix the virus i got it sadly and it ecrptyed all my photo music and some word documents im really sad and scared i ran 2 scans on my anti virus malwarebytes and eset scan they took off the virus i think because they found alot of bad things in my appdata temp and i deleted them and i think its off my pc now but all my things are ecrypted is there a way to fix it now pls help im scared idk why
As has been said numerous times throughout this and many other threads, there is no method of decryption available for this ransomware aside from paying the ransom and hoping to receive a working decryption utility (although this is not recommended).
Information Security Engineer | Penetration Tester | Forensic Analyst
CipherTechs.com
Posted 18 February 2015 - 05:01 PM
How do I turn off notifications of this topic that I posted to?
Nevermind, found the unfollow button.
Posted 18 February 2015 - 10:50 PM
When will the decrprtion come out im thinking of waiting or just restart my pc i barley got any photos and i barley have word documents like 5 or 10 and i have a back up photo but i dont want to restart because i play games and i have alot of games that i dont want to restart. idk what to do when can we expect a fix ty
Posted 19 February 2015 - 04:00 AM
No decrytor
Come on Nathan kick Butt!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Robert James Crawley Klopp
Posted 22 February 2015 - 06:36 AM
I got CryptoWall 3.0, and I've been on the phone with several tech support guys over the last few days, and there's no luck in finding any usable shadow copies or backups of my data as even my external hard drive backup was decrypted because I left it plugged into my PC. I decided to just keep my encrypted data on a storage drive software and wiped my machine.
I'm still holding onto hope that a fix may one day be possible. Is the same team of law enforcement that took down the Gameover ZeuS botnet and CryptoLocker during Operation Tovar currently tracking down the perpetrators behind CryptoWall?
Posted 28 February 2015 - 03:42 PM
Posted 28 February 2015 - 10:11 PM
Srry Mate no decryptor yet
Edited by RobertHD, 28 February 2015 - 10:11 PM.
Robert James Crawley Klopp
Posted 01 March 2015 - 11:30 AM
Thanks, I am aware there is no decrypter available yet and may never be.Srry Mate no decryptor yet
0 members, 1 guests, 0 anonymous users