Tweet

Hai bloccato @demonslay335

Sei sicuro di voler vedere questi Tweet? Visualizzare i Tweet non sbloccherà @demonslay335

  1. Tweet fissato
    24 mar 2016

    ID is live! Special thanks to for the sub-domain.

    Annulla
  2. ha ritwittato
    14 ore fa
    Annulla
  3. 14 ore fa

    Looks like has updated to v1.5.1.0. ID Ransomware picked up on example file named "[email protected] -1614714137-578233478334310455516964.fname-README.txt.doubleoffset"

    Annulla
  4. ha ritwittato
    17 ore fa

    ScammerLocker (Hidden Tear) ransomware: Ext: .jodis Based on name & the GUI (it won't appear if you just run, it will only encrypt & drop note), prob. will target scammers. 🤔 Also, first time I hear about IOTA related to RW.

    Annulla
  5. ha ritwittato
    19 ore fa

    New Ladon ransomware portal cdmsxo25y4lfht6v[.]onion cc:

    Annulla
  6. 22 ore fa
    Annulla
  7. 5 mar

    , possible extension ".BLOCKED". Has a function for every possible drive of the system... talk about inefficient. Crashes with a 403 on trying to contact its C2, lol. Seems based on LightningCrypt and other junk ones according to

    Annulla
  8. 5 mar

    Weird changes for , this one appends extension "! ,--, Revert Access ,--, [email protected] ,--,.BlockBax_v3.2" (lots of spaces in there) to files.

    Annulla
  9. 5 mar

    Anyone familiar with command line? I'm not sure from the commands used by the malware in the screenshots if we can help victims decrypt.

    Annulla
  10. ha ritwittato
    4 mar
    Mostra questa discussione
    Annulla
  11. ha ritwittato
    5 mar

    So, the new GandCrab is arrived. 👏 And they are using a new extension, note name & even TOR domain, so we are good (). Thanks guys. 😂 They now linking to the decryption tutorial on NoMoreRansom, and says that won't work...

    Mostra questa discussione
    Annulla
  12. ha ritwittato
    4 mar
    Annulla
  13. 4 mar

    Interesting here, using extension ".Bitconnect" and some new extortion text wanting you to take a photo of yourself to post on Instagram.

    Annulla
  14. ha ritwittato
    3 mar

    just found this site infected with "Awesomeware" . an email for the list xD

    Annulla
  15. 3 mar

    If anyone has been hit by , please contact me. The current published decrypter can't decrypt your files right away, I have to actually bruteforce your keys manually at the present time.

    Annulla
  16. 3 mar

    I've updated detection on ID Ransomware. Seems they've started using "READ_ME.txt" for the note, which is way too generic... but I can detect based on format of the URLs in the note dynamically now.

    Annulla
  17. ha ritwittato
    2 mar
    Mostra questa discussione
    Annulla
  18. 1 mar

    seems to be still out there. ID Ransomware just got a submission with note "=_HOW_TO_FIX_RQZLIN.txt" and Tor address royal25fphqilqft[.]onion. Seeing no references to this address yet, site is still up as of now.

    Annulla
  19. 1 mar

    Oh, we got 2 victim submissions to IDR this week that were false-positive for an old HiddenTear-based ransomware (sorry). This one definitely isn't HiddenTear.

    Mostra questa discussione
    Annulla
  20. 1 mar

    Interesting spotted by , tries to use GPG to do its encryption for it, then sdelete. Supposed to use extension ".<number>.qwerty", but since I didn't have those exes bundled, just drops the note and does nothing. ¯\_(ツ)_/¯

    Mostra questa discussione
    Annulla
  21. 1 mar

    ID Ransomware spotted a new extension for yesterday - ".id-<id>.[<email>].arrow"

    Annulla

Il caricamento sembra essere lento.

Twitter potrebbe essere sovraccarico o avere un problema temporaneo. Riprova o visita Twitter Status per ulteriori informazioni.

    Potrebbero piacerti

    ·