Tweets

Você bloqueou @demonslay335

Tem certeza de que deseja ver estes Tweets? Visualizar os Tweets não desbloqueará @demonslay335

  1. Tweet Fixado
    24 de mar de 2016

    ID is live! Special thanks to for the sub-domain.

    Desfazer
  2. retweetou
    14 horas atrás
    Desfazer
  3. 14 horas atrás

    Looks like has updated to v1.5.1.0. ID Ransomware picked up on example file named "[email protected] -1614714137-578233478334310455516964.fname-README.txt.doubleoffset"

    Desfazer
  4. retweetou
    17 horas atrás

    ScammerLocker (Hidden Tear) ransomware: Ext: .jodis Based on name & the GUI (it won't appear if you just run, it will only encrypt & drop note), prob. will target scammers. 🤔 Also, first time I hear about IOTA related to RW.

    Desfazer
  5. retweetou
    19 horas atrás

    New Ladon ransomware portal cdmsxo25y4lfht6v[.]onion cc:

    Desfazer
  6. 22 horas atrás
    Desfazer
  7. 5 de mar

    , possible extension ".BLOCKED". Has a function for every possible drive of the system... talk about inefficient. Crashes with a 403 on trying to contact its C2, lol. Seems based on LightningCrypt and other junk ones according to

    Desfazer
  8. 5 de mar

    Weird changes for , this one appends extension "! ,--, Revert Access ,--, [email protected] ,--,.BlockBax_v3.2" (lots of spaces in there) to files.

    Desfazer
  9. 5 de mar

    Anyone familiar with command line? I'm not sure from the commands used by the malware in the screenshots if we can help victims decrypt.

    Desfazer
  10. retweetou
    4 de mar
    Mostrar esta sequência
    Desfazer
  11. retweetou
    5 de mar

    So, the new GandCrab is arrived. 👏 And they are using a new extension, note name & even TOR domain, so we are good (). Thanks guys. 😂 They now linking to the decryption tutorial on NoMoreRansom, and says that won't work...

    Mostrar esta sequência
    Desfazer
  12. retweetou
    4 de mar
    Desfazer
  13. 4 de mar

    Interesting here, using extension ".Bitconnect" and some new extortion text wanting you to take a photo of yourself to post on Instagram.

    Desfazer
  14. retweetou
    3 de mar

    just found this site infected with "Awesomeware" . an email for the list xD

    Desfazer
  15. 3 de mar

    If anyone has been hit by , please contact me. The current published decrypter can't decrypt your files right away, I have to actually bruteforce your keys manually at the present time.

    Desfazer
  16. 3 de mar

    I've updated detection on ID Ransomware. Seems they've started using "READ_ME.txt" for the note, which is way too generic... but I can detect based on format of the URLs in the note dynamically now.

    Desfazer
  17. retweetou
    2 de mar
    Mostrar esta sequência
    Desfazer
  18. 1 de mar

    seems to be still out there. ID Ransomware just got a submission with note "=_HOW_TO_FIX_RQZLIN.txt" and Tor address royal25fphqilqft[.]onion. Seeing no references to this address yet, site is still up as of now.

    Desfazer
  19. 1 de mar

    Oh, we got 2 victim submissions to IDR this week that were false-positive for an old HiddenTear-based ransomware (sorry). This one definitely isn't HiddenTear.

    Mostrar esta sequência
    Desfazer
  20. 1 de mar

    Interesting spotted by , tries to use GPG to do its encryption for it, then sdelete. Supposed to use extension ".<number>.qwerty", but since I didn't have those exes bundled, just drops the note and does nothing. ¯\_(ツ)_/¯

    Mostrar esta sequência
    Desfazer
  21. 1 de mar

    ID Ransomware spotted a new extension for yesterday - ".id-<id>.[<email>].arrow"

    Desfazer

O carregamento parece estar demorando.

O Twitter deve estar sobrecarregado ou passando por algum problema momentâneo. Tente novamente ou acesse o Status do Twitterpara obter mais informações.

    Você também pode gostar

    ·