Tweetler

@demonslay335 adlı kişiyi engelledin

Bu Tweetleri görüntülemek istediğinden emin misin? Tweetleri görüntülemek @demonslay335 adlı kişinin engelini kaldırmaz.

  1. Sabitlenmiş Tweet
    24 Mar 2016

    ID is live! Special thanks to for the sub-domain.

    Geri al
  2. Retweetledi
    14 saat önce
    Geri al
  3. 14 saat önce

    Looks like has updated to v1.5.1.0. ID Ransomware picked up on example file named "[email protected] -1614714137-578233478334310455516964.fname-README.txt.doubleoffset"

    Geri al
  4. Retweetledi
    17 saat önce

    ScammerLocker (Hidden Tear) ransomware: Ext: .jodis Based on name & the GUI (it won't appear if you just run, it will only encrypt & drop note), prob. will target scammers. 🤔 Also, first time I hear about IOTA related to RW.

    Geri al
  5. Retweetledi
    19 saat önce

    New Ladon ransomware portal cdmsxo25y4lfht6v[.]onion cc:

    Geri al
  6. 22 saat önce
    Geri al
  7. 5 Mar

    , possible extension ".BLOCKED". Has a function for every possible drive of the system... talk about inefficient. Crashes with a 403 on trying to contact its C2, lol. Seems based on LightningCrypt and other junk ones according to

    Geri al
  8. 5 Mar

    Weird changes for , this one appends extension "! ,--, Revert Access ,--, [email protected] ,--,.BlockBax_v3.2" (lots of spaces in there) to files.

    Geri al
  9. 5 Mar

    Anyone familiar with command line? I'm not sure from the commands used by the malware in the screenshots if we can help victims decrypt.

    Geri al
  10. Retweetledi
    4 Mar
    Bu Tweet dizisini göster
    Geri al
  11. Retweetledi
    5 Mar

    So, the new GandCrab is arrived. 👏 And they are using a new extension, note name & even TOR domain, so we are good (). Thanks guys. 😂 They now linking to the decryption tutorial on NoMoreRansom, and says that won't work...

    Bu Tweet dizisini göster
    Geri al
  12. Retweetledi
    4 Mar
    Geri al
  13. 4 Mar

    Interesting here, using extension ".Bitconnect" and some new extortion text wanting you to take a photo of yourself to post on Instagram.

    Geri al
  14. Retweetledi
    3 Mar

    just found this site infected with "Awesomeware" . an email for the list xD

    Geri al
  15. 3 Mar

    If anyone has been hit by , please contact me. The current published decrypter can't decrypt your files right away, I have to actually bruteforce your keys manually at the present time.

    Geri al
  16. 3 Mar

    I've updated detection on ID Ransomware. Seems they've started using "READ_ME.txt" for the note, which is way too generic... but I can detect based on format of the URLs in the note dynamically now.

    Geri al
  17. Retweetledi
    2 Mar
    Bu Tweet dizisini göster
    Geri al
  18. 1 Mar

    seems to be still out there. ID Ransomware just got a submission with note "=_HOW_TO_FIX_RQZLIN.txt" and Tor address royal25fphqilqft[.]onion. Seeing no references to this address yet, site is still up as of now.

    Geri al
  19. 1 Mar

    Oh, we got 2 victim submissions to IDR this week that were false-positive for an old HiddenTear-based ransomware (sorry). This one definitely isn't HiddenTear.

    Bu Tweet dizisini göster
    Geri al
  20. 1 Mar

    Interesting spotted by , tries to use GPG to do its encryption for it, then sdelete. Supposed to use extension ".<number>.qwerty", but since I didn't have those exes bundled, just drops the note and does nothing. ¯\_(ツ)_/¯

    Bu Tweet dizisini göster
    Geri al
  21. 1 Mar

    ID Ransomware spotted a new extension for yesterday - ".id-<id>.[<email>].arrow"

    Geri al

Yükleme biraz zaman alacak gibi görünüyor.

Twitter aşırı kapasiteyle çalışıyor ya da anlık sorunlar yaşıyor olabilir. Yeniden dene ya da daha fazla bilgi almak için Twitter Durumu sayfasını ziyaret et.

    Şunları da beğenebilirsin

    ·