Tuits

Has blocat @demonslay335

Estàs segur que vols veure aquests tuits? Això no desblocarà @demonslay335.

  1. Tuit fixat
    24 de març de 2016

    ID is live! Special thanks to for the sub-domain.

    Desfés
  2. ha retuitat
    fa 15 hores
    Desfés
  3. fa 14 hores

    Looks like has updated to v1.5.1.0. ID Ransomware picked up on example file named "[email protected] -1614714137-578233478334310455516964.fname-README.txt.doubleoffset"

    Desfés
  4. ha retuitat
    fa 17 hores

    ScammerLocker (Hidden Tear) ransomware: Ext: .jodis Based on name & the GUI (it won't appear if you just run, it will only encrypt & drop note), prob. will target scammers. 🤔 Also, first time I hear about IOTA related to RW.

    Desfés
  5. ha retuitat
    fa 19 hores

    New Ladon ransomware portal cdmsxo25y4lfht6v[.]onion cc:

    Desfés
  6. fa 22 hores
    Desfés
  7. 5 de març

    , possible extension ".BLOCKED". Has a function for every possible drive of the system... talk about inefficient. Crashes with a 403 on trying to contact its C2, lol. Seems based on LightningCrypt and other junk ones according to

    Desfés
  8. 5 de març

    Weird changes for , this one appends extension "! ,--, Revert Access ,--, [email protected] ,--,.BlockBax_v3.2" (lots of spaces in there) to files.

    Desfés
  9. 5 de març

    Anyone familiar with command line? I'm not sure from the commands used by the malware in the screenshots if we can help victims decrypt.

    Desfés
  10. ha retuitat
    4 de març
    Mostra el fil
    Desfés
  11. ha retuitat
    5 de març

    So, the new GandCrab is arrived. 👏 And they are using a new extension, note name & even TOR domain, so we are good (). Thanks guys. 😂 They now linking to the decryption tutorial on NoMoreRansom, and says that won't work...

    Mostra el fil
    Desfés
  12. ha retuitat
    4 de març
    Desfés
  13. 4 de març

    Interesting here, using extension ".Bitconnect" and some new extortion text wanting you to take a photo of yourself to post on Instagram.

    Desfés
  14. ha retuitat
    3 de març

    just found this site infected with "Awesomeware" . an email for the list xD

    Desfés
  15. 3 de març

    If anyone has been hit by , please contact me. The current published decrypter can't decrypt your files right away, I have to actually bruteforce your keys manually at the present time.

    Desfés
  16. 3 de març

    I've updated detection on ID Ransomware. Seems they've started using "READ_ME.txt" for the note, which is way too generic... but I can detect based on format of the URLs in the note dynamically now.

    Desfés
  17. ha retuitat
    2 de març
    Mostra el fil
    Desfés
  18. 1 de març

    seems to be still out there. ID Ransomware just got a submission with note "=_HOW_TO_FIX_RQZLIN.txt" and Tor address royal25fphqilqft[.]onion. Seeing no references to this address yet, site is still up as of now.

    Desfés
  19. 1 de març

    Oh, we got 2 victim submissions to IDR this week that were false-positive for an old HiddenTear-based ransomware (sorry). This one definitely isn't HiddenTear.

    Mostra el fil
    Desfés
  20. 1 de març

    Interesting spotted by , tries to use GPG to do its encryption for it, then sdelete. Supposed to use extension ".<number>.qwerty", but since I didn't have those exes bundled, just drops the note and does nothing. ¯\_(ツ)_/¯

    Mostra el fil
    Desfés
  21. 1 de març

    ID Ransomware spotted a new extension for yesterday - ".id-<id>.[<email>].arrow"

    Desfés

Sembla que triga molt a carregar-se.

És possible que el Twitter hagi assolit el límit de capacitat o que experimenti una sobrecàrrega momentània. Torna-ho a provar o vés a l'estat del Twitter si en vols obtenir més informació.

    També et pot interessar

    ·