Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

November 26th, 2010, 13:46 GMT · By

Malicious PDF Documents Install File Encrypting Ransomware

SHARE:

Adjust text size:

New malware holds files to ransom
Enlarge picture
A new drive-by attack leverages PDF exploits to install an aggressive piece of ransomware on people's computers, which is designed to encrypt their files and ask for money to restore them.

The new threat was discovered by security researchers from Sophos, and is distributed via maliciously crafted PDF documents, which exploit a vulnerability in older versions of Adobe Reader.

Successful exploitation leads to the ransomware program being dropped and executed on the system with the purpose of extorting money from users.

Ransomware is considered the next step in the evolution of scareware. However, unlike scareware, ransomware does not trick users into making payments; it downright demands it.

In this case, the application makes a wide variety of personal documents inaccessible by encrypting them and asks for $120 to restore them to their original form.

The targeted extensions include .jpg, .jpeg, .psd, .cdr, .dwg, .max, .mov, .m2v, .3gp, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .rar, .zip, .mdb, .mp3, .cer, .p12, .pfx, .kwm, .pwm, .txt, .pdf, .avi, .flv, .lnk, .bmp, .1cd, .md, .mdf, .dbf, .mdb, .odt, .vob, .ifo, .mpeg, .mpg, .doc, .docx, .xls, and .xlsx.

The desktop wallpaper is changed to warn the victim about what happened and how to proceed. "Attention!!!!!! All your personal files were encrypted with a strong algorythm RSA-1024 and you can't get an access to them without making of what we need!," part of the message reads.

Users are told to read a text file dropped on their desktop and called "HOW TO DECRYPT FILES," which contains further instructions about contacting the attackers.

The Sophos researchers point out that the program encrypts the first 10% of the files, making them unusable and appends the .ENCODED extension to them.

"Of course, we don't recommend paying money to ransomware extortionists. There's nothing to say that they won't simply raise their ransom demands even higher once they discover you are prepared to pay up," says Graham Cluley, a senior technology consultant at Sophos.

Unfortunately, there is currently no way to decrypt the files, unless you have an unaffected clean backup from where you can restore them.



3,318 hits · 3 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


New Rogueware Blocks Windows Explorer From Loading

New Koobface Variant Installs Highly Invasive Rogueware

Obscene Ukrainian Ransomware in the Wild

More Fake AVs Adopt the Ransomware Model

READER COMMENTS:


Comment #1 by: 13166 J3FF on 27 Nov 2010, 17:20 UTC reply to this comment

i have said virus, so there is no way to recover any of my files, system restore was deleated in this process and all of my backups are infected as well. i really need my pictures back so there is no way to decrypt the pictures?


Comment #2 by: Al on 01 Dec 2010, 02:03 UTC reply to this comment

Will you inform us if the decryption method will be found?

Comment #2.1 by: Lucian Constantin on 01 Dec 2010, 13:49 GMT

I have looked around for more information released by AV vendors about this threat. None of the companies who warned about it so far have provided a solution to recover the data.

The ransom note claims that RSA-1024 has been used to encrypt the files. If that's true, there's little to no chance that it can be decrypted without the attackers' key.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM