Emsisoft releases a free decrypter for the GetCrypt Ransomware
#1
Exclamation 
Quote:
[Image: logo.svg]

Our malware team just released a decrypter for the GetCrypt ransomware.

GetCrypt is a ransomware spread by the RIG exploit kit and encrypts files using Salsa20 and RSA-4096. It appends a random 4-character extension to files that is unique to the victim such as four random uppercase letters (e.g. .NHCR) generated from the victim’s CPU’s serial number. A test version used a static “.EZDZ” extension.

According to BleepingComputer‘s Lawrence Abrams, GetCrypt will utilize the WNewEnumResourceW function to enumerate a list of available network shares, or if it fails, will try to brute force network account credentials instead.

Malware researcher @nao_sec discovered the ransomware and ethical hacker @VK_Intel shared his analysis of the exploit to BleepingComputer.

If you’re a victim of this ransomware, DO NOT PAY the ransom. Download the decrypter and reach out to us if you have any questions.

* Download the GetCrypt Decrypter Here
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.2.0 / 19.2.3 Update
Changes in 19.2.3 ...harlan4096 — 07:10
Google Chrome 140.0.7339.207 / 140.0.733...
Google Chrome 140....harlan4096 — 07:08
hunderbird 143.0.1
Thunderbird 143.0....harlan4096 — 07:06
Firefox add-on developers may roll back ...
For many users, a ...harlan4096 — 07:05
Microsoft silently introduces Windows AI...
Microsoft has quie...harlan4096 — 07:04

[-]
Birthdays
Today's Birthdays
avatar (40)maskbSleew
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (38)eqiduseb

[-]
Online Staff
There are no staff members currently online.

>