Emsisoft releases a free decrypter for the GetCrypt Ransomware
#1
Exclamation 
Quote:
[Image: logo.svg]

Our malware team just released a decrypter for the GetCrypt ransomware.

GetCrypt is a ransomware spread by the RIG exploit kit and encrypts files using Salsa20 and RSA-4096. It appends a random 4-character extension to files that is unique to the victim such as four random uppercase letters (e.g. .NHCR) generated from the victim’s CPU’s serial number. A test version used a static “.EZDZ” extension.

According to BleepingComputer‘s Lawrence Abrams, GetCrypt will utilize the WNewEnumResourceW function to enumerate a list of available network shares, or if it fails, will try to brute force network account credentials instead.

Malware researcher @nao_sec discovered the ransomware and ethical hacker @VK_Intel shared his analysis of the exploit to BleepingComputer.

If you’re a victim of this ransomware, DO NOT PAY the ransom. Download the decrypter and reach out to us if you have any questions.

* Download the GetCrypt Decrypter Here
Continue Reading
Reply


Messages In This Thread
Emsisoft releases a free decrypter for the GetCrypt Ransomware - by harlan4096 - 27 May 19, 08:15

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
[Test & Review Request] Looking for fee...
Can you at least i...LFTyyy — 14:28
Surfshark VPN : Award-winning VPN servi...
Dausos: Surfshark'...jasonX — 14:08
K-Lite Codec Pack 19.6.6 / 19.6.7 Update
Changes in 19.6.6:...harlan4096 — 07:37
AdGuard for iOS 4.5.19
AdGuard for iOS 4....harlan4096 — 07:35
Adobe Acrobat Reader DC 26.001.21431
Adobe Acrobat Read...harlan4096 — 07:34

[-]
Birthdays
Today's Birthdays
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>