vxCrypter Ransomware
vxCrypter is a recently observed .NET-based ransomware tool that has the capability to delete duplicate files on infected machines.
Summary
vxCrypter is a recently observed .NET-based ransomware tool that has the capability to delete duplicate files on infected machines.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, the delivery method of vxCrypter is unknown as it was discovered in its development stage by a security researcher. As with most ransomware, it is likely to be delivered via spam campaigns.
Once installed, vxCrypter will attempt to encrypt all files matching a hard-coded extension list. During the encryption process, it will keep a record of the SHA256 file hash of each encrypted file and delete any further files that produce a previously encountered hash. vxCrypter will not delete duplicate encrypted files with certain extensions, such as .exe or .dll, but will delete files with the following extensions:
| 7z | cpp | h | key | ppt | sql | txt |
| asp | csv | hpp | mdb | pptx | sqlite | wmv |
| aspx | db | htm | mpeg | psd | sqlite3 | xls |
| avi | doc | html | odt | py | sqlitedb | xlsx |
| bak | docx | java | pem | rar | tar | xml |
| bat | fla | jpeg | php | rb | tgz | xsd |
| bmp | flv | jpg | pl | reg | tif | zip |
| c | gif | jsp | png | sln | tiff |
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:47 pm