Phone : +91 9582 90 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Free decryptor released for GetCrypt ransomware that spreads through RIG exploit kit

Free decryptor released for GetCrypt ransomware that spreads through RIG exploit kit

  • GetCrypt uses a combo of Salsa20 and RSA-4096 algorithms to encrypt the victim’s files.
  • While encrypting, it appends a random 4 character extension to the infected files.

Users infected by GetCrypt ransomware can now retrieve their encrypted files without paying a ransom. It is possible through a decryptor that has been released by security researchers.

What is GetCrypt ransomware?

GetCrypt is a new ransomware that is distributed via RIG exploit kit. The ransomware was discovered by a researcher nao_sec. The researcher found the malware being used in Popcash malvertising campaigns and alerted BleepingComputer.

When the exploit kit executes the ransomware, GetCrypt first checks if the Windows is set to Ukrainian, Belarusian, Russian or Kazakh language. If it finds the system with any of these languages, then the ransomware will terminate and not encrypt the computer.

What are its capabilities?

GetCrypt uses a combo of Salsa20 and RSA-4096 algorithms to encrypt the victim’s files. While encrypting, it appends a random 4 character extension to the infected files.

Later, it drops a ransom note named ‘decrypt my files #.txt’ in each folder to guide a victim with the payment process. The ransom note advises the victim to contact getcrypt@cock[.]li for payment instructions.

During the infection process, the ransomware also changes the desktop background to a random image which is stored at %LocalAppData%\Tempdesk.bmp.

What is the solution?

Emsisoft security researchers have released a free decryptor for the GetCrypt ransomware. The victims are required to retain the original unencrypted copy of the files that have been encrypted before initiating the decryption process.

Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 9582 90 7788 | Support Number : +91-9654016484
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket