<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ransomware &#8211; Martijn Grooten</title>
	<atom:link href="/tag/ransomware/feed/" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>Lapsed Ordinary</description>
	<lastBuildDate>Sat, 22 Feb 2014 19:52:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>Researchers crack Bitcrypt ransomware</title>
		<link>/2014/02/22/researchers-crack-bitcrypt-ransomware/</link>
					<comments>/2014/02/22/researchers-crack-bitcrypt-ransomware/#respond</comments>
		
		<dc:creator><![CDATA[Martijn]]></dc:creator>
		<pubDate>Sat, 22 Feb 2014 19:52:40 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[bitcrypt]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[virus bulletin]]></category>
		<guid isPermaLink="false">http://www.lapsedordinary.net/?p=129</guid>

					<description><![CDATA[There are 256 (28) different bytes and only ten different digits. So if your secret (RSA) key consists of 128 digits rather than of 128 bytes, the entropy of the key (that is, the amount of &#8216;surprise&#8217; to an attacker) is a whole lot lower. No shit, Sherlock. Apparently, this somewhat basic fact was beyond [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>There are 256 (2<sup>8</sup>) different bytes and only ten different digits. So if your secret (RSA) key consists of 128 digits rather than of 128 bytes, the entropy of the key (that is, the amount of &#8216;surprise&#8217; to an attacker) is a whole lot lower.<br />
No shit, Sherlock. Apparently, this somewhat basic fact was beyond the understanding of those who wrote the Bitcrypt ransomware, probably inspired by the sad success story of CryptoLocker. In practise, it meant the difference between &#8220;only the NSA can crack your key&#8221; and &#8220;anyone can crack your key&#8221;. Two researchers from <i>Airbus</i> cracked the key and thus were able to restore the encrypted files on a friend&#8217;s computer, without paying the 0.4BTC ransom.<br />
More at <i>Virus Bulletin</i> <a href="http://www.virusbtn.com/blog/2014/02_21.xml">here</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>/2014/02/22/researchers-crack-bitcrypt-ransomware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Browser-based ransomware</title>
		<link>/2014/01/24/browser-based-ransomware/</link>
					<comments>/2014/01/24/browser-based-ransomware/#comments</comments>
		
		<dc:creator><![CDATA[Martijn]]></dc:creator>
		<pubDate>Fri, 24 Jan 2014 00:19:30 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[drive-by download]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[reveton]]></category>
		<guid isPermaLink="false">http://www.lapsedordinary.net/?p=78</guid>

					<description><![CDATA[Tonight I stumbled upon some browser-based ransonmware, that pretends to be a message from the police. This is neither very advanced (it isn&#8217;t anything like Cryptolocker), nor is it very new. It doesn&#8217;t install any malware on your machine (though this trick has been used by actual malware, such as &#8216;Urausy&#8217;). All it does is [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Tonight I stumbled upon some browser-based ransonmware, that pretends to be a message from the police. This is neither very advanced (it isn&#8217;t anything like <a href="http://www.virusbtn.com/blog/2013/11_18.xml">Cryptolocker</a>), nor is it very new. It doesn&#8217;t install any malware on your machine (though this trick has been used by actual malware, such as &#8216;Urausy&#8217;). All it does is tell you that &#8220;your browser has been blocked up for safety reasons&#8221;, and that to prevent going to jail for anything between 5 and 11 years (for watching something very illegal), you need to pay a fine. Because of course, that is how the legal system works.<br />
<center><a href="/wp-content/uploads/2014/01/policeransomware.png"><img fetchpriority="high" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/policeransomware-300x197.png" alt="policeransomware" width="300" height="197" class="alignnone size-medium wp-image-81" /></a></center><br />
I&#8217;ll do a more detailed write-up about this later. I thought it was interesting that it was spreading via <i>Twitter</i> and used some subdomains to domains hosted at a UK-based registrar, whose customers probably had their DNS hacked.<br />
One thing that is typical for this kind of scam is that based on where you access the website from, you get the message in the local language and the logo of the national police force. They typically include a photo of the head of state as well. Because that makes it a lot more real.<br />
And since this isn&#8217;t a very advanced scam, I could grab the various logos that are used. I had seen most of these before, but I don&#8217;t know if they had ever been shown on a single site. Now they have. (Actually, just before posting I noticed these are the same images used by Urausy last summer; <a href="http://malware.dontneedcoffee.com/2013/07/urausy-ransomware-july-2013-design.html">Kafeine</a> has all those images. Oh well.)<br />
Austria<br />
<center><a href="/wp-content/uploads/2014/01/AT.jpg"><img decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/AT-300x52.jpg" alt="AT" width="300" height="52" class="alignnone size-medium wp-image-83" /></a></center><br />
Australia<br />
<center><a href="/wp-content/uploads/2014/01/AU.jpg"><img decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/AU-300x52.jpg" alt="AU" width="300" height="52" class="alignnone size-medium wp-image-84" /></a></center><br />
Belgium<br />
<center><a href="/wp-content/uploads/2014/01/BE.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/BE-300x52.jpg" alt="BE" width="300" height="52" class="alignnone size-medium wp-image-85" /></a></center><br />
Bolivia<br />
<center><a href="/wp-content/uploads/2014/01/BO.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/BO-300x52.jpg" alt="BO" width="300" height="52" class="alignnone size-medium wp-image-86" /></a></center><br />
Canada<br />
<center><a href="/wp-content/uploads/2014/01/CA.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/CA-300x52.jpg" alt="CA" width="300" height="52" class="alignnone size-medium wp-image-87" /></a></center><br />
Cyprus<br />
<center><a href="/wp-content/uploads/2014/01/CY.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/CY-300x52.jpg" alt="CY" width="300" height="52" class="alignnone size-medium wp-image-89" /></a></center><br />
Czech Republic<br />
<center><a href="/wp-content/uploads/2014/01/CZ.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/CZ-300x52.jpg" alt="CZ" width="300" height="52" class="alignnone size-medium wp-image-90" /></a></center><br />
Germany<br />
<center><a href="/wp-content/uploads/2014/01/DE.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/DE-300x52.jpg" alt="DE" width="300" height="52" class="alignnone size-medium wp-image-91" /></a></center><br />
Ecuador<br />
<center><a href="/wp-content/uploads/2014/01/EC.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/EC-300x52.jpg" alt="EC" width="300" height="52" class="alignnone size-medium wp-image-92" /></a></center><br />
Finland<br />
<center><a href="/wp-content/uploads/2014/01/FI.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/FI-300x52.jpg" alt="FI" width="300" height="52" class="alignnone size-medium wp-image-94" /></a></center><br />
France<br />
<center><a href="/wp-content/uploads/2014/01/FR.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/FR-300x52.jpg" alt="FR" width="300" height="52" class="alignnone size-medium wp-image-95" /></a></center><br />
Greece<br />
<center><a href="/wp-content/uploads/2014/01/GR.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/GR-300x52.jpg" alt="GR" width="300" height="52" class="alignnone size-medium wp-image-97" /></a></center><br />
Hungary<br />
<center><a href="/wp-content/uploads/2014/01/HU.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/HU-300x52.jpg" alt="HU" width="300" height="52" class="alignnone size-medium wp-image-98" /></a></center><br />
Ireland<br />
<center><a href="/wp-content/uploads/2014/01/IE.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/IE-300x52.jpg" alt="IE" width="300" height="52" class="alignnone size-medium wp-image-99" /></a></center><br />
Italy<br />
<center><a href="/wp-content/uploads/2014/01/IT.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/IT-300x52.jpg" alt="IT" width="300" height="52" class="alignnone size-medium wp-image-100" /></a></center><br />
Latvia<br />
<center><a href="/wp-content/uploads/2014/01/LV.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/LV-300x52.jpg" alt="LV" width="300" height="52" class="alignnone size-medium wp-image-101" /></a></center><br />
Mexico<br />
<center><a href="/wp-content/uploads/2014/01/MX.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/MX-300x52.jpg" alt="MX" width="300" height="52" class="alignnone size-medium wp-image-102" /></a></center><br />
Netherlands<br />
<center><a href="/wp-content/uploads/2014/01/NL.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/NL-300x52.jpg" alt="NL" width="300" height="52" class="alignnone size-medium wp-image-103" /></a></center><br />
New Zealand<br />
<center><a href="/wp-content/uploads/2014/01/NZ.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/NZ-300x52.jpg" alt="NZ" width="300" height="52" class="alignnone size-medium wp-image-105" /></a></center><br />
Norway<br />
<center><a href="/wp-content/uploads/2014/01/NO.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/NO-300x52.jpg" alt="NO" width="300" height="52" class="alignnone size-medium wp-image-104" /></a></center><br />
Poland<br />
<center><a href="/wp-content/uploads/2014/01/PL.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/PL-300x52.jpg" alt="PL" width="300" height="52" class="alignnone size-medium wp-image-106" /></a></center><br />
Portugal<br />
<center><a href="/wp-content/uploads/2014/01/PT.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/PT-300x52.jpg" alt="PT" width="300" height="52" class="alignnone size-medium wp-image-107" /></a></center><br />
Romania<br />
<center><a href="/wp-content/uploads/2014/01/RO.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/RO-300x52.jpg" alt="RO" width="300" height="52" class="alignnone size-medium wp-image-108" /></a></center><br />
Slovakia<br />
<center><a href="/wp-content/uploads/2014/01/SK.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/SK-300x52.jpg" alt="SK" width="300" height="52" class="alignnone size-medium wp-image-111" /></a></center><br />
Slovenia<br />
<center><a href="/wp-content/uploads/2014/01/SI.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/SI-300x52.jpg" alt="SI" width="300" height="52" class="alignnone size-medium wp-image-110" /></a></center><br />
Spain<br />
<center><a href="/wp-content/uploads/2014/01/ES.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/ES-300x52.jpg" alt="ES" width="300" height="52" class="alignnone size-medium wp-image-93" /></a></center><br />
Sweden<br />
<center><a href="/wp-content/uploads/2014/01/SE.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/SE-300x52.jpg" alt="SE" width="300" height="52" class="alignnone size-medium wp-image-109" /></a></center><br />
Switzerland<br />
<center><a href="/wp-content/uploads/2014/01/CH.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/CH-300x52.jpg" alt="CH" width="300" height="52" class="alignnone size-medium wp-image-88" /></a></center><br />
Turkey<br />
<center><a href="/wp-content/uploads/2014/01/TR.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/TR-300x52.jpg" alt="TR" width="300" height="52" class="alignnone size-medium wp-image-112" /></a></center><br />
United Kingdom<br />
<center><a href="/wp-content/uploads/2014/01/GB.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/GB-300x52.jpg" alt="GB" width="300" height="52" class="alignnone size-medium wp-image-96" /></a></center><br />
United States<br />
<center><a href="/wp-content/uploads/2014/01/US.jpg"><img loading="lazy" decoding="async" src="http://www.lapsedordinary.net/wp-content/uploads/2014/01/US-300x52.jpg" alt="US" width="300" height="52" class="alignnone size-medium wp-image-113" /></a></center></p>
]]></content:encoded>
					
					<wfw:commentRss>/2014/01/24/browser-based-ransomware/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
