Stung by Spora Ransomware - Bastard!

@Hawkster It says it's corrupted. But no infection occurred.

If you want, I can make a test with a smaller file maybe? 10-15mb max?

Nonetheless, this thing with ransomware looks great, and it seems that there are people willing to spend money.

How I believe it actually acts: it modifies the PATH for the .pdf/.doc format. So, instead of using adobe reader/microsoft office to open, it will actually open the virus. Simple, yet effective.

However, it may go deeper and inject some code in the .pdf/docx files, not sure yet.

I'd really give it a try if I wouldn't be so petrified by "ethics", but tell me what exactly is pure white hat?
Wow here comes the twist, don't do it man.
 
How I believe it actually acts: it modifies the PATH for the .pdf/.doc format. So, instead of using adobe reader/microsoft office to open, it will actually open the virus. Simple, yet effective.

However, it may go deeper and inject some code in the .pdf/docx files, not sure yet.

I'd really give it a try if I wouldn't be so petrified by "ethics", but tell me what exactly is pure white hat?

If only it was that simple to fix!

It encrypts the files at a byte level using public/private key encryption (RSA + AES). They hold the private key on their servers. The public one is generated by the malware on the PC on first run. The decryption tools in most cases have managed to reverse engineer the private key due to a maths fail (remember the ps3?) in creating it or the private key leaked from the server in some cases.

With spora the public key will be saved in a .key file. You would need this file to upload to them to get your files decrypted.


That sucks there's not much defence against that other than the obvious of not running random exe's. Im sure you'll remember that next time ;)

Are you running windows as Administrator account or Limited? If you're on a limited account the malware will have a much harder time latching onto your startup and as such will be a lot easier to get rid of.
 
Last edited:
Spora ransomware performs the encryption without a command and control (C&C) server connection. According to researchers from security firm Emsisoft, the Spora creators have developed this ransomware to contain a hard-coded RSA public key. This RSA pulic key is used to encrypt a unique AES key that is locally generated for every victim. Ransomware is mainly created to encrypt your data and demand you to pay money. Spora ransomware is found to spread via emails containing attachments. These emails contain a ZIP attachment and the ZIP contains an HTA (HTML Application) file inside, disguising as a PDF or DOC to entice users to click on it. After your computer gets infected with ransomware, you can get rid of it through performing system restore.
 
The only way was re install the os.

Even dll get locked.

Hope you backed up and made paper copys of all your apps and passwords dam job

Big headache
 
Spora ransomware performs the encryption without a command and control (C&C) server connection. According to researchers from security firm Emsisoft, the Spora creators have developed this ransomware to contain a hard-coded RSA public key. This RSA pulic key is used to encrypt a unique AES key that is locally generated for every victim. Ransomware is mainly created to encrypt your data and demand you to pay money. Spora ransomware is found to spread via emails containing attachments. These emails contain a ZIP attachment and the ZIP contains an HTA (HTML Application) file inside, disguising as a PDF or DOC to entice users to click on it. After your computer gets infected with ransomware, you can get rid of it through performing system restore.
There no way system restore will do it.

Sorry that a myth , it locks deep dll files
How can a restore correct that ?

No sorry i say a full re install only way , or take it to a de cripter cost thousands to de crept every file.

It grabs and piggy banks on the os it self...

If you find a way post evedence please .

Usally installed from risky websites or free software infected.
 
Last edited by a moderator:
I had a ransomware recently for the first time in my life. I didn't even know they existed to be honest.

Mine was called Cerber, or Cerberus, if I'm not mistaken.

What it did was encrypt various photos/word/notepad files, and every folder where it encrypted something it added a photo instructing me to download TOR, then go to a specific URL (which can only be accessed through the TOR browser), and then pay money in order to receive a key to unlock/decrypt my files.

But, thankfully I keep all my files backed up on external hard drives. So after a small upset, I calmed down, and formatted my lap top. I didn't lose any files. External hard drives kicked ass :)
 
Here are some tips to start surfing the interent securely:

- Don't rush.
- Check if the content is legit (through many ways).
- Don't use Microsoft Windows.

Shit, I've heard about another ransomware that offer you to decrypt your files for free as soon as you "invite" your friends (two of them) to download it. Forgot the name tho.

Wow a pyramid scheme ransomware :D. What's next "buy windows 10 pro or we'll send CP from your ip"? Joking aside, I feel bad for the OP, but at least now there is more awareness of this ransomware. :)
 
I had a ransomware recently for the first time in my life. I didn't even know they existed to be honest.

Mine was called Cerber, or Cerberus, if I'm not mistaken.

What it did was encrypt various photos/word/notepad files, and every folder where it encrypted something it added a photo instructing me to download TOR, then go to a specific URL (which can only be accessed through the TOR browser), and then pay money in order to receive a key to unlock/decrypt my files.

But, thankfully I keep all my files backed up on external hard drives. So after a small upset, I calmed down, and formatted my lap top. I didn't lose any files. External hard drives kicked ass :)
Well done , that why everybody needs to backup , they dont thu .

I give you another tip ,the ransom can even reach other harddrive devices if there connected , so it best once backed up onto a hardrive ,only re connect when need to .

Downloading free sofwere can cause random .

But you also got websites that self trigger ransom downloads stright away.

The best pratice is to add a antivirus that can ptotect the browser for internet
Browsing , catch all infected web pages....
 
Well done , that why everybody needs to backup , they dont thu .

I give you another tip ,the ransom can even reach other harddrive devices if there connected , so it best once backed up onto a hardrive ,only re connect when need to .

Downloading free sofwere can cause random .

But you also got websites that self trigger ransom downloads stright away.

The best pratice is to add a antivirus that can ptotect the browser for internet
Browsing , catch all infected web pages....

Yeah, I figure as much. But it still won't hurt me. I have a 100% way of not losing jack.

I have all of my files on multiple external hard drives (one for movies, one for tv shows, one for music and a few other things, and one for all the rest).

And then I have 1 hard drive that's 6TB in size, and I have ALL the stuff from ALL my other hard drives backed up on the 6TB one. And I keep the 6TB hard drive in box I bought it in :D

So I can't lose :)
 
Yeah, I figure as much. But it still won't hurt me. I have a 100% way of not losing jack.

I have all of my files on multiple external hard drives (one for movies, one for tv shows, one for music and a few other things, and one for all the rest).

And then I have 1 hard drive that's 6TB in size, and I have ALL the stuff from ALL my other hard drives backed up on the 6TB one. And I keep the 6TB hard drive in box I bought it in :D

So I can't lose :)

Do you know where you picked this up from, which site you downloaded from?
 
Do you know where you picked this up from, which site you downloaded from?

Not exactly. But I was trying to download this program cracked - Easy Duplicate Finder

And I surely used one of the first Google results to download it from.

Firefox warned me the file is unsecure, I was suspicious, but I went ahead and installed and clicked next on everything. I fucked up, I deserved it. I was just in one of those "I don't give a fuck moods," and I stepped on my di*k.

And I run my computer without an antivirus (I've been running this way for over 5 years now), so I'm not a noob, I know what to do and what not to do. But this time, my "I don't care, just click next" attitude, really burned me.

But I've been wanting to do a format forever, so I just took it as a sign from the universe, a good thing, and I formatted :)
 
Just got hit on one my Windows server. Haven't logged in there for like 2 months. And crap:


===============================# aes-ni ransomware #===============================

                   █████╗ ███████╗███████╗      ███╗   ██╗██╗
                  ██╔══██╗██╔════╝██╔════╝      ████╗  ██║██║
                  ███████║█████╗  ███████╗█████╗██╔██╗ ██║██║
                  ██╔══██║██╔══╝  ╚════██║╚════╝██║╚██╗██║██║
                  ██║  ██║███████╗███████║      ██║ ╚████║██║
                  ╚═╝  ╚═╝╚══════╝╚══════╝      ╚═╝  ╚═══╝╚═╝

SPECIAL VERSION: NSA EXPLOIT EDITION

INTRO: If you are reading it, your server was attacked with NSA exploits.
Make World Safe Again.

SORRY! Your files are encrypted.
File contents are encrypted with random key (AES-256 bit; ECB mode).
Random key is encrypted with RSA public key (2048 bit).

We STRONGLY RECOMMEND you NOT to use any "decryption tools".
These tools can damage your data, making recover IMPOSSIBLE.

Also we recommend you not to contact data recovery companies.
They will just contact us, buy the key and sell it to you at a higher price.

If you want to decrypt your files, you have to get RSA private key.
 
Back
Top