Crypt0L0cker

Tony Cole

Level 27
Thread author
Verified
May 11, 2014
1,639
Hi Everyone:

Has/have you heard about Crypt0L0cker, thread on:


http://www.bleepingcomputer.com/forums/t/574608/crypt0l0cker-support-topic/

There is a new ransomware out called Crypt0L0cker (the OHs are replaced with ZEROs). This ransomware appears to be a direct descendant of TorrentLocker, with the only known difference at this point being how it targets files for encryption. It is currently being distributed via email campaigns claiming to be government notices such as speeding violations. Once a user is infected the ransom will be set at approximately 2 bitcoins. This infection is targeting almost all countries other than the United States. Computers using an United States IP address will not become infected at this time.

In the past TorrentLocker would target only certain file types for encryption. Crypt0L0cker on the hand uses an exclude list that contains only a few file types. This exclude list is:

avi,wav,mp3,gif,ico,png,bmp,txt,html,inf,manifest,chm,ini,tmp,log,url,lnk,cmd,bat,scr,msi,sys,dll,exe
Known Command & Control Servers and associated IP addresses:

62.173.145.212 tidisow . ru
62.173.145.212 lepodick . ru

We will be using this topic to support this ransomware and to post new analysis as it comes in.

Screenshots:

DECRYPT_INSTRUCTIONS.html.jpg

DECRYPT_INSTRUCTIONS.HTML


DECRYPT_INSTRUCTIONS.txt.jpg

DECRYPT_INSTRUCTIONS.TXT


decryption-site.jpg

Decryption Site Buy Decryption Page


free-decryption.jpg

Decryption Site One Free Decryption Page


frequently-asked-questions.jpg

Decryption Site FAQ Page


dc-support-page.jpg

Decryption Site Support Page


afp-ransomware.png
 
H

hjlbx

The exclude list allows for faster encryption process and less likelihood that user will notice something is amiss... until it's too late.
 
  • Like
Reactions: Tony Cole

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top