Encrypted files

Discussion in 'Malware Analysis Archive' started by Palanca, Oct 6, 2015.

  1. Palanca

    Palanca New Member

    Oct 5, 2015
    2
    3
    Sweden
    Hi

    I am sorry if I have posted in the wrong forum...

    I have stumbled upon a problem. I have not found a source executable but have alot of encrypted files. The encrypted files has an email appended to the filename. I have found the source user because his user folder has encrypted files. But I can't find any ransom instructions!

    Files encrypted has the following file extensions txt, xls, pdf, sql, jpg, mp3, wmv, doc, ppt, gho, xlsm, zip, spf, avi, rar, sldprt, mdb, iso, xml, pdb, rtf (probably more).

    What kind of malware could this be?
     
    Spawn likes this.
  2. frogboy

    frogboy Level 61
    Trusted

    Jun 9, 2013
    6,228
    64,805
    Heavy Duty Mechanic.
    Western Australia
    Windows 10
    Emsisoft
    upnorth, LabZero and Spawn like this.
  3. jamescv7

    jamescv7 Level 61
    Trusted

    Mar 15, 2011
    12,664
    17,722
    Web and FileMaker Developer
    Philippines
    Windows 10
    Microsoft
    @Palanca : Any malware that can be related to Cryptolocker or others cause the number one main attack landscape is by encrypted the common file extensions.
     
    LabZero likes this.
  4. Spawn

    Spawn Administrator
    Staff Member Content Creator

    Jan 8, 2011
    16,260
    24,187
  5. Palanca

    Palanca New Member

    Oct 5, 2015
    2
    3
    Sweden
    Hi

    I posted in that forum but it was moved here. (I think)
     
  6. LabZero

    LabZero Guest

    Hello, presumably it could be a ransomware.
    Maybe you don't find the .exe file because it may have been removed by the antivirus but it is only a hypothesis, not knowing the facts.
    Unfortunately there is no guarantee that you will be able to recover the files.
    The only prevention is the backup plan.
     
    frogboy likes this.
Loading...
Similar Threads Forum Date
New ransonware encrypted my files to .aac "Learn how to recover your files.txt" Malware Removal Assistance For Windows Jul 25, 2017
Malware Alert The Locky Ransomware is Back and Still Adding OSIRIS to Encrypted Files Security News Apr 22, 2017
Add-on It is possible to decrypt files encrypted with Trojan.Encoder.10465 Dr Web Apr 15, 2017