App Review GOLDENEYE Ransomware!Demonstration of attack video review.

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 43
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
Note that with this new malware the Mischa component is dropped only when the original malware vector can't get Admin privilege. Otherwise you'll see the usual system repair screens while the malware is messing with the MBR, and when finished you'll get the "skull and crossbones" ransom screen- this time in Yellow. Petya 1 and 2 were Red and Green, respectively (or was it the other way around?),
 

tim one

Level 21
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
I wonder to myself if they fixed the problem of the old version: by extracting 512 verification bytes from sector 55 and 8 bytes from the sector 54 of the infected drive (both encoded in Base64), it was possible to generate the decryption key needed to unlock the data.

Indeed...useless question, they will fix that for sure :D
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top