Infected By Cryptolocker? Get Your Files Back For Free!

Status
Not open for further replies.

Cowpipe

Level 16
Thread author
Verified
Well-known
Jun 16, 2014
781
Today marks the launch of a new online service provided by FireEye and Fox-IT aimed at helping victims of Cryptolocker to recover their files for free.

The service can be accessed here and comes after a major operation to grab a copy of Cryptolockers database proved successful.

crypto2.png


For more information and to read the full blog post detailing how Cryptolocker works and how the service works, see the blog post here.

A word of caution to anyone jumping for joy, there are many variants of Cryptolocker and so using the decryption service is by no means a guarantee of getting your files back safe and sound. It is however, another beacon of hope for innocent victims caught up in the ongoing battle against ransomware.
 

marg

Level 12
Verified
May 26, 2014
583
Thats news for some hope at least. I notice they use that stupid scrambled word text that is very hard for a normal person to figure out. I really hate sites that use this & what is the reason for using it.:confused:
 
R

RevolutionSphere

Thats news for some hope at least. I notice they use that stupid scrambled word text that is very hard for a normal person to figure out. I really hate sites that use this & what is the reason for using it.:confused:
If I'm correct, I think its to stop spam.
 
  • Like
Reactions: Cowpipe

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
Thats news for some hope at least. I notice they use that stupid scrambled word text that is very hard for a normal person to figure out. I really hate sites that use this & what is the reason for using it.:confused:

To verify that you are human, as opposed to an automated robot spammer.
 
  • Like
Reactions: Cowpipe

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,148
Please note that FireEye is being upfront by stating that any files saved are being done so by the result of WhiteHat hacking and not by any un-encryption routine.

To give a bit of nebulous background, you may know that the group responsible for Cryptolocker was identified and subsequently busted. Prior to the shutdown, a database of all the private unlock keys were acquired by the GoodGuys. One can then compare a file that was encrypted by this strain of Cryptolocker and derive the unlock key by consulting the seized database. This is what the Service does.

Don't get me wrong- this is a good thing, but only for this specific Cryptolocker.


Fun Fact- Less than 2% of those infected actually paid the ransom to get the code to unlock their files.
 

Cowpipe

Level 16
Thread author
Verified
Well-known
Jun 16, 2014
781
Please note that FireEye is being upfront by stating that any files saved are being done so by the result of WhiteHat hacking and not by any un-encryption routine.

To give a bit of nebulous background, you may know that the group responsible for Cryptolocker was identified and subsequently busted. Prior to the shutdown, a database of all the private unlock keys were acquired by the GoodGuys. One can then compare a file that was encrypted by this strain of Cryptolocker and derive the unlock key by consulting the seized database. This is what the Service does.

Don't get me wrong- this is a good thing, but only for this specific Cryptolocker.


Fun Fact- Less than 2% of those infected actually paid the ransom to get the code to unlock their files.

Correct, which is why this is simply a "beacon of hope" rather than "First there was Crypto-locker, now there is Crypto-unlocker".

And interestingly that 2% accounted for approximately $30 million dollars, not bad earnings for a crook!
 
  • Like
Reactions: avast! Protection

Cowpipe

Level 16
Thread author
Verified
Well-known
Jun 16, 2014
781
Thats news for some hope at least. I notice they use that stupid scrambled word text that is very hard for a normal person to figure out. I really hate sites that use this & what is the reason for using it.:confused:

They're called CAPTCHA and some are much, much more annoying than others. The purpose however as others have pointed out is to try to verify if you're human or not by producing an image which cannot be automatically analysed for example by text recognition software (hence the distortions and lines). The recapcha series (an implementation or 'brand' of CAPTCHA) are incredibly annoying because of the way they distort the text, but they do have a secondary purpose in that the words come from old books. In entering the words you see on the screen, you're helping to digitize these old books.

There are other solutions however. SolveMedia produces a CAPTCHA system which requires you to enter in text from sponsors, which is of course, very easy to read.

captcha-ad.jpg


Although where the advertising CAPTCHAs are disabled, or where the website thinks that you're a robot, a harder CAPTCHA is delivered like this one:

widget-sec-l2.png


Notice the strong contrasting colours in the text and the irregularly shaped letters and broken lines. These are all to throw off recognition software ;)

Still, the CAPTCHA above is much easier to enter than Recaptcha with those annoying distortions:

PHP-Google-Captcha-reCAPTCHA.jpg


Hope that explains things a little better ;)
 

Moose

Level 22
Jun 14, 2011
2,271
Greeting!;)

FireEye:

From what I hear has a great Android Anti-virus! I would love to try there Windows and Android Anti-vrus does anybody
have a trail/demo and/or code? Thanks!
 
  • Like
Reactions: Cowpipe and Oxygen

Tony Cole

Level 27
Verified
May 11, 2014
1,639
Hi Cowpipe

This is excellent news, the fight against Cyryptolocker type malware is moving forward. Thank you for the info, it is very helpful and I've book marked the link. I just hope one never needs it.

Tony :)
 
  • Like
Reactions: Cowpipe
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top