Spora Ransomware
cruelsister Level 43 Thread author Verified Honorary Member Top Poster Content Creator Well-known Apr 13, 2013 3,224 Jan 10, 2017 #1 Reactions: Der.Reisende, Exterminator, WinXPert and 22 others
Duotone Level 10 Verified Well-known Mar 17, 2016 464 Jan 10, 2017 #2 Zero-day... and you already got a sample Reactions: Der.Reisende, Svoll, Evjl's Rain and 4 others
Solarquest Moderator Verified Staff Member Malware Hunter Well-known Jul 22, 2014 2,525 Jan 10, 2017 #3 Any chance you post it on the HUB for us to test it? Reactions: Der.Reisende, Svoll, Evjl's Rain and 3 others
H HarborFront Level 72 Verified Top Poster Content Creator Oct 9, 2016 6,142 Jan 10, 2017 #4 Can AppCheck block it? Reactions: Der.Reisende and Svoll
cruelsister Level 43 Thread author Verified Honorary Member Top Poster Content Creator Well-known Apr 13, 2013 3,224 Jan 10, 2017 #5 Yes it does. Actually I ran the malware initially on a system with AppCheck on it- the encryption process was detected and prevented. Reactions: Der.Reisende, HarborFront, Evjl's Rain and 4 others
Yes it does. Actually I ran the malware initially on a system with AppCheck on it- the encryption process was detected and prevented.
_CyberGhosT_ Level 53 Verified Honorary Member Top Poster Content Creator Well-known Aug 2, 2015 4,286 Jan 10, 2017 #6 cruelsister said: Yes it does. Actually I ran the malware initially on a system with AppCheck on it- the encryption process was detected and prevented. Click to expand... +1 for little known AppCheck, nice job Reactions: Der.Reisende, Evjl's Rain and Svoll
cruelsister said: Yes it does. Actually I ran the malware initially on a system with AppCheck on it- the encryption process was detected and prevented. Click to expand... +1 for little known AppCheck, nice job
Solarquest Moderator Verified Staff Member Malware Hunter Well-known Jul 22, 2014 2,525 Jan 11, 2017 #7 I just run Appcheck free with default settings in an older VM and .jpgs were encrypted... Reactions: Der.Reisende, _CyberGhosT_, Evjl's Rain and 3 others
Z Zero Knowledge Level 20 Verified Top Poster Content Creator Dec 2, 2016 849 Jan 11, 2017 #8 Nice video. Thanks! Reactions: Der.Reisende
Solarquest Moderator Verified Staff Member Malware Hunter Well-known Jul 22, 2014 2,525 Jan 11, 2017 #9 Appcheck 2.0.2.0.20 missed it Appcheck 2.0.0.20 blocked it. Reactions: Der.Reisende, harlan4096 and Evjl's Rain
cruelsister Level 43 Thread author Verified Honorary Member Top Poster Content Creator Well-known Apr 13, 2013 3,224 Jan 11, 2017 #10 Yeah- the current AppCheck version (build 20) that was released a few days prior to the release of this ransomware detected the encryption routine totally. Reactions: Der.Reisende and harlan4096
Yeah- the current AppCheck version (build 20) that was released a few days prior to the release of this ransomware detected the encryption routine totally.