vxCrypter Is the First Ransomware to Delete Duplicate Files

Stu Sjouwerman | Apr 1, 2019

 

image004

Our friend Larry Abrams at bleepingcomputer wrote: "The vxCrypter Ransomware could be the first ransomware infection that not only encrypts a victim's data, but also tidies up their computer by deleting duplicate files.

Last week I discovered a new ransomware called vxCrypter that was currently in development. It is a .NET ransomware and is based on an older ransomware that was never finished called vxLock.

When I first tested the ransomware, I noticed that it had deleted every file in a folder except for one, which is illustrated in the images below.   As I knew this ransomware was still being developed, I assumed it was just a bug in the encryption routine.

During the weekend, Michael Gillespie told me that this deletion of files was intentional as the ransomware was deleting duplicate files. Furthermore, this was the first ransomware that Gillespie or I have seen that performed this behavior.

When analyzing the ransomware, Gillespie noticed that the ransomware was keeping tracking of the SHA256 hashes of each file it encrypted. As the ransomware encrypted other files, if it encountered the same SHA256 hash, it would delete the file instead of decrypting it.

It is not known why the ransomware is doing this other than as a possible way to increase the speed of encrypting a computer. It also illustrates how we have to stay alert as attackers continue to evolve malware to increase performance, cause havoc, or just do things for no obvious reason. Full story and more tech detail at:

https://www.bleepingcomputer.com/news/security/vxcrypter-is-the-first-ransomware-to-delete-duplicate-files/


Get Your Ransomware Hostage Rescue Manual

Ransomware-Hostage-PagesThis 20-page manual is packed with actionable info that you need to prevent infections, and what to do when you are hit with malware like this. You also get a Ransomware Attack Response Checklist and Prevention Checklist. You will learn more about:

  • What is Ransomware?
  • Am I Infected?
  • I’m Infected, Now What?
  • Protecting Yourself in the Future
  • Resources

Don’t be taken hostage by ransomware. Download your rescue manual now! 

Get Your Manual

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://info.knowbe4.com/ransomware-hostage-rescue-manual-0

 

Topics: Ransomware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.