- Related Stories
-
Fix in for Windows flaw
May 10, 2005 -
Why hackers are a step ahead of the law
May 14, 2002
This so-called "ransomware" Trojan, dubbed Cryzip, is the second of its type to emerge in the past 10 months, following the PGPcoder Trojan. It also is the third such Trojan to appear since 1989.
Lurhq researchers noted Tuesday that the appearance within a year of two encryption Trojans may indicate they are part an emerging trend in malicious software.
"Last year, we saw the PGPcoder, and anything that shows itself to be a viable way to make money, usually people start jumping on the bandwagon after that," said Joe Stewart, senior security researcher for Lurhq.
The Cryzip Trojan will search for files, such as source code or database files, on infected systems. It then uses a commercial zip library to store the encrypted files. Security researchers, however, have yet to determine how the Trojan is distributed, noting it could come from a number of sources, including malicious Web sites, or enter through a previously created backdoor on a virus-infested computer.
The Trojan will overwrite the victims' text and then delete it, leaving only encrypted material that contains the original file name and _CRYPT_.ZIP.
"Unlike the PGPcoder that used a trivial encryption scheme, the zip encryption is stronger. It's harder to go through a list of possible (encryption) keys to get the information back," Stewart said. "But a brute-force attack is still possible, if a user has a copy of the original file. It can be reversed-engineered with a copy of the Trojan."
Cryzip has yet to become a widespread problem. Lurhq said it is aware of only about two dozen infection cases. Increasingly, malicious software writers are becoming more interested in launching low-level attacks in the hopes that it will take longer for security companies to notice their presence and develop a defense.
Users may also be less willing to seek help if it involves disclosing where they might have come across the threat.
The Cryzip writer, who uses an E-Gold account for collecting ransom payments, tells the victims: "Your computer catched our software while browsing illegal porn pages, all your documents, text files, databases was archived with long enough password. You cannot guess the password for your archived files--password length is more than 10 symbols that makes all password recovery programs fail to bruteforce it."
The Trojan writer then goes on to demand that a $300 payment be sent electronically to the E-Gold account.
Stewart advises users to frequently back up their important files, not only to minimize the damage if their system crashes but to reduce damage from an encryption attack.
See more CNET content tagged:
LURHQ Corp., malicious software, trojan horse, victim, writer






- How little do you know
- by mario05111976 March 22, 2006 7:15 AM PST
- No they don't get it because of porn. Porn is the mosty common platform to use on the net, since over 80% of net users do visit porn sites. And nobody deserves it either. Another words if a woman wears very sexy clothes, and gets raped, according to you she deserves it. My god, I thought narrow minded dinos died long time ago, quess I was wrong. It's a shame that people get victimized, and then somebody like yourself comes along and says: "You deserve it".
- Like this Reply to this comment
-
-
- Finally, somebody intelligent
- by pcdoctor101 March 22, 2006 8:32 AM PST
- You've got it! Perfect platform to conduct criminal activities. Porn is the most visited on the internet. Not just in North America, but world wide. People like sex, it's our nature. Most people would feel to embarassed to go to a local porn shop, but in privacy of their own homes, they can satisfy their needs and curiosity. Curiosity can be a weaknes, and in this case is being exploited by thief.<br />And to even suggest by Brian S. that "They deseve it", it's pretty pathetic.
- Like this
-
(24 Comments)