Jump to content

Recommended Posts

  • ExTS Admin
Posted

A new variant of the Apocalypse Ransomware was released that utilizes the VMProtect software protection product.

Using VMProtect, the ransomware developers hoped to make it more difficult for security researchers to reverse engineer their ransomware.

 

Over the weekend, Fabian Wosar, of Emsisoft, was able to get past the VMProtect protection and create a decryptor for the latest variant of the Apocalypse Ransomware's encrypted files.

This new variant uses the .encrypted and .locked extensions and will create a ransom note called [filename].How_To_Get_Back.txt for each file that is encrypted.

For example, the ransom note for the test.jpg file will be called test.jpg.How_To_Get_Back.txt.

 

To decrypt your files, you can download the ApocalypseVM decryptor from the link below.

 

http://img.photobucket.com/albums/v708/starbuck50/decryptinfinite-icon_zpsrg1v5xxn.png

Apocalypse Decryptor

 

Once downloaded, you will most likely need to drag a encrypted and unencrypted copy of the same file on top of the decryptor in order to generate the key.

These files also need to be at least 4096 bytes in order for this process to work.

If a key can be found it will show an alert like the one below.

 

http://img.photobucket.com/albums/v708/starbuck50/key-found_zpssvgbvi1v.png

 

If a key is found, press OK and follow the prompts till you get to the main screen.

You can then click on the Decrypt button to decrypt the C: drive.

If there are other drives you need to decrypt, you can add them at this screen as well.

 

The decryptor will then decrypt your files and display a screen similar to the one below.

 

http://img.photobucket.com/albums/v708/starbuck50/decrypted_zpsluhyt15h.png

 

The files should now be decrypted and you can exit the program.

 

 

Source and Credit:

 

Lawrence Abrams

http://www.bleepingcomputer.com/news/security/emsisoft-releases-a-decryptor-for-the-apocalypsevm-ransomware/

Member of:

UNITE

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...