ExTS Admin Starbuck Posted June 22, 2016 ExTS Admin Posted June 22, 2016 A new variant of the Apocalypse Ransomware was released that utilizes the VMProtect software protection product. Using VMProtect, the ransomware developers hoped to make it more difficult for security researchers to reverse engineer their ransomware. Over the weekend, Fabian Wosar, of Emsisoft, was able to get past the VMProtect protection and create a decryptor for the latest variant of the Apocalypse Ransomware's encrypted files. This new variant uses the .encrypted and .locked extensions and will create a ransom note called [filename].How_To_Get_Back.txt for each file that is encrypted. For example, the ransom note for the test.jpg file will be called test.jpg.How_To_Get_Back.txt. To decrypt your files, you can download the ApocalypseVM decryptor from the link below. http://img.photobucket.com/albums/v708/starbuck50/decryptinfinite-icon_zpsrg1v5xxn.png Apocalypse Decryptor Once downloaded, you will most likely need to drag a encrypted and unencrypted copy of the same file on top of the decryptor in order to generate the key. These files also need to be at least 4096 bytes in order for this process to work. If a key can be found it will show an alert like the one below. http://img.photobucket.com/albums/v708/starbuck50/key-found_zpssvgbvi1v.png If a key is found, press OK and follow the prompts till you get to the main screen. You can then click on the Decrypt button to decrypt the C: drive. If there are other drives you need to decrypt, you can add them at this screen as well. The decryptor will then decrypt your files and display a screen similar to the one below. http://img.photobucket.com/albums/v708/starbuck50/decrypted_zpsluhyt15h.png The files should now be decrypted and you can exit the program. Source and Credit: Lawrence Abrams http://www.bleepingcomputer.com/news/security/emsisoft-releases-a-decryptor-for-the-apocalypsevm-ransomware/ Quote Member of:UNITE
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.