PadCrypt is a new ransomware
discovered by @abuse.ch and
analyzed by MalwareHunterTeam that
implement a chat interface embedded in its product. For the first time a
ransomware virus offers a live support chat feature as well as an uninstaller
for its victims.
It is very shocking because this is the first ransomware which
provide support service on their payment sites. With the help of live chat features,
it let you interact with the malware developers in the real time.
PadCrypt offers a Live Support Chat Feature
Ransomware took a new turn by
releasing of PadCrypt, customer support. This new malware offers live chat, that
is enough to gain trust of victim.
Live Chat option let the victim send message to the developers.
Live Chat feature of PadCrypt
Now the Command & Control servers for PadCrypt are offline so it won’t actually encrypt anything though it display the ransomware screen. In addition, the live support chat requires to active C2 server.
PadCrypt let you to remove the infection easily
Those who want to remove
this virus from them PadCrypt makes it easy by giving the uninstaller. It has
been noticed that the ransomware let you to enable and disable autorun. When it
gets installed, an uninstaller can be downloaded and installed at %AppData%\PadCrypt\unistl.exe.
And once you execute the uninstaller, it’ll remove all the ransom notes
and files linked with PadCrypt infection. But the encrypted files will remain
there.
Ransomware developers added some CryptoWall features
There is something
in CryptoWall that almost very ransomware developers love to use in their other
ransomware virus. This is also noticed in the case of PadCrypt as the
executable have the various references to the CryptoWall in it. For instance
the PDB for PadCrypt executable is:
C:\Users\user\Documents\Visual
Studio 2013\Projects\Cryptowall
2.0\Cryptowall\bin\Debug\Obfuscated\PadCrypt.pdb
There are various references
to CryptoWall inside C# project for this new ransomware. Like the namespaces
for ransomware is also known as Cryptowall.
For More Information: https://www.pcthreatremoval.net/new-ransomware-padcrypt-the-first-with-live-chat-support
0 comments:
Post a Comment