Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Twist on Spyware--Ransonware (My Title)
LurHQ ^ | March 11, 2006 | by LURHQ Threat Intelligence Group

Posted on 03/16/2006 7:43:24 PM PST by yhwhsman

In May 2005, a trojan called PGPcoder was discovered in the wild by Websense Security Labs. The trojan's purpose was to encrypt a user's files, then demand a ransom for their decryption. Although this scheme seemed novel, it is actually predated by over 15 years, by a similar scam in 1989. LURHQ's Threat Intelligence Group has now discovered a third such scheme involving ransomware which we are calling Cryzip.

Unlike PGPcoder, which used a custom encryption scheme (which was subsequently reverse-engineered by LURHQ), Cryzip uses a commercial zip library in order to store files inside a password-protected zip. Although the zip encryption is stronger, a brute-force attack is still possible on the files, especially if one has a copy of the original file inside the zip.

(Excerpt) Read more at lurhq.com ...


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; News/Current Events; Technical
KEYWORDS: adware; computer; getamac; linus; linux; macos; malware; ransonware; spyware; threat; trojan; trojans; virus; windows; windoze
Navigation: use the links below to view more comments.
first 1-2021-37 next last
Great, as if normal spyware wasn't enough of a hassle.
1 posted on 03/16/2006 7:43:27 PM PST by yhwhsman
[ Post Reply | Private Reply | View Replies]

To: yhwhsman

One of the irritating aspects is that even people who send in the ransom money often don't recive the unlock code.


2 posted on 03/16/2006 7:44:46 PM PST by gondramB (Render unto Caesar that which is Caesar's and unto God that which is God's.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: yhwhsman
Linux is the cure for the common spyware.
3 posted on 03/16/2006 7:49:31 PM PST by Halfmanhalfamazing (Linux, the #2 OS. Mac, the #3 OS. Apple's own numbers are hard to argue with.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: yhwhsman
Here's the story via Fox: Computer Virus Demands Ransom for Encrypted Files
4 posted on 03/16/2006 7:50:48 PM PST by yhwhsman ("Never give in--never, never, never, never, in nothing great or small..." -Sir Winston Churchill)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Halfmanhalfamazing

I'd prefer an operating system to an thing that needs to be endlessly tweaked. Something that runs software and is generally useful. And even fun.

Probably most of these idiotic geeks who create spyware and viruses and other malware are LUNIX users trying to herd us into LUNIX before springing some final trap.

No thank you.

Why does LUNIX use the penguin as it's mascot? They ripped off the O/S from UNIX so did they rip off their mascot from the 1980's video game Pengo? Pengo was fun and most LUNIX geeks are generally humorless and uptight so I don't think that's it. So where did they rip off their mascot from? I know they didn't come up with it on their own.


5 posted on 03/16/2006 8:01:02 PM PST by Duke Nukum (To thine own self be true...or relatively true. --Guy Caballero)
[ Post Reply | Private Reply | To 3 | View Replies]

To: yhwhsman

At least two full backups of important data stored separate from the computer is the answer. It is not difficult to do. IOMEGA has the fast REV drive now with replaceable 35 GB drives or there are many other solutions such as thumb (handy) USB drives.


6 posted on 03/17/2006 12:34:14 AM PST by Northern Alliance
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

7 posted on 03/17/2006 5:55:50 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Duke Nukum
I know they didn't come up with it on their own.

You're wrong of course--just like most of the rest of your post. Google the history of the logo if you're that interested.

8 posted on 03/17/2006 5:57:33 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Duke Nukum
I'd prefer an operating system to an thing that needs to be endlessly tweaked. Something that runs software and is generally useful. And even fun.

I absolutely agree.

There's no fun in having to buy, install and maintain anti-virus, anti-spyware, personal firewalls, service packs and who-knows-what.

Even IE5, which shipped with Windows 2000 Pro, is too obsolete for some modern software and has to be "upgraded" to IE6. Outlook Express still doesn't support yEnc, so it's almost totally unusable on usenet, and you have to buy a decent usenet client.

Meanwhile, my Linux servers just run happily in their closet in the guest bedroom. No need to touch them except for monthly backups. My Linux workstation supports anything I want to do on the Internet. No need to buy anything more, if there's something else you need you just look around SourceForge.

9 posted on 03/17/2006 6:12:08 AM PST by TechJunkYard (DMCA: Don't Make Content Accessable)
[ Post Reply | Private Reply | To 5 | View Replies]

To: TechJunkYard

What got me was when I found XP won't restore backup files made in Win 95.


10 posted on 03/17/2006 6:43:25 AM PST by Tribune7
[ Post Reply | Private Reply | To 9 | View Replies]

To: Duke Nukum
They ripped off the O/S from UNIX

Actually, he got the basics from his college textbook, which had Minix, itself a UNIX clone written from scratch by professor Andrew Tanenbaum, a friend of the creators of UNIX.

11 posted on 03/17/2006 6:43:34 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 5 | View Replies]

To: yhwhsman; ShadowAce
I received a spoof email this morning that was so deceptive I would have clicked through except Cox mail had marked it as spam. It was a message from a eBay seller offering me a Second Chance offer for a item. The format was a perfect copy and except for the poor spelling I almost fell for it.

I cut and pasted the item number in the eBay search box and it came back as a listing from a member warning of the spoof.

Here is the warning... SPOOF
12 posted on 03/17/2006 7:09:48 AM PST by tubebender (BIG REWARD for my missing tag line. Please advance a security deposit to enter...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: yhwhsman
Here is a sure solution to this problem:

http://en.wikipedia.org/wiki/Scaphism

with 24hr webcams.
13 posted on 03/17/2006 1:51:16 PM PST by beef (Who Killed Kennewick Man?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: yhwhsman

I am beginning to think that the solution is to have an independant computer just for the internet. Keep a set of the operating system software and if something by passes all my protection, just reformat and reload, and start over.

Keep all my important stuff on a separate computer not connected in any way to the internet computer.


14 posted on 03/17/2006 1:58:48 PM PST by CIB-173RDABN
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
You're wrong of course--just like most of the rest of your post. Google the history of the logo if you're that interested.

Wow! LUNIX came up with a penguin all on their own! Who knows, maybe one day they will write their own O/S and stop ripping of UNIX.

In the meanwhile, I'll play some games while waiting for someone to come up with an O/S that sucks less then XP.

15 posted on 03/17/2006 2:49:11 PM PST by Duke Nukum (To thine own self be true...or relatively true. --Guy Caballero)
[ Post Reply | Private Reply | To 8 | View Replies]

To: tubebender
Yeah... I fell for such a spoof. Never again!

(Denny Crane: "I Don't Want To Socialize With A Pinko Liberal Democrat Commie. Say What You Like About Republicans. We Stick To Our Convictions. Even When We Know We're Dead Wrong.")

16 posted on 03/17/2006 2:54:46 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Duke Nukum
and stop ripping of UNIX

See Post #11.

17 posted on 03/17/2006 3:56:07 PM PST by rzeznikj at stout (This is a darkroom. Keep the door closed or you'll let all the dark out...)
[ Post Reply | Private Reply | To 15 | View Replies]

To: TechJunkYard
Meanwhile, my Linux servers just run happily in their closet in the guest bedroom.

Oh yeah, LUNIX is great as long as you never have to use it. It's when you want to do things like edit photos or process words. Then you have to know that Photoshop is called GIMP and Word for LUNIX is called Painful Rectal Itch.

I think the LUNIX geeks write the spyware and viruses so they can boast about how great LUNIX is and feel good that they belong to an exclusive club when they can't find any D&D players in the neighborhood. Otherwise, there's no reason for LUNIX to be so mind bendingly stupid.

I mean, when it first came out, yeah, it had to be mind bendingly stupid because they didn't have more then two bits of memory back then, but now it's a million years later so the only reason must be anti-social geek angle.

Well, at least it keeps them from the World Domination Plots James Bond used to have to break up in the 1960's.

Speaking of movie plot devices, I think my favorite version of UNIX ever is the one they used in Jurassic Park.

18 posted on 03/17/2006 3:56:18 PM PST by Duke Nukum (To thine own self be true...or relatively true. --Guy Caballero)
[ Post Reply | Private Reply | To 9 | View Replies]

To: antiRepublicrat
Any idea if Minix installs on VMWare (player)?
19 posted on 03/17/2006 3:57:21 PM PST by rzeznikj at stout (This is a darkroom. Keep the door closed or you'll let all the dark out...)
[ Post Reply | Private Reply | To 11 | View Replies]

To: antiRepublicrat
Actually, he got the basics from his college textbook, which had Minix, itself a UNIX clone written from scratch by professor Andrew Tanenbaum, a friend of the creators of UNIX.

So, LUNIX is a rip-off of a rip-off, then. Very good, since Windows is a rip-off of a rip-off too. Except it doesn't suck as bad as LUNIX. Except for all the viruses and malware the jealous LUNIX geeks write it's a hardly noticeable level of suckiness.

But, realistically, I don't think there will ever be an O/S that doesn't suck, it's the nature of the machines. Maybe, one day, if there are organic computers that write their own O/S based on their biological function, that might be as close to zero suckiness as it can get, but it's probably a long way off if it happens at all.

20 posted on 03/17/2006 4:08:40 PM PST by Duke Nukum (To thine own self be true...or relatively true. --Guy Caballero)
[ Post Reply | Private Reply | To 11 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-37 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson