Mikrotek Solutions Ltd Mikrotek Solutions Ltd
Telephone: 01869 360006
Email: info@mikrotek-solutions.co.uk
  • Home
  • IT Services
    • IT Support Services
    • Networks And Infrastructure
    • Email Checker
  • Computer Hardware
  • Managed Services
  • Connectivity
  • Telephony
    • VOIP Phones For Small Business
    • Telephone Systems
  • Mikrotek Solutions
  • Customer Support
  • Mikrotek Blog
Mikrotek Solutions Ltd Mikrotek Solutions Ltd
  • Home
  • IT Services
    • IT Support Services
    • Networks And Infrastructure
    • Email Checker
  • Computer Hardware
  • Managed Services
  • Connectivity
  • Telephony
    • VOIP Phones For Small Business
    • Telephone Systems
  • Mikrotek Solutions
  • Customer Support
  • Mikrotek Blog
Aug 29

It’s Happening Again. but this time it’s users who like to look at photo’s

  • August 29, 2017
  • mikrotekhosting
  • IT News

This week, we have seen a new kind of ransomware being distributed via spam but also being repopulated on Facebook, Instagram and PinTerest. The purpose of this image is to be a message with a sense of urgency and importance that comes with a document attached but in fact contains a Windows Script file (.wsf) within a zip archive. Once executed it will download a seemingly non-malicious image file and then installs a ransomware called SyncCrypt.

Downloading the file will get you this non-malicious looking file:

The downloaded JPG is actually an archive which contains the Ransomeware components.

These files are then unpacked and saved in the following location:

  • %temp%/BackupClient/sync.exe [Detected as GAV: SyncCrypt.RSM (Trojan)
  • %temp%/BackupClient/readme.html
  • %temp%/BackupClient/readme.png

It then tries to confuse the victim by displaying an error message after the script runs.

Meanwhile the ransomware encrypts the victim’s file like usual and appends .KK to all encrypted files. The ransomware note with details on payment instructions is then displayed as shown in the figure below:

Because of the prevalence of these types of malware attacks, I recommend training users as well having them back up their files regularly.

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)

Related

  • Facebook
  • Twitter
  • Tumblr
  • Pinterest
  • Google+
  • LinkedIn
  • E-Mail

About The Author

About Mikrotek Solutions

Established Specialists in Managed IT Services.

The world of Information Technology has certainly evolved since Mikrotek Solutions was launched in 1999.

We’ve seen the rise of the internet, the mass adoption of smart technology and the move to cloud based solutions.

Privacy Policy

Areas Served

Located in Bicester, Oxfordshire.

Mikrotek Solutions Ltd have been providing IT Support Services to small businesses for eighteen years.

We serve the Thames Valley area within a 30-mile radius of Bicester.

Index

  • Home
  • Privacy Policy
  • Mikrotek Solutions
  • Networks And Infrastructure
  • IT Support Services
  • Managed Services
  • VOIP Phones For Small Business
  • Computer Hardware
  • Connectivity
  • Email Checker
  • Telephone Systems
  • Customer Support
  • Mikrotek Blog

Contact Us

Office Number:
01869 360 006

08:00 – 18:00 Monday – Friday

General Enquiries
info@mikrotek-solutions.co.uk

Client Support Enquiries
support@mikrotek-solutions.co.uk

© All Rights Reserved, Mikrotek Solutions 2017 | Website design by: YostratO Ltd
 

Loading Comments...