Jump to content

Breaking Bad themed Cryptolocker ransomware discovered

zlolslavez

Security researchers at Symantec recently discovered a new piece of malware that, believe it or not, incorporates a number of themes from the hit TV show Breaking Bad. The malware itself primarily affects users in Australia and represents a new strain of an existing ransomware trojan dubbed Trojan.Cryptolocker.S.

breaking-bad-pollos-hermanos-malware.png

this is a picture

 

 

This ransomware is generally only in the Australian area, but this is quite interesting, especially due to the recent talk about these things, and this shows the kinds of people that are creating these types of things. I am quite interested in "themed" viruses that may show up in the future.

 

Source of article : http://bgr.com/2015/05/11/breaking-bad-malware-gus-los-pollos-hermanos/

virustotal scan of article if you really think it's the actual malware : https://www.virustotal.com/en/url/7221d6154f6bb002a3285d31f0694ed676af211a64dbc6f6698d6f7d4e7fbfb4/analysis/1431399856/

Current Desktop Build | 2200G | RX 580 4GB | 8GB RAM | CTRL | Logitech G Pro Wireless

Laptop | 2018 MBA 256/16GB | MX Master 

Link to comment
Share on other sites

Link to post
Share on other sites

How exactly does one get around one of those? Seriously. I'm taking networking security classes, and after 7 semesters all we have covered is basically setup and prevention (plus english, math, and useless business and humanities classes). Nothing of any actual substance on how to get around or remove a malware.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Not sure the link called source is a news article or the malware.

Cleared up in the post if that was a legitimate post.

Current Desktop Build | 2200G | RX 580 4GB | 8GB RAM | CTRL | Logitech G Pro Wireless

Laptop | 2018 MBA 256/16GB | MX Master 

Link to comment
Share on other sites

Link to post
Share on other sites

Not sure the link called source is a news article or the malware.

It both :)

Magical Pineapples


 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Link to comment
Share on other sites

Link to post
Share on other sites

No I was joking.

Well now there's a virustotal link for anyone that thinks it is.

Current Desktop Build | 2200G | RX 580 4GB | 8GB RAM | CTRL | Logitech G Pro Wireless

Laptop | 2018 MBA 256/16GB | MX Master 

Link to comment
Share on other sites

Link to post
Share on other sites

You does this work without them getting caught. What do you pay them through

24 fps for that "cinematic" feel


After a couple weeks of behavioral sciences at my school I can easily conclude my parents need to grow up.

Link to comment
Share on other sites

Link to post
Share on other sites

The same way you pay for the 5 start hotel trips you win over the phone, just do a simple identity check using you credit card information.

Why don't they get caught easily?

24 fps for that "cinematic" feel


After a couple weeks of behavioral sciences at my school I can easily conclude my parents need to grow up.

Link to comment
Share on other sites

Link to post
Share on other sites

The one who knocks. LMAO.  :lol:

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

How exactly does one get around one of those? Seriously. I'm taking networking security classes, and after 7 semesters all we have covered is basically setup and prevention (plus english, math, and useless business and humanities classes). Nothing of any actual substance on how to get around or remove a malware.

 

 

Add a cryptography course to that work load if you want to understand various ransomware and the encryption methods used. There is no getting around or removing it; the only solutions are to cut your loss and wipe everything, pay up, or hope the creator of that particular one was sloppy with his keys and they will eventually be leaked.

https://www.coursera.org/course/crypto

You keep using that word. I do not think it means what you think it means.
Users cannot, and will not securely manage key material. Most users can't and the ones that can, wont.

Ask me about Bitcoin, Litecoin, Crypto-Currencies, and/or Mining them.

Link to comment
Share on other sites

Link to post
Share on other sites

How exactly does one get around one of those? Seriously. I'm taking networking security classes, and after 7 semesters all we have covered is basically setup and prevention (plus english, math, and useless business and humanities classes). Nothing of any actual substance on how to get around or remove a malware.

1. Make fire

2. Put HDD in fire

3. Sing 'kumbayah' around the fire and roast marshmellows

4. Buy new HDD

Link to comment
Share on other sites

Link to post
Share on other sites

1. Make fire

2. Put HDD in fire

3. Sing 'kumbayah' around the fire and roast marshmellows

4. Buy new HDD

Hahahahahahaha you just made my day.

Security Analyst & Tech Enthusiast

Ask me anything.

Link to comment
Share on other sites

Link to post
Share on other sites

How exactly does one get around one of those? Seriously. I'm taking networking security classes, and after 7 semesters all we have covered is basically setup and prevention (plus english, math, and useless business and humanities classes). Nothing of any actual substance on how to get around or remove a malware.

you can't...if your files are encrypted..they are basically gone

unless the governement intervens and take control over the hackers software...then they can learn how it works and make a program to remove the passwords on the encrypted files

If you need remote help fixing something on your computer

I can help over Teamviewer if you wish

just msg me on my profile

Link to comment
Share on other sites

Link to post
Share on other sites

I recent got a client who got a randsomware virus..basically encryprted the whole hard drive ....and basically had to wipe the drive...and they lost a few things

thankfully they had a backup of 90% of there important stuff

If you need remote help fixing something on your computer

I can help over Teamviewer if you wish

just msg me on my profile

Link to comment
Share on other sites

Link to post
Share on other sites

Damn, I am hearing about this all over the place now. :(

 

How can people protect themselves against this? Like any other virus, like the obviously "don't click strange links, ads or downloads", right?

|  The United Empire of Earth Wants You | The Stormborn (ongoing build; 90% done)  |  Skyrim Mods Recommendations  LTT Blue Forum Theme! | Learning Russian! Blog |
|"They got a war on drugs so the police can bother me.”Tupac Shakur  | "Half of writing history is hiding the truth"Captain Malcolm Reynolds | "Museums are racist."Michelle Obama | "Slap a word like "racist" or "nazi" on it and you'll have an army at your back."MSM Logic | "A new command I give you: love one another. As I have loved you, so you must love one another"Jesus Christ | "I love the Union and the Constitution, but I would rather leave the Union with the Constitution than remain in the Union without it."Jefferson Davis |

Link to comment
Share on other sites

Link to post
Share on other sites

Damn, I am hearing about this all over the place now. :(

 

How can people protect themselves against this? Like any other virus, like the obviously "don't click strange links, ads or downloads", right?

you could sandbox your browser...and any files you open from the net....

or use a vm windows on top of your real OS

If you need remote help fixing something on your computer

I can help over Teamviewer if you wish

just msg me on my profile

Link to comment
Share on other sites

Link to post
Share on other sites

you could sandbox your browser...and any files you open from the net....

or use a vm windows on top of your real OS

 

Sandbox? What do you mean?

 

A simple VM install could really prevent this from happening? Wow. :o

|  The United Empire of Earth Wants You | The Stormborn (ongoing build; 90% done)  |  Skyrim Mods Recommendations  LTT Blue Forum Theme! | Learning Russian! Blog |
|"They got a war on drugs so the police can bother me.”Tupac Shakur  | "Half of writing history is hiding the truth"Captain Malcolm Reynolds | "Museums are racist."Michelle Obama | "Slap a word like "racist" or "nazi" on it and you'll have an army at your back."MSM Logic | "A new command I give you: love one another. As I have loved you, so you must love one another"Jesus Christ | "I love the Union and the Constitution, but I would rather leave the Union with the Constitution than remain in the Union without it."Jefferson Davis |

Link to comment
Share on other sites

Link to post
Share on other sites

you could sandbox your browser...and any files you open from the net....

or use a vm windows on top of your real OS

It's less likely this type of infection will coexist among the web. This type of infection usually comes in the form of x86 and is binded to other software that you might presume to be "legit". Browsers like Chrome run entirely in userspace so such malware would never be effective running from a browser. You need to fool the user into giving the software administrator rights otherwise you'll never successfully hijack the system.

Link to comment
Share on other sites

Link to post
Share on other sites

Sandbox? What do you mean?

 

A simple VM install could really prevent this from happening? Wow. :o

I use this program to sandbox my browsers and files I open from the net

 

http://www.sandboxie.com/

If you need remote help fixing something on your computer

I can help over Teamviewer if you wish

just msg me on my profile

Link to comment
Share on other sites

Link to post
Share on other sites

How exactly does one get around one of those? Seriously. I'm taking networking security classes, and after 7 semesters all we have covered is basically setup and prevention (plus english, math, and useless business and humanities classes). Nothing of any actual substance on how to get around or remove a malware.

 

If they implemented it properly, there really is no way without brute forcing the encrypted drive and with modern encryption, that's not very feasible. Just back up important files and be prepared to reformat.

 

 

Damn, I am hearing about this all over the place now. :(

 

How can people protect themselves against this? Like any other virus, like the obviously "don't click strange links, ads or downloads", right?

 

Be careful with what you download for the most part. But the best way is really to back up everything important to an external drive or cloud storage. Then reformat your drive and reinstall anything important if this ever happens to you.

Turnip OC'd to 3Hz on air

Link to comment
Share on other sites

Link to post
Share on other sites

How exactly does one get around one of those? Seriously. I'm taking networking security classes, and after 7 semesters all we have covered is basically setup and prevention (plus english, math, and useless business and humanities classes). Nothing of any actual substance on how to get around or remove a malware.

You don't, you can't break the encryption algorithms typically used with these types of infections. Per example a 2048-bit RSA key (both a public and private) is something that's actually impossible to break with modern technology. So it's one of them things you need to protect yourself from because once you get hit with it there is no going back. You might be able to kill off the infection itself and remove it to prevent any future harm although all of your data will sit there and remain encrypted (unusable). This is why they try hitting you for like $500 to get your data back because without that private key you're up shit creek without a paddle.

Link to comment
Share on other sites

Link to post
Share on other sites

I use this program to sandbox my browsers and files I open from the net

 

http://www.sandboxie.com/

 

Oh now that sounds like a neat program! 35$ is a great price, too. Thank you!

 

Be careful with what you download for the most part. But the best way is really to back up everything important to an external drive or cloud storage. Then reformat your drive and reinstall anything important if this ever happens to you.

 

Thanks. I guess I need another drive to do this with for extra precaution. I would hate to lose all that I have with no option of even paying for the content back. haha

 

 

|  The United Empire of Earth Wants You | The Stormborn (ongoing build; 90% done)  |  Skyrim Mods Recommendations  LTT Blue Forum Theme! | Learning Russian! Blog |
|"They got a war on drugs so the police can bother me.”Tupac Shakur  | "Half of writing history is hiding the truth"Captain Malcolm Reynolds | "Museums are racist."Michelle Obama | "Slap a word like "racist" or "nazi" on it and you'll have an army at your back."MSM Logic | "A new command I give you: love one another. As I have loved you, so you must love one another"Jesus Christ | "I love the Union and the Constitution, but I would rather leave the Union with the Constitution than remain in the Union without it."Jefferson Davis |

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×