• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Preventive Measure Against GandCrab Ransomware Found!

July 26, 2018Simeon Georgiev

A cybersecurity company located in South Korea AhnLab has found a solution to tackle GandCrab’s Ransomware. The company has released a vaccine application. Ransomware removal experts believe that AhnLab’s application has paved the way for other cybersecurity companies to counter the latest ransomware threats.

According to ransomware removal experts, GandCrab is a notorious ransomware that is known to not only lock the files of its victims via encryption algorithms but also taking command of the root folder in the system.

How Does the Application Work?

AhnLab’s application provides the ability to duplicate a file with the extension of ‘.lock’ that is created by the GandCrab Ransomware.

The name of the unique file is [[hexadecimal-string].lock] and it is saved in the Program Data folder in the C Drive of Windows Operating Systems. The hexadecimal string is created with respect to a computer’s details related to the volume of its root drive with the presence of a cryptographic algorithm known as Salsa20.

GandCrab places this file in order to observe if a victim’s system has been affected with the ransomware before so they can be prevented in running the .exe file multiple times, saving the ransomware from working repeatedly.

Ransomware removal experts explain that AhnLab app’s duplication of the file means that the ransomware is deceived into believing a computer to be already infected as well as duped into thinking that users’ files have already been encrypted. Thus, it saves users from the infamous ransomware’s machinations.

Only Works against the Latest Versions

However, there is a hint of negative news too. Unluckily, the app can only fool the GandCrab Ransomware’s version of 4.1.2 which has been noticed in the security circles since mid-July. The file with ‘.lock’ extension has been a part of GandCrab since that beginning of July.

According to ransomware removal experts, it is still possible to modify the source code of the application so it can deal with the older versions of GandCrab. Since the previous versions of GandCrab were similar in their modus operandi, hence it will be easier to tackle them.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post GandCrab Ransomware Evolves Next post FBI’s Stance on Ransomware Threat

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.