Showing posts with label Cerber. Show all posts
Showing posts with label Cerber. Show all posts
Friday, 28 July 2017
New variant of Cerber ransomware (Ferber) analyzed
This summer Cerber is on duty. It comes via spear-phishing emails, bypasses antiviruses leveraging polymorphic encryption and API calls obfuscation. The cryptolocker can be easily customized for every target by embedding the JSON-formatted configuration data encrypted with RC4-128 (the decrypted config is on Github for cfd2d6f189b04d42618007fc9c540352). The file encryption scheme 'master RSA-2048 key'-> 'session RSA-880' -> 'file's RC4-128' used by Cerber is not breakable. Cerber scans the IP ranges specified by CIDRs in the config for the C&C server.
Monday, 3 April 2017
Subscribe to:
Posts (Atom)