{"id":3702,"date":"2017-11-27T14:26:54","date_gmt":"2017-11-27T06:26:54","guid":{"rendered":"https:\/\/www.microdium.net\/public\/?p=3702"},"modified":"2017-11-27T14:26:54","modified_gmt":"2017-11-27T06:26:54","slug":"ordinypt-ransomware-destroys-data-instead-encrypting","status":"publish","type":"post","link":"https:\/\/www.microdium.com\/public\/2017\/11\/27\/ordinypt-ransomware-destroys-data-instead-encrypting\/","title":{"rendered":"Ordinypt &#8216;Ransomware&#8217; Destroys Data Instead of Encrypting It"},"content":{"rendered":"<p><strong>A new malware called Ordinypt that targets German users is making the rounds\u2014billing itself as ransomware. However, the code is really a wiper, with apparent twin motives of financial gain as well as disrupting business operations. <\/strong><\/p>\n<p>G Data security researcher <a href=\"https:\/\/twitter.com\/struppigel\/status\/928238020867887105\">Karsten Hahn<\/a> found that the malware, which also goes by the name HSDFSDCrypt, is<a href=\"https:\/\/blog.knowbe4.com\/ordinypt-ransomware-intentionally-destroys-files-currently-targeting-germany\"> targeting<\/a> German users for the moment, using emails and ransom notes that are written in flawless Deutsch. It\u2019s being spread via responses to job ads\u2014the emails purport to have a ZIP file with a resume and CV attached.<\/p>\n<p>According to an <a href=\"http:\/\/29wspy.ru\/reversing\/Ordinypt\/Ordinypt.pdf\">analysis<\/a> from Valthek, once opened, the malware infects a victim\u2019s machine, making files inaccessible, and then requests 0.12 Bitcoin (around 600 EUR) for recovering them. Unbeknownst to the target, the files are actually destroyed, not encrypted, and the attackers have no code for \u201cunlocking\u201d them, even if victims pay up.<\/p>\n<p>Interestingly, Valthek found that the malware deletes files, overwriting them with garbage strings of random letters and numbers. However, the affected files will remain in the raw hard disk untouched\u2014leaving open the possibility (\u201cwith luck\u201d, he said) to recovering them using a program such as <a href=\"https:\/\/www.piriform.com\/recuva\">Recuva<\/a>. It also doesn\u2019t destroy Shadow Volume or Restore Point files in the system, he said, so the use of a tool like <a href=\"https:\/\/www.bleepingcomputer.com\/download\/shadowexplorer\/\">Shadow Explorer<\/a> could be useful in <a href=\"https:\/\/www.bleepingcomputer.com\/tutorials\/how-to-recover-files-and-foldersusing-shadow-volume-copies\/\">getting data back<\/a>.<\/p>\n<p>In both cases though, Valthek said it\u2019s unlikely that victims will be able to recover their files in totality.<\/p>\n<p>What\u2019s also notable about the code is that while it\u2019s effective, it\u2019s poorly written. Valthek\u2019s overall assessment of it is straightforward: \u201cA stupid malware that destroy information of enterprises and innocent people and try steal money saying that is a ransomware. Bad coding style, a easy packer, only need one hour of my time to reverse it and writing this report.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new malware called Ordinypt that targets German users is making the rounds\u2014billing itself as ransomware. However, the code is really a wiper, with apparent twin motives of financial gain as well as disrupting business operations. G Data security researcher Karsten Hahn found that the malware, which also goes by the name HSDFSDCrypt, is targeting [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-3702","post","type-post","status-publish","format-standard","hentry","category-disaster-recovery-cybersecurity-news-malaysia"],"_links":{"self":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/posts\/3702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/comments?post=3702"}],"version-history":[{"count":0,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/posts\/3702\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/media?parent=3702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/categories?post=3702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/tags?post=3702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}