TG Soft's Research Centre (C.R.A.M.) has identified a new ransomware in the night of 26th june called CryptoBubble. This ransomware maybe is made in Italy.
|
CONTENTS==> How CryptoBubble spreads==> How to protect yourself from CryptoBubble ==> What to do to mitigate the damage from CryptoBubble ==> Can I restore the encrypted files ==> Conclusions |
png, jpeg, jpg, 3gp, bmp, tiff, mp4, mov, mpeg, avi |
zip, doc, docx, docm, pdf, xls, xlsm, xlsx, mdb, accdb, accdt, dwg, cdr, rar, odt, ods, odg, odp, odb, odf, otg, otp, ott, csv, txt, png, jpeg, jpg, 3gp, bmp, tiff, mp4, mov, mpeg, avi |
mp3, ac3, DivX, mpg, mpeg, mp4, mov, ogv, ogg, avi |
mp3, ac3, mid, wav, mp4, mov, mpeg |
mp3, docx, zip, doc, docx, docm, pdf, xls, xlsm, xlsx, mdb, accdb, accdt, dwg, cdr, rar, odt, ods, odg, odp, odb, odf, otg, otp, ott, csv, txt, png, jpeg, jpg, 3gp, bmp, tiff, mp4, mov, mpeg, avi |
bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... bubble bobble... |
Hello, I am Bob, do you remember the game? Unfortunately, the world has changed and I have changed too: once spit bubbles, today i encode your file! :) Well, if you want to recover your files, please contact us at 'br5wf@notsharingmy.info' and we will find a solution and will promptly send you the unlock key to retrieve all your files... Good Lucky |
When the Alert screen on the side appears means that the Vir.IT eXplorer Pro's Anti-CryptoMalware integrated protection is acting and so, avoiding getting caught by the "panic" NOT close the window and perform the steps that are indicated:
|
![]() Clicca per ingrandire l'immagine 99,63% Average percentage Expectation of protected files from encryption thanks to Vir.IT eXplore PRO's Anti-CryptoMalware protection ==> Check the information |
With the Anti-Crypto Malware protection integrated in VirIT, the number of encrypted files by Anubis will be at most a few dozen.
The "sacrificed" files during the mitigation must be replaced with a backup copy, currently there aren't tools for recovering files .bubble.
In the analyzed cases by the TG Soft's C.R.A.M., it was possible to recover files by using the shadow copies of the days preceding the attack.
If you opened an infected attachment and has been started the encryption, you could:
you have Vir.IT eXplorer Pro installed, correctly set up, up-to-date and running on your pc - in this case, you must follow the instructions on the Alert message and you will manage to save AT LEAST 99.63% of your data;
you have a AntiVirus software that DOESN'T DETECT, signal and halt the ongoing encryption - in this case you still could do
UNPLUG EVERY NETWORK CABLE
LEAVE YOUR COMPUTER TURNED OFF - every time the computer is rebooted and the malware is still active, a new encryption key will be used and the amount of money demanded as ransom will increase (note that paying the ransom does not guarantee the decryption and is therefore highlynot recommended)
Either way, remain calm and do not panic.