{"id":25452,"date":"2022-06-29T00:01:00","date_gmt":"2022-06-28T22:01:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=25452"},"modified":"2022-06-29T04:33:02","modified_gmt":"2022-06-29T02:33:02","slug":"decryptor-fr-hive-ransomware-v1-bis-v4-verfgbar","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/06\/29\/decryptor-fr-hive-ransomware-v1-bis-v4-verfgbar\/","title":{"rendered":"Decryptor for Hive ransomware v1 till v4 released"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/06\/29\/decryptor-fr-hive-ransomware-v1-bis-v4-verfgbar\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Victims of Hive ransomware may hope to decrypt their encrypted files. This is because Korean security researchers have succeeded in developing a decryptor for versions 1 to 4 of this Hive ransomware. This was possible because there was a vulnerability in the encryption that could be exploited.<\/p>\n<p><!--more--><\/p>\n<p>I have already reported on the Hive Ransomware group several times here on the blog. In Germany, the attack on Media Markt\/Saturn was carried out by this group (<a href=\"https:\/\/borncity.com\/win\/2021\/11\/09\/media-markt-saturn-ransomware-angriff-durch-hive-gang-240-mio-us-lsegeldforderung\/\">Media Markt\/Saturn: Ransomware attack by hive gang, $240 million US ransom demand<\/a>). First discovered in June 2021, Hive is a ransomware-as-a-service used by cybercriminals to attack healthcare facilities, nonprofits, retailers, utilities and other industries worldwide. I traced the anatomy of such an attack in the post <a href=\"https:\/\/borncity.com\/win\/2022\/06\/17\/anatomie-eines-hive-ransomware-angriffs-auf-exchange-per-proxyshell\/\">Anatomy of a Hive Ransomware Attack on Exchange via ProxyShell<\/a>. <\/p>\n<p><a href=\"https:\/\/twitter.com\/campuscodi\/status\/1541720573448962048\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Hive Ransomware Decoder\" alt=\"Hive Ransomware Decoder\" src=\"https:\/\/i.imgur.com\/zq5xXUQ.png\"><\/a><\/p>\n<p>According to the above <a href=\"https:\/\/twitter.com\/campuscodi\/status\/1541720573448962048\" target=\"_blank\" rel=\"noopener\">tweet<\/a>, however, there is now a decoder for the first four versions of the ransomware that can be downloaded from this Korean website (if necessary, use a translator to find the download link for <em>Hive_Ransomware_Integrated_Decryption_Tool.zip<\/em>). <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Victims of Hive ransomware may hope to decrypt their encrypted files. This is because Korean security researchers have succeeded in developing a decryptor for versions 1 to 4 of this Hive ransomware. This was possible because there was a vulnerability &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/06\/29\/decryptor-fr-hive-ransomware-v1-bis-v4-verfgbar\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-25452","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/25452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=25452"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/25452\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=25452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=25452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=25452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}