{"id":25520,"date":"2022-07-05T14:15:23","date_gmt":"2022-07-05T12:15:23","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=25520"},"modified":"2022-11-04T11:40:46","modified_gmt":"2022-11-04T10:40:46","slug":"astralocker-will-aktivitten-beenden-und-gibt-decryptor-frei","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/07\/05\/astralocker-will-aktivitten-beenden-und-gibt-decryptor-frei\/","title":{"rendered":"AstraLocker terminates activities and releases Decryptor"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/07\/05\/astralocker-will-aktivitten-beenden-und-gibt-decryptor-frei\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Strange things are happening at the moment. The threat actor behind the lesser-known AstraLocker ransomware seems to want to stop its activities. The actor plans to switch to cryptojacking and has published an archive of AstraLocker decryption programs. I'll try to summarize the facts I know, although much is unclear, even though the actor has probably also contacted my English-language blog.<\/p>\n<p><!--more--><\/p>\n<h2>About AstraLocker<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg04.met.vgwort.de\/na\/0bc754ec4b4c438bb6bfe37cf7af64b2\" width=\"1\" height=\"1\">The threat actors under the name AstraLocker were actually unknown to me until now. Only yesterday I reported about such an actor in the blog post <a href=\"https:\/\/borncity.com\/win\/2022\/07\/04\/astralocker-2-0-infektion-per-word-anhang\/\">AstraLocker 2.0: Infection via Word attachment<\/a>. Its malware had been discovered by security researchers from ReversingLabs. They came across this relatively unknown malware in phishing emails. In version 2.0, the attackers switched to reloading the malicious payload directly from a Word document included as an attachment to a mail. This was quite unusual because ransomware groups used to try to avoid detection for as long as possible.<\/p>\n<h2>Strange reference to Decryptor archive<\/h2>\n<p>An <a href=\"https:\/\/borncity.com\/win\/2022\/07\/04\/astralocker-2-0-infektion-per-word-anhang\/#comment-15117\">unusual comment<\/a> hit my blog post <a href=\"https:\/\/borncity.com\/win\/2022\/07\/04\/astralocker-2-0-infektion-per-word-anhang\/\" target=\"_blank\" rel=\"noopener\">AstraLocker 2.0: Infection via Word attachment<\/a> yesterday. A visitor to the blog named AstraLocker shared a link to a Decryptor archive uploaded to Virustotal.&nbsp; <\/p>\n<blockquote>\n<p>Link on virustotal.<\/p>\n<p>comIts all from me<\/p>\n<\/blockquote>\n<p>I didn't quite understand the whole thing, especially since he wrote that Bleeping Computer should fix its registry via Tor. Colleague Lawrence Abrams, who runs Bleeping Computer, was also absent on yesterday's US Independence Day, so he couldn't answer my private inquiry on Twitter. The <a href=\"https:\/\/www.virustotal.com\/gui\/file\/b82912864b2336fb19a48a3b141913c456335d1b4abf3cda481a16609be4e97e\" target=\"_blank\" rel=\"noopener\">link on VirusTotal<\/a> shows that an archive file <a title=\"https:\/\/www.virustotal.com\/gui\/file\/b82912864b2336fb19a48a3b141913c456335d1b4abf3cda481a16609be4e97e#:~:text=AstraLocker%202.0%20Decryptors.zip\" href=\"https:\/\/www.virustotal.com\/gui\/file\/b82912864b2336fb19a48a3b141913c456335d1b4abf3cda481a16609be4e97e#:~:text=AstraLocker%202.0%20Decryptors.zip\">AstraLocker Decryptors.zip<\/a> was uploaded.  <\/p>\n<p><img decoding=\"async\" title=\"AstraLocker Decrytors on VirusTotal \" alt=\"AstraLocker Decrytors on VirusTotal \" src=\"https:\/\/i.imgur.com\/qWc65mJ.png\"><br \/>AstraLocker Decrytors on VirusTotal  <\/p>\n<p>However, this archive is marked as malicious by 42 virus scanners. I was also unsure because the previous blog post <a href=\"https:\/\/borncity.com\/win\/2022\/07\/04\/astralocker-2-0-infektion-per-word-anhang\/\" target=\"_blank\" rel=\"noopener\">AstraLocker 2.0: Infection via Word attachment<\/a> said that people probably had limited skills for running a ransomware platform. So just off the top of my head, I rhymed that the comment could also be an attempt at \"dumbing down\". Just put the ransomware in a ZIP archive and upload it somewhere, hoping that people will fall for it. The ZIP archive in question can be downloaded in a certain version from <a href=\"http:\/\/bazaar.abuse.ch\/sample\/b82912864b2336fb19a48a3b141913c456335d1b4abf3cda481a16609be4e97e\/\" target=\"_blank\" rel=\"noopener\">this Swiss website<\/a>. It was uploaded by the colleagues from Bleeping Computer. .  <\/p>\n<h2>Bleeping Computer: AstraLocker shots down<\/h2>\n<p>Now, the threat actor behind AstraLocker has probably contacted Bleeping Computer and told them that it is ceasing its operations in the ransomware sector. They want to focus on cryptojacking, i.e. the theft of crypto assets from corresponding accounts. The colleagues quote the ransomware developer within their article <a href=\"https:\/\/web.archive.org\/web\/20220827002745\/https:\/\/www.bleepingcomputer.com\/news\/security\/astralocker-ransomware-shuts-down-and-releases-decryptors\/\" target=\"_blank\" rel=\"noopener\">AstraLocker ransomware shuts down and releases decryptors<\/a> as:<\/p>\n<blockquote>\n<p>It was fun, and fun things always end sometime. I'm closing the operation, decryptors are in zip files, clean. I will come back. I'm done with ransomware for now. I'm going in cryptojaking lol.<\/p>\n<\/blockquote>\n<p>The actor's says, that the files with the decryptors are clean, even though they are marked as malicious on VirusTotal. BleepingComputer has downloaded the archive and confirmed that the decryptors are legitimate and work. They have tested a decryptor on files encrypted in a recent AstraLocker campaign. However, there are probably a number of decryptors, some of which may have been intended for previous campaigns. The colleagues have published some more details in the article and guess that the sudden attention from media might have been too hot for the actor.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Strange things are happening at the moment. The threat actor behind the lesser-known AstraLocker ransomware seems to want to stop its activities. The actor plans to switch to cryptojacking and has published an archive of AstraLocker decryption programs. I'll try &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/07\/05\/astralocker-will-aktivitten-beenden-und-gibt-decryptor-frei\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-25520","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/25520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=25520"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/25520\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=25520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=25520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=25520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}