pbjnr Posted July 24, 2017 ID:1145538 Share Posted July 24, 2017 Are there any decryption tools available for DMA Locker 3.0 ? Link to post Share on other sites More sharing options...
Aura Posted July 24, 2017 ID:1145547 Share Posted July 24, 2017 Hi pbjnr According to the latest update on Malwarebytes' DMA Locker article, v3.0 of the Ransomware fixed the bug in their encryption process, which means the decrypter they released no longer works for files encrypted with this version. https://blog.malwarebytes.com/threat-analysis/2016/02/dma-locker-strikes-back/ Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145548 Share Posted July 24, 2017 Check in http://www.thewindowsclub.com/list-ransomware-decryptor-tools it seems this ransomware has evolved to make decryption impossible as per http://www.2-spyware.com/remove-dma-locker-3-0-ransomware-virus.html also check in https://www.bleepingcomputer.com/forums/t/604873/dma-locker-ransomware-support-and-help-topic/ were Dave99uk says about a solution.. and some forum help.. Link to post Share on other sites More sharing options...
Aura Posted July 24, 2017 ID:1145560 Share Posted July 24, 2017 I wouldn't list anything coming from an ESG affiliate website (2-spyware.com), sman. Also, see this tweet: Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145567 Share Posted July 24, 2017 Is it Enigmasoftware (ESG)?.. Link to post Share on other sites More sharing options...
Aura Posted July 24, 2017 ID:1145577 Share Posted July 24, 2017 Yes, ESG stands for Enigma Software Group USA LLC. Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145584 Share Posted July 24, 2017 Ok.. but the site (2-spyware.com) has no reference to ESG.. and not reported for any malicious content too.. so pretty unkniwn and on outlook appears safe enough.. and how to get the DMALOCKS? https://sensorstechforum.com/decrypt-files-encrypted-dma-locker-3-0-ransomware/ also refers to those 3 DMALOCKS as in that tweet.., but how to check the DMALOCKS? Link to post Share on other sites More sharing options...
Aura Posted July 24, 2017 ID:1145599 Share Posted July 24, 2017 Looks like 2-spyware changed their affiliation from ESG to Reimage. Anyway, in both cases, this website isn't as reliable as you would think, so I would take everything coming from it with a grain of salt. SensorTechForum seems to be an ESG affiliate though. Anyway, we're going off-topic. Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145600 Share Posted July 24, 2017 Ok.. but what about DMALOCKS? How to know it? Link to post Share on other sites More sharing options...
Aura Posted July 24, 2017 ID:1145607 Share Posted July 24, 2017 It should be listed in the ransom note that DMA Locker drops. Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145611 Share Posted July 24, 2017 I doubt if it will it be so obvious / revealing by the hacker?.. Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145612 Share Posted July 24, 2017 and where would that be in the note? ie. where to look for? Link to post Share on other sites More sharing options...
Aura Posted July 24, 2017 ID:1145614 Share Posted July 24, 2017 Google is your friend https://www.bleepingcomputer.com/news/security/dma-locker-ransomware-targets-unmapped-network-shares/ Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145619 Share Posted July 24, 2017 so one has to check the file header, but if they are evolving, even this header logic also would have variation/evolved.. so no guarantee that the infection would be obvious (yes, ransom note, apart, to get to the victim).. Link to post Share on other sites More sharing options...
sman Posted July 24, 2017 ID:1145620 Share Posted July 24, 2017 and if files are encrypted/locked, probably the drive has to be checked externally only (as an external drive, probably).. Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now