Transmission Installer Update Fixes Ransomware Flaw

You know what’s missing from your workday? Losing access to a number of your key files after accidentally downloading some ransomware. Nothing makes the day go smoother than receiving a message, telling you to pay the Bitcoin ransom if you want to get your files back.

Unfortunately, that was the reality for some users who’d downloaded Transmission BitTorrent Installer. This software for MacOS X (Linux version available, bundled with Ubuntu) doesn’t take up a lot of space so it runs in the background to install torrents quickly. It can even be operated remotely via the web. Sadly, versions of the software that were downloaded anytime on March 4th and 5th may have also been infected with KeRanger ransomware.

ransomware

First discovered by Palo Alto Networks, this ransomware was found on two versions of Transmission 2.90. Since Transmission is a fully open-source project, the researchers have speculated that the download website itself was compromised.

According to their post on KeRanger by Claud Xiao and Jin Chen, the ransomware encrypts individual files to lock you out of them, a process that they’ll undo for a fee. The encryption process itself is pretty slick:

“To encrypt each file, KeRanger starts by generating a random number (RN) and encrypts the RN with the RSA key retrieved from the C2 server using the RSA algorithm. It then stores the encrypted RN at the beginning of resulting file. Next, it will generate an Initialization Vector (IV) using the original file’s contents and store the IV inside the resulting file. After that, it will mix the RN and the IV to generate an AES encryption key. Finally, it will use this AES key to the contents of the original file and write all encrypted data to the result file.”

But be warned: further investigation into the mechanism behind KeRanger uncovered an alarming feature, namely that it looked like there were processes involved that hadn’t been completed. Undetected, it’s possible these features could have been activated at a later date.

“It seems like KeRanger is still under development. There are some apparent functions named ‘_create_tcp_socket’, ‘_execute_cmd’ and ‘_encrypt_timemachine’. Some of them have been finished but are not used in current samples. Our analysis suggests the attacker may be trying to develop backdoor functionality and encrypt Time Machine backup files as well. If these backup files are encrypted, victims would not be able to recover their damaged files using Time Machine.”

Fortunately, Transmission’s developers have released a new version that fixes this vulnerability. For those who may already have been infected, Palo Alto Networks has complete clean up instructions here.

The post Transmission Installer Update Fixes Ransomware Flaw appeared first on FileHippo News.



via FileHippo News http://ift.tt/1Ysd5Pt

ComboFix 16.3.7.1

http://ift.tt/20oUAAn Combofix is designed to scan a computer for known malware, spyware and automatically remove any types of malware that it locates. The app will also allow you to manually remove spyware infections as well. Combo fix is a specialized effective cleaning tool that is a useful companion to other malware and spyware removers. After Combofix has finished ...


via FileHippo.com http://ift.tt/20oUybw [[ We are also giving web service. Email:wasim.akh2@gmail.com]]

Apowersoft Video Converter Studio 4.4.6

http://ift.tt/1FAuJVl Apowersoft Video Converter Studio is a powerful video editing suite that can convert numerous types of video formats, such as AVI, MP4, FLV, and MKV. The application is also capable of converting audio formats, such as MP3, MP2, OGG, and AAC. Key features include: Numerous video and audio formats supported. Built in media player. Import and...


via FileHippo.com http://ift.tt/1dfshwK [[ We are also giving web service. Email:wasim.akh2@gmail.com]]

ConvertXtoDVD 6.0.0.29

http://ift.tt/1YDrvLm ConvertXtoDVD is an easy and simple way to convert and burn your movie files to a compatible DVD playable on your home DVD player. It supports most popular formats (including: DivX, Xvid, MOV, VOB, Mpeg, Mpeg4, AVI, WMV, DV). ConvertXtoDVD has a great looking interface that is very easy to navigate and extremely intuitive. As soon as you open ...


via FileHippo.com http://ift.tt/1Opv5cq [[ We are also giving web service. Email:wasim.akh2@gmail.com]]

Tresorit 2.1.700.431

http://ift.tt/1VIPah3 Tresorit is an easy-to-use, secure file synchronizing application that is designed to store, sync and share confidential from the cloud. Simply add any folder to a Tresor (or vault) then place a file into it and Tresorit will automatically sync with every computer and device that is connected to the same account. As encryption is ...


via FileHippo.com http://ift.tt/1VIPblj [[ We are also giving web service. Email:wasim.akh2@gmail.com]]

Comodo Dragon Internet Browser 48.12.18.243

http://ift.tt/O8znTg Comodo Dragon is a Chromium technology-based Browser that offers you all of Chrome's features PLUS the unparalleled level of security and privacy you only get from Comodo. Including a greater level of privacy than Chromium technology offers. Features: Improved Privacy over Chromium Easy SSL Certificate Identification Fast Website Access Grea...


via FileHippo.com http://ift.tt/111O18B [[ We are also giving web service. Email:wasim.akh2@gmail.com]]

Windows 11 Insider Preview Build 29560.1000 Released to New Canary Channel

UPDATE: Windows 11 Insider Preview build 29560.1000 released to the new Canary channel. Windows Insiders on the refreshed Canary Channel wil...