DCry crypto-malware developers persistently create new versions

DCry virus functions as crypto-malware which tries to evoke more terror by disguising under the notorious WannaCry[1] ransomware. Fortunately, the virus does not exhibit such capabilities as the former threat. Indeed, there have been such threats as, for example, FakeCry, which inflicts great damage. However, the release of the decrypter has not discouraged racketeers to engage in such illegal activity – DCry 2.0 version has made its appearance.
Speaking of the current virus, it does not launch its own graphic interface. In its HOW_TO_DECRYPT.txt file, scarce information is delivered:
Files has been encrypted.
If you want to decrypt, please, write me to e-mail: bbqb@protonmail.com
The message delivered through MsgBox repeats the same information. Besides these qualities, the original malware version appends .dcry file extension to the encrypted files, but there are new virus versions which also use .qwqd extensions.
Interestingly, the malware links to Germany[2]. According to its technical specifications, it is detectable as Trojan-Ransom.Win32.Purgen, Ransom_FAKEWCRY.I, or Trojan.GenericKD.5584545. The former entry resembles the variations of GlobeImposter family of ransomware.
Luckily, multiple cyber security applications are able to detect this malicious presence. Thus, you will be able to remove DCry virus as well. FortectIntego or MalwarebytesMalwarebytes will speed up the process.
Update September 15th, 2017. The developers of this malware seem to be persistently working on new improvements. Besides recent .qwqda extension virus variation, now the perpetrators have released a new version – DCry 2.0 malware – which adds .dian file extension to mark encrypted files.
This version seems to be still under development as the malware authors left an amusing greeting[3] for a famous ransomware researcher Michael Gillespie embedded in the source code. Leaving aside entertaining remarks, the virus functions via Uds.Dangerousobject.Multi!c, TR/AD.RansomHeur.rfwab, Ransom_Purgen.R01BC0WIB17, etc. Considering the latter, the very modus operandi does not seem to have changed dramatically. Besides the mentioned changes, cyber criminals switched to lnq@protonmail.com email address as well.
Update September 11th, 2017. In response to the released decrypter, the cyber developers have created another version which attaches .gocr file extension. The ransom note slightly changed its veneer as well. Now the felons present their demands in HOW_TO_GET_MY_FILES.txt file. The content of the message was slightly altered as well. Here is a short extract from it:
Hello my friend, first sorry for this.
Your files have been crypted with AES-256 method.
Don't try decrypt files use third-party software, otherwise you may loss all files permanently.
If you want to decrypt your data, write to e-mail: lnq@protonmail.com.
If you want to test the decrypt, go to https://s7c4wrcmzgbtldbs.onion (use tor browser)
Update July 14th, 2017. Security experts Michael Gillespie and Francesco Mauroni managed to create a free decryption tool for victims of DCry crypto-virus. Therefore, do not hesitate and remove the ransomware ASAP. You have a chance to restore your files for free, so do not even consider paying the ransom to cybercriminals. You can find DCry Decrypter here.
NOTE: DCry Decrypter has been updated to restore files encrypted by the latest ransomware version which appends .qwqd extensions and uses qwqd@protonmail.com email address for communication.
WannaCry – as the inspiration for cyber villains
Though since the first wave of the former threat, almost two months have passed, other crooks still use it as the material to evoke more fear to victims. Fortunately, such clones often happen to be poorly programmed and much less destructive.
DCry ransomware happens to be one of such samples as well. On the other hand, its developer cunningly makes a diversion. The virus contains references to FakeCry, WammaCry, and even Globe as some anti-virus detect as Purgen virus, reference to Globe.
Furthermore, the virus functions via Cryptor.exe and message.vbs files. The malware connects to hidden onion websites www.indyproject.org/. The latter websites serve as the opens source website created by an unknown group of netizens.
It is designed for exchanging ideas how to transfer an entire system to another computer. Regarding the fact that DCry may target systems via remote desktop protocols (RDP), the websites turn out to be more than shady.
The malware also connects to one IP address which links to Germany. However, taking into account that the perpetrator uses Tor, it might be only a diversion.
Key aspects of transmission strategy
Besides RDP, the threat may lurk for Windows OS users in certain corrupted websites. Thus, when they click on a certain link or download an infected website, they might encounter DCry hijack.
The latter method is getting much more dangerous as cyber criminals have found a way how to foist an infection in a file. In order to activate victims do not need to click on file anymore – hovering over it[4] is enough to face the aftermath of crypto-malware.
Thirdly, note that ransomware distribution via spam emails is still viable. Vigilance and cautiousness are not sufficient in countering ransomware. You will need cyber security applications to ward off and counterattack the malware. Now let us move on to the section which presents DCry removal options.
Eradicate DCry virus
Even though the malware may not be as destructive as its referrer, you should not delay DCry removal. In some cases, rebooting the computer interrupts data encryption process.
Before you decrypt files, you might check some of our suggested programs at the bottom of the page. Hungarian users should be careful as the virus might target the residents of this country more.[2]
Was this guide helpful?
Be the first to comment