Previous All Posts Next

vxCrypter: Ransomware and Duplicate File Cleanup

Posted: April 11, 2019 to Cybersecurity.

Tags: Ransomware, Malware, Data Breach

vxCrypter Ransomware not only encrypts your computer, it also deletes duplicate files.  According to Lawrence Abrams, creator and owner of BleepingComputer, the vxCrypter Ransomware could be “the first ransomware infection that not only encrypts a victim's data, but also tidy's up their computer by deleting duplicate files.” vxCrypter is based on an older ransomware called vxLock that never saw fruition. At first, Abrams believed the duplicate file deletions to be a bug in the encryption code.  Collaboration with Michael Gillespie, a ransomware researcher at BleepingComputer, the file deletions were deliberate and targets a multitude of file extensions including: .txt .doc .docx .xls .xlsx .ppt .pptx .sqlite .odt .jpg .jpeg .bmp .gif .png .csv .sql .mdb .sln .php .asp .aspx .html .xml .psd .xsd .cpp .c .h .hpp .htm .py .reg .rb .pl .zip .rar .tgz .key .jsp .db .sqlite3 .sqlitedb .bat .bak .7z .avi .fla .flv .java .mpeg .pem .wmv .tar .tgz .tif .tif It leaves duplicates for other files such as .exe or .dll. Though the exact reason behind the deletion process is unknown, it may increase the efficacy and tempo of the virus encryption process.
Craig Petronella
Craig Petronella
CEO & Founder, Petronella Technology Group | CMMC Registered Practitioner

Craig Petronella is a cybersecurity expert with over 24 years of experience protecting businesses from cyber threats. As founder of Petronella Technology Group, he has helped over 2,500 organizations strengthen their security posture, achieve compliance, and respond to incidents.

Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next