{"id":7599,"date":"2017-05-11T10:11:00","date_gmt":"2017-05-11T18:11:00","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/05\/11\/news-1384\/"},"modified":"2017-05-11T10:11:00","modified_gmt":"2017-05-11T18:11:00","slug":"news-1384","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/05\/11\/news-1384\/","title":{"rendered":"New &#8216;Jaff&#8217; ransomware via Necurs asks for 2 BTC"},"content":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Thu, 11 May 2017 17:11:12 +0000<\/strong><\/p>\n<p>There is yet another ransomware on the block, but contrary to the many copycats out there this one appears to be more serious and widespread since it is part of the Necurs spam campaigns.<\/p>\n<p>Originally <a href=\"https:\/\/twitter.com\/siri_urz\/status\/862586080507424769\" target=\"_blank\" rel=\"noopener noreferrer\">identified<\/a> by security researcher\u00a0<a href=\"https:\/\/twitter.com\/siri_urz\" target=\"_blank\" rel=\"noopener noreferrer\">S!Ri<\/a>, the Jaff ransomware looks very identical to Locky in many ways: same distribution via the Necurs botnet, same PDF that opens up a Word document with a macro, and also similar payment page.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/email.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17886\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/email.png\" alt=\"\" width=\"663\" height=\"484\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/email.png 799w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/email-300x219.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/email-600x438.png 600w\" sizes=\"auto, (max-width: 663px) 100vw, 663px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/Jaff_decoy.png\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17884\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/Jaff_decoy.png\" alt=\"\" width=\"1283\" height=\"869\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/Jaff_decoy.png 1283w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/Jaff_decoy-300x203.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/Jaff_decoy-600x406.png 600w\" sizes=\"auto, (max-width: 1283px) 100vw, 1283px\" \/><\/a><\/p>\n<p>However, this is where the comparison ends, since the code base is\u00a0different\u00a0as well as the ransom itself. Jaff asks for an astounding 2 BTC, which is about $3,700 at the time of writing.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/encrypted.png\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17887\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/encrypted.png\" alt=\"\" width=\"1894\" height=\"1080\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/encrypted.png 1894w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/encrypted-300x171.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/encrypted-600x342.png 600w\" sizes=\"auto, (max-width: 1894px) 100vw, 1894px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\" target=\"_blank\" rel=\"noopener noreferrer\">Malwarebytes<\/a> users are already protected against this ransomware thanks to our multi-layer defense. In the diagram below we show how the threat can\u00a0be blocked via each of our\u00a0protection modules (in a typical\u00a0scenario, the threat would be stopped\u00a0at the first layer which is the Application Behavior Protection):<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/protection.png\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-17888 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/protection.png\" alt=\"\" width=\"544\" height=\"472\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/protection.png 1664w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/protection-300x260.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/protection-600x521.png 600w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/a><\/p>\n<p>In the meantime, <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/04\/locky-ransomware-is-back-but-we-already-protect-against-it\/\" target=\"_blank\" rel=\"noopener noreferrer\">the return of Locky<\/a> after a short hiatus has not been as big as anticipated. The appearance of the Jaff ransomware may also take away\u00a0some market shares from it.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/new-jaff-ransomware-via-necurs-asks-for-2-btc\/\">New &#8216;Jaff&#8217; ransomware via Necurs asks for 2 BTC<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/new-jaff-ransomware-via-necurs-asks-for-2-btc\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Thu, 11 May 2017 17:11:12 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/new-jaff-ransomware-via-necurs-asks-for-2-btc\/' title='New 'Jaff' ransomware via Necurs asks for 2 BTC'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/background.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>The dreaded Necurs botnet delivers a new ransomware with a high ransom ask in this newest spam campaign.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/malware\/\" rel=\"category tag\">Malware<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/jaff\/\" rel=\"tag\">Jaff<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/jaff-ransomware\/\" rel=\"tag\">Jaff ransomware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/locky\/\" rel=\"tag\">Locky<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/locky-ransomware\/\" rel=\"tag\">Locky ransomware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/necurs\/\" rel=\"tag\">necurs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/ransomware\/\" rel=\"tag\">ransomware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/new-jaff-ransomware-via-necurs-asks-for-2-btc\/' title='New 'Jaff' ransomware via Necurs asks for 2 BTC'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/05\/new-jaff-ransomware-via-necurs-asks-for-2-btc\/\">New &#8216;Jaff&#8217; ransomware via Necurs asks for 2 BTC<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,12225,12226,10795,10971,3764,11977,3765,10518],"class_list":["post-7599","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-jaff","tag-jaff-ransomware","tag-locky","tag-locky-ransomware","tag-malware","tag-necurs","tag-ransomware","tag-spam"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7599","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7599"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7599\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7599"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7599"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}