Wednesday 2 September 2015

ORX Locker a new ransomware

Security experts at Sensecy have uncovered ORX-Locker, a Darknet Ransomware-as-a-service platform that could allow everyone to become a cyber criminal.

It is becoming even easier to become a cyber-criminal thanks to the model of sale known as malware-as-a-service that offers off-the-shelf malware for rent or sale. Recently malware authors started to offer also Ransomware-as-a-Service (RaaS), in August security experts at McAfee discovered in the Deep Web a ransomware-construction kit, dubbed Tox ransomware platform that allows easy to build malware in just 3 steps, implementing this model of sale.
Now experts at Sensecy are warning of a new RaaS platform dubbed titled ORX-Locker, it allows criminals to create their piece of malware to infect systems and request the payment of a fee to unlock the system.
In RaaS model, when victims decide to pay, the malware redirects them through a service provider that keeps a percent of the fee and forwards the rest to the criminal.
ORX implements a sophisticated AV evasion method and complex communication techniques, the researchers discovered that it uses universities and other platforms as control infrastructure.
The First Appearance for the ORX ransomware is dated August 25, 2015, when a user dubbed orxteam announced the availability of a new RaaS service in a post.
Team Orx RaaS ransomware message
The team ORX developed a hidden service to implement the RaaS, the experts highlight that the website requests a few details to new users.
“To enter the site, new users just need to register. No email or other identifying details are required. Upon registration, users have the option to enter a referral username, which will earn them three percent from every payment made to the new user.” state the post that provides a detailed description of the ORX platform.
In order to create a ransomware stub the users just need to add the ID number (5 digits max) and the ransom price (ORX put a minimum of $75), then they have to click the Build EXE button.
The user can easily withdraw his earnings by transferring them to a Bitcoin address by using the Wallet function. The Orx ransomware platform also implements a friendly statistics on its users.
The Orx Ransomware is a zip file containing the binary for the malware.
The researchers at Sensecy have identified these addresses belonging the C&C infrastructure.
  1. 130[.]75[.]81[.]251 – Leibniz University of Hanover
  2. 130[.]149[.]200[.]12 – Technical University of Berlin
  3. 171[.]25[.]193[.]9 – DFRI (Swedish non-profit and non-party organization working for digital rights)
  4. 199[.]254[.]238[.]52 – Riseup (Riseup provides online communication tools for people and groups working on liberatory social change)
The Orx ransomware encrypts the victim’s files and informs it about the infection by displaying a popup message, it also creates on the desktop a file containing the payment instruction.
orx platform message
The post published by the researchers at Sensecy includes also the Yara rule for the malware detection.


2 comments:

  1. 🔍🔍Are you Seeking for the Best Legit Professional Hackers online??❓💻💻💻
    Congratulations Your search ends right here with us. 🔍🔍🔍🔍

    🏅ALEXGHACKLORD is a vibrant squad of dedicated online hackers maintaining the highest standards and unparalleled professionalism in every aspect.
    We Are One Of The Leading Hack Teams in The United States🇺🇸🇺🇸 With So many Accolades From The IT Companies🏆🏅🥇. In this online world there is no Electronic Device we cannot hack. Having years of experience in serving Clients with Professional Hacking services, we have mastered them all. You might get scammed for wrong hacking services or by fake hackers on the Internet. Don't get fooled by scamers that are advertising false professional hacking services via False Testimonies, and sort of Fake Write Ups.❌❌❌❌

    * ALEXGHACKLORD is the Answers to your prayers. We Can help you to recover the password of your email, Facebook or any other accounts, Facebook Hack, Phone Hack (Which enables you to monitor your kids/wife/husband/boyfriend/girlfriend, by gaining access to everything they are doing on their phone without their notice), You Wanna Hack A Website or Database? You wanna Clear your Criminal Records?? Our Team accepts all types of hacking orders and delivers assured results to alleviate your agonies and anxieties. Our main areas of expertise include but is never confined to:

    ✅Website hacking 💻,✅Facebook and social media hacking📲, ✅Database hacking, Email hacking⌨️, ✅Phone and Gadget Hacking📲💻,✅Clearing Of Criminal Records❌ ✅Location Tracking✅ Credit Card Loading✅ and many More✅

    🏅We have a trained team of seasoned professionals under various skillsets when it comes to online hacking services. Our company in fact houses a separate group of specialists who are productively focussed and established authorities in different platforms. They hail from a proven track record and have cracked even the toughest of barriers to intrude and capture or recapture all relevant data needed by our Clients. 📲💻

    🏅 ALEXGHACKLORD understands your requirements to hire a professional hacker and can perceive what actually threatens you and risk your business⚔️, relationships or even life👌🏽. We are 100% trusted professional hacking Organization and keep your deal entirely confidential💯. We are aware of the hazards involved. Our team under no circumstances disclose information to any third party❌❌. The core values adhered by our firm is based on trust and faith. Our expert hacking online Organization supports you on time and reply to any query related to the unique services we offer. 💯

    🏅ALEXGHACKLORD is available for customer care 24/7, all day and night. We understand that your request might be urgent, so we have a separate team of allocated hackers who interact with our Clients round the clock⏰. You are with the right people so just get started.💯✅

    ✅CONTACT US TODAY VIA:✅
    📲 ALEXGHACKLORD@GMAiL. COM 📲

    Reply

    ReplyDelete
  2. Selling USA FRESH SSN Leads/Fullz, along with Driving License/ID Number with good connectivity.

    **Price for One SSN lead 2$**

    All SSN's are Tested & Verified. Fresh spammed data.

    **DETAILS IN LEADS/FULLZ**

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER
    ->ADDRESS WITH ZIP
    ->PHONE NUMBER, EMAIL
    ->EMPLOYEE DETAILS

    ->Bulk order negotiable
    ->Hope for the long term business
    ->You can asked for specific states too

    **Contact 24/7**

    Whatsapp > +923172721122

    Email > leads.sellers1212@gmail.com

    Telegram > @leadsupplier

    ICQ > 752822040

    ReplyDelete