A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29657  by 711PartTimeJob
 Tue Nov 29, 2016 9:51 pm
A new ransomware in development has been found called "cockblocker" or sometimes "cocklocker". It encrypts files using RSA-2048 and renames them to a .hannah extension. Currently demands 1 BTC and displays a very ugly lock screen as seen here:
Image
Attachments
PW=infected
(300.52 KiB) Downloaded 182 times
 #29668  by p1nk
 Thu Dec 01, 2016 2:54 am
C2 server is: ws://collabvm.xyz:4444/rs

If you follow WHOIS data and bounce around a bit, you can find some links to https://github.com/cjhannah

GET /rs HTTP/1.1
User-Agent: websocket-sharp/1.0
Host: collabvm.xyz:4444
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Key: TQAYVC2FuB/7rRtmYE3QAw==
Sec-WebSocket-Version: 13