New CoinVault ransomware from the same family as CryptoGraphic Locker. Encryption and decryption performed by same executable. Appears to use AES for encryption.
Files associated with CoinVault:
Files associated with CoinVault:
Code: Select all
Registry entries associated with CoinVault:%AppData%\Microsoft\Windows\coinvault.exe
%AppData%\Microsoft\Windows\edone
%AppData%\Microsoft\Windows\filelist.txt
%Temp%\CoinVaultFileList.txt
%Temp%\wallpaper.jpg
Code: Select all
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Vault "%AppData%\Microsoft\Windows\coinvault.exe"
HKCU\Control Panel\Desktop\Wallpaper "%Temp%\wallpaper.jpg"
Attachments
Infected
(400.96 KiB) Downloaded 862 times
(400.96 KiB) Downloaded 862 times
BleepingComputer.com