A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #21677  by Cody Johnston
 Fri Dec 13, 2013 7:58 pm
It was reported today that there is a new crypto ransomware called "Locker". I was wondering if anyone had seen this in circulation or has a sample.

Sadly, the articles do not have an md5:
Locker's encryption is based on an open source tool called 'TurboPower LockBox' library. After encrypting all files, the malware place a "CONTACT.TXT" file in each directory, which provides contact details of the author to buy the decryption key and once the ransom is paid, each victim gets a key to unscramble files.
http://www.zdnet.com/new-crypto-ransomw ... 000024282/
http://thehackernews.com/2013/12/locker ... riant.html

Thanks!