Geeks for your information
Emsisoft releases new decryptor for ChernoLocker ransomware - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: Security (https://www.geeks.fyi/forumdisplay.php?fid=68)
+--- Forum: Security Vendors (https://www.geeks.fyi/forumdisplay.php?fid=87)
+---- Forum: EmsiSoft (https://www.geeks.fyi/forumdisplay.php?fid=89)
+----- Forum: Emsisoft Blog Articles (https://www.geeks.fyi/forumdisplay.php?fid=140)
+----- Thread: Emsisoft releases new decryptor for ChernoLocker ransomware (/showthread.php?tid=9667)



Emsisoft releases new decryptor for ChernoLocker ransomware - harlan4096 - 27 December 19

Quote:
[Image: logo.svg]

We just released a new decryption tool for the ChernoLocker ransomware strain. You can download the FREE decryption tool linked below. A detailed guide is also included.

Download the ChernoLocker Decryptor here

Technical details

ChernoLocker is programmed in Python, and encrypts files using AES-256, adding the extension “(.CHERNOLOCKER)”. When ran before it encrypts the victim’s files, the following popup appears:

[Image: 2019-12-19_1527.png]

Unlike most ransomware strains that include a text file containing its ransom note, ChernoLocker’s ransom note is delivered via a popup window. It reads:

[Image: image-2.png]

Quote:All Your Files have now been encrypted with the strongest encryption You need to purchase the encryption key otherwise you won’t recover your files Read the Browser tab on ways to recover your files Make Sure you don’t loose this Email as you it will be loosing it will be fatal Write it in a notepad and keep it safe Email: filelocker@protonmail.ch
...
Continue Reading