Sat. Apr 20th, 2024

“Blank Slate” Spam Campaign Spreads GlobeImposter Virus

By KWS Adams Aug 8, 2017
“Blank Slate” Spam Campaign Spreads GlobeImposter Virus

The Blank Slate spam operation has shifted from spreading the BTCware ransomware to spreading GlobeImposter ransomware version that adds the .crypt extension. This spam campaign is known as Blank Slate because all spam emails lack contents in the message body and also have blank subject lines.

At the same time, all emails include ZIP archive attachments named using the simple format: EMAIL_(Random Numbers)_(Recipient Name).ZIP.

If victims open this ZIP file they will find another ZIP file inside called like: (Random Numbers).ZIP. This second ZIP file then carries a random named dubious JS script. So names development will looks like this: EMAIl_372616_legaldept.zip > 372616.ZIP > sdeSh.js.

Once launched, the JS script will contact a special website controlled by criminals and download an executable file named 1.dat.

A remarkable feature of the most recent downloaded virus executable is that it signed by the Thawte Certificate Authority.

When the .dat file is downloaded, it will run and install any payload malware authors believe suitable. Most recently the installed virus is a GlobeImposter ransomware variant that adds .crypt extension to locked files.

While encrypting data files this virus is presenting a ransom note called !back_files!.html in all folders on the victim’s machine. In the ransom note hackers instruct their victims to send messages to contact [email protected] to get further payment instructions.

To try to remove this virus and decrypt your files you can use this guide or seek help at the dedicated thread on malware help forum.

By KWS Adams

My name is KWS Adams . (Call me Kateregga). I am an IT addict who loves playing around with computers and internet. Computers help me try out different things while turning them into reality, while the internet powers me stay live online. Besides computers, I am a project planning and management professional with an Award obtained from MUK, one of the oldest and best Universities in Africa. Find me on Twitter, Facebook and Whatsapp. Find more on how to contact me using the contact me page.

Related Post

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.