<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>LockCrypt on Melted in Hex</title>
    <link>https://meltedinhex.com/tags/lockcrypt/</link>
    <description>Recent content in LockCrypt on Melted in Hex</description>
    <image>
      <title>Melted in Hex</title>
      <url>https://meltedinhex.com/images/og-social.png</url>
      <link>https://meltedinhex.com/images/og-social.png</link>
    </image>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 01 Dec 2017 04:43:00 +0530</lastBuildDate>
    <atom:link href="https://meltedinhex.com/tags/lockcrypt/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Analysis of LockCrypt ransomware</title>
      <link>https://meltedinhex.com/posts/analysis-of-lockcrypt-ransomware/</link>
      <pubDate>Fri, 01 Dec 2017 04:43:00 +0530</pubDate>
      <guid>https://meltedinhex.com/posts/analysis-of-lockcrypt-ransomware/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Introduction:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Attackers have been recently breaking into corporate servers via RDP brute force attacks to spread a new variant of ransomware called LockCrypt. The attacks first started in June but there was an increase of attacks in October. The victims were asked to pay 0.5 to 1 BTC to recover their server.&lt;br&gt;
LockCrypt encrypts all files and renames them with a &amp;lsquo;.lock&amp;rsquo; extension. It also installs itself for persistence and deletes backups.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
