Intelligence View
Hitler Ransomware Infects Everyone, Not Just the Jews
Two days ago, AVG security researcher Jakub Kroustek discovered a quite originally named ransomware variant called the Hitler Ransomware (actually Ransonware but the grammar Nazi lying in me could not let that pass) that deletes your files…
The Hitler ransomware infection takes place when the user double-clicks on an infected binary. According to Bleeping Computer, this file drops a batch file on the user's system, which then drops three files called firefox32.exe, ErOne.vbs, and chrst.exe.
Firefox32.exe is copied to the startup folder to ensure the ransomware starts with every PC boot. ErOne.vbs shows an error when the user clicks the original executable, making him believe the file contains an error. Chrst.exe is the actual ransomware, which displays...
SOCIAL SHARE CARD GENERATOR