O que é um Ransoware?

Ransomware é um tipo de software malicioso (categoria de malware) que criptografa os dados armazenados em um equipamento, tornando eles inacessíveis aos usuários.
“Geralmente ele exige o pagamento de resgate (ransom) para devolver ou restabelecer o acesso ao dados dos usuários”.
Malware são códigos maliciosos especificamente desenvolvidos para executar usado para causar prejuízo, que pode ser até financeiro, interceptar dados, comprometer sistemas afetando computadores, dispositivos móveis e até redes inteiras.
O ransomware é projetado para criptografar os arquivos do usuário de forma que eles se tornem inacessíveis, e os criminosos por trás do ataque exigem o pagamento de um valor em dinheiro, geralmente em criptomoedas, para fornecer a chave de descriptografia e permitir que o usuário recupere seus arquivos.
Os ransomwares podem infectar os sistemas de várias maneiras, incluindo:
- E-mails de phishing: Os criminosos enviam e-mails fraudulentos que parecem legítimos, geralmente com anexos maliciosos ou links para sites comprometidos. Quando o usuário abre o anexo ou clica no link, o ransomware é baixado e executado em seu sistema.
- Exploits de software: Os ransomwares podem se aproveitar de vulnerabilidades em softwares desatualizados para infiltrar-se nos sistemas. Uma vez que o ransomware ganha acesso, ele começa a criptografar os arquivos.
- Downloads de sites não confiáveis: Ao fazer o download de arquivos de fontes não confiáveis ou de sites comprometidos, é possível que o usuário acabe baixando um arquivo que contém ransomware.
Quando um sistema é infectado com ransomware, o usuário geralmente recebe uma mensagem de resgate na qual os criminosos exigem o pagamento em troca da chave de descriptografia. Essas mensagens muitas vezes contêm instruções detalhadas sobre como realizar o pagamento, geralmente usando criptomoedas para dificultar o rastreamento.
É importante destacar que pagar o resgate não garante a recuperação dos arquivos, pois os criminosos podem não cumprir suas promessas ou podem retornar com novas exigências de pagamento. Além disso, o pagamento incentiva o crescimento desse tipo de atividade criminosa.
A melhor maneira de se proteger contra ransomware é tomar medidas preventivas, como manter o sistema e o software atualizados, fazer backups regulares de dados importantes e evitar abrir anexos ou clicar em links suspeitos em e-mails ou sites desconhecidos. O uso de software antivírus e firewalls também pode ajudar a identificar e bloquear a entrada de ransomware nos sistemas.
Lista de Extensões de arquivos utilizados por Ransowares (Atualizado 2023)
# | Extensão | File type description |
---|---|---|
1 | _AiraCropEncrypted | AiraCrop Ransomware affecte file |
2 | 1cbu1 | Princess Locker ransomware affected file |
3 | 1txt | Enigma ransomware affected file |
4 | 73i87A | Xorist Ransomware affected data |
5 | a5zfn | Alma Locker ransomware affected data |
6 | aaa | TeslaCrypt ransomware encrypted data |
7 | abc | TeslaCrypt ransomware encrypted data |
8 | adk | Angry Duck ransomware affected file |
9 | aesir | Locky ransomware affected file |
10 | alcatraz | Alcatraz Locker ransomware affected file |
11 | angelamerkel | Angela Merkel ransomware affected file |
12 | AngleWare | HiddenTear/MafiaWare (variant) ransomware affected file |
13 | antihacker2017 | Xorist (variant) Ransomware affected file |
14 | atlas | Atlas ransomware affected file |
15 | axx | AxCrypt encrypted data |
16 | BarRax | BarRax (HiddenTear variant) ransomware affected file |
17 | bin | Alpha/Alfa ransomware affected data |
18 | bitstak | Bitstak ransomware affected data |
19 | braincrypt | Braincrypt ransomware affected file |
20 | breaking_bad | Files1147@gmail(.)com ransomware affected data |
21 | bript | BadEncriptor ransomware affected file |
22 | btc | Jigsaw Ransomware affected data |
23 | ccc | TeslaCrypt or Cryptowall encrypted data |
24 | CCCRRRPPP | Unlock92 ransomware affected data |
25 | cerber | Cerber ransomware affected data |
26 | cerber2 | Cerber 2 ransomware affected file |
27 | cerber3 | Cerber 3 ransomware affected data |
28 | coded | Anubis ransomware affected file |
29 | comrade | Comrade ransomware affected file |
30 | conficker | Conficker ransomware affected file |
31 | coverton | Coverton ransomware affected data |
32 | covid-19 | Phishing / ransomware file |
33 | covid19 | Phishing / ransomware file |
34 | crab | GandCrab ransomware affected data |
35 | crinf | DecryptorMax or CryptInfinite ransomware affected data |
36 | crjoker | CryptoJoker ransomware affected data |
37 | crptrgr | CryptoRoger ransomware affected data |
38 | cry | CryLocker ransomware affected data |
39 | cryeye | DoubleLocker ransomware affected data |
40 | cryp1 | CryptXXX ransomware affected data |
41 | crypt | Scatter ransomware affected data |
42 | crypte | Jigsaw (variant) ransomware affected file |
43 | crypted | Nemucod ransomware affected file |
44 | cryptolocker | CryptoLocker encrypted file |
45 | cryptowall | Encrypted file by Cryptowall ransomware |
46 | crypz | CryptXXX ransomware affected data |
47 | czvxce | Coverton ransomware affected file |
48 | d4nk | PyL33T ransomware affected file |
49 | dale | Chip ransomware affected file |
50 | damage | Damage ransomware affected file |
51 | darkness | Rakhni ransomware affected data |
52 | dCrypt | DummyLocker ransomware affected file |
53 | deadbolt | Deadbolt ransomware affected file |
54 | decrypt2017 | Globe 3 ransomware affected file |
55 | derp | Derp ransomware renamed file |
56 | Dexter | Troldesh (variant) ransomware affected file |
57 | dharma | CrySiS ransomware affected file |
58 | dll | FSociety ransomware affected file |
59 | dxxd | DXXD ransomware affected file |
60 | ecc | Cryptolocker or TeslaCrypt virus encrypted file |
61 | edgel | EdgeLocker ransomware affected file |
62 | enc | TorrentLocker ransomware affected file |
63 | enc | Cryptorium ransomware affected file |
64 | enciphered | Malware (ransomware) encoded data |
65 | EnCiPhErEd | Xorist Ransomware affected data |
66 | encr | FileLocker ransomware affected file |
67 | encrypt | Alpha ransomware affected data |
68 | encrypted | Various ransomware affected file |
69 | encrypted | Donald Trump ransomware affected file |
70 | encrypted | KeRanger OS X ransomware affected file |
71 | enigma | Coverton ransomware affected data |
72 | evillock | Evil-JS (variant) ransomware affected file |
73 | exotic | Exotic ransomware affected file |
74 | exx | Alpha Crypt encrypted data |
75 | ezz | Alpha Crypt virus encrypted data |
76 | fantom | Fantom ransomware affected data |
77 | file0locked | Evil ransomware affected file |
78 | fucked | Manifestus ransomware affected file |
79 | fun | Jigsaw Ransomware affected data |
80 | fun | Jigsaw (variant) ransomware affected file |
81 | gefickt | Jigsaw (variant) ransomware affected file |
82 | globe | Globe ransomware affected file |
83 | good | Scatter ransomware affected data |
84 | grt | Karmen HiddenTear (variant) ransomware affected file |
85 | ha3 | El-Polocker affected file |
86 | helpmeencedfiles | Samas/SamSam ransomware affected file |
87 | herbst | Herbst ransomware affacted data |
88 | hnumkhotep | Globe 3 ransomware affected file |
89 | hush | Jigsaw ransomware affected file |
90 | ifuckedyou | SerbRansom ransomware affected file |
91 | info | PizzaCrypts Ransomware affected data |
92 | kernel_complete | KeRanger OS X ransomware data |
93 | kernel_pid | KeRanger OS X ransomware data |
94 | kernel_time | KeRanger OS X ransomware |
95 | keybtc@inbox_com | KeyBTC ransomware affected data |
96 | kimcilware | KimcilWare ransomware affected data |
97 | kkk | Jigsaw Ransomware affected data |
98 | kostya | Kostya ransomware affected file |
99 | krab | GandCrab v4 ransomware affected data |
100 | kraken | Rakhni ransomware affected file |
101 | kratos | KratosCrypt ransomware affected data |
102 | kyra | Globe ransomware affected file |
103 | lcked | Jigsaw (variant) ransomware affected file |
104 | LeChiffre | LeChiffre ransomware affected data |
105 | legion | Legion ransomware affected data |
106 | lesli | CryptoMix ransomware affected file |
107 | lock93 | Lock93 ransomware affected file |
108 | locked | Various ransomware affected data |
109 | locklock | LockLock ransomware affected data |
110 | locky | Locky ransomware affected data |
111 | lol! | GPCode ransomware affected data |
112 | loli | LOLI RanSomeWare ransomware affected file |
113 | lovewindows | Globe (variant) ransomware affected file |
114 | madebyadam | Roga ransomware affected file |
115 | magic | Magic ransomware affected data |
116 | maya | HiddenTear (variant) ransomware affected file |
117 | MERRY | Merry X-Mas ransomware affected file |
118 | micro | TeslaCrypt 3.0 ransomware encrypted data |
119 | mole | CryptoMix (variant) ransomware affected data |
120 | mp3 | TeslaCrypt 3.0 ransomware encrypted data |
121 | MRCR1 | Merry X-Mas ransomware affected file |
122 | noproblemwedecfiles | Samas/SamSam ransomware affected file |
123 | nuclear55 | Nuke ransomware affected file |
124 | odcodc | ODCODC ransomware affected file |
125 | odin | Locky ransomware affected file |
126 | onion | Dharma ransomware affected data |
127 | oops | Marlboro ransomware affected file |
128 | osiris | Locky (variant) ransomware affected data |
129 | p5tkjw | Xorist Ransomware affected data |
130 | padcrypt | PadCrypt ransomware affected data |
131 | paym | Jigsaw Ransomware affected data |
132 | paymrss | Jigsaw Ransomware affected file |
133 | payms | Jigsaw Ransomware affected file |
134 | paymst | Jigsaw Ransomware affected file |
135 | paymts | Jigsaw Ransomware affected file |
136 | payrms | Jigsaw Ransomware affected file |
137 | pays | Jigsaw Ransomware affected data |
138 | pdcr | PadCrypt Ransomware script |
139 | pec | PEC 2017 ransomware affected file |
140 | PEGS1 | Merry X-Mas ransomware affected file |
141 | perl | Bart ransomware affected file |
142 | PoAr2w | Xorist Ransomware affected file |
143 | potato | Potato ransomware affected file |
144 | powerfulldecrypt | Samas/SamSam ransomware affected file |
145 | pubg | PUBG ransomware affected data |
146 | purge | Globe ransomware affected file |
147 | pzdc | Scatter ransomware affected data |
148 | R16m01d05 | Ransomware affected data |
149 | r5a | 7ev3n ransomware affected file |
150 | raid10 | Globe [variant] ransomware affected file |
151 | RARE1 | Merry X-Mas ransomware affected file |
152 | razy | Razy ransomware affected data |
153 | rdm | Radamant ransomware affected file |
154 | realfs0ciety@sigaint.org.fs0ciety | Fsociety ransomware affected file |
155 | reco | STOP/DJVU ransomware file |
156 | rekt | HiddenTear (variant) ransomware affected file |
157 | rekt | RektLocker ransomware affected data |
158 | remk | STOP Ransomware variant |
159 | rip | KillLocker ransomware affected file |
160 | RMCM1 | Merry X-Mas ransomware affected file |
161 | rmd | Zeta ransomware affected file |
162 | rnsmwr | Gremit ransomware affected file |
163 | rokku | Rokku ransomware affected data |
164 | rrk | Radamant v2 ransomware affected file |
165 | ruby | Ruby ransomware affected file |
166 | sage | Sage ransomware affected data |
167 | SecureCrypted | Apocalypse ransomware affected file |
168 | serp | Serpent (variant) ransomware affected file |
169 | serpent | Serpent ransomware affected file |
170 | sexy | PayDay ransomware affected files |
171 | shit | Locky ransomware affected file |
172 | spora | Spora ransomware affected file |
173 | stn | Satan ransomware affected file |
174 | surprise | Surprise ransomware affected data |
175 | szf | SZFLocker ransomware affected data |
176 | theworldisyours | Samas/SamSam ransomware affected file |
177 | thor | Locky ransomware affected file |
178 | ttt | TeslaCrypt 3.0 ransomware encrypted data |
179 | unavailable | Al-Namrood ransomware affected file |
180 | vbransom | VBRansom 7 ransomware affected file |
181 | venusf | Venus Locker ransomware affected file |
182 | VforVendetta | Samsam (variant) ransomware affected file |
183 | vindows | Vindows Locker ransomware affected file |
184 | vvv | TeslaCrypt 3.0 ransomware encrypted data |
185 | vxlock | vxLock ransomware affected file |
186 | wallet | Globe 3 (variant) ransomware affected file |
187 | wcry | WannaCry ransomware affected file |
188 | wflx | WildFire ransomware affected file |
189 | Whereisyourfiles | Samas/SamSam ransomware affected file |
190 | windows10 | Shade ransomware affected data |
191 | wncry | Wana Decrypt0r 2.0 ransomware affected data |
192 | xxx | TeslaCrypt 3.0 ransomware encrypted file |
193 | xxx | help_dcfile ransomware affected file |
194 | xyz | TeslaCrypt ransomware encrypted data |
195 | ytbl | Troldesh (variant) ransomware affected file |
196 | zcrypt | ZCRYPT ransomware affected data |
197 | zepto | Locky ransomware affected data |
198 | zorro | Zorro ransomware affected file |
199 | zyklon | ZYKLON ransomware affected data |
200 | zzz | TeslaCrypt ransomware encrypted data |
201 | zzzzz | Locky ransomware affected file |