Home Malware Programs Potentially Unwanted Programs (PUPs) RanDsomeWare Ransomware

RanDsomeWare Ransomware

Posted: July 27, 2017

Threat Metric

Threat Level: 8/10
Infected PCs: 1,159
First Seen: July 27, 2017
Last Seen: November 6, 2021
OS(es) Affected: Windows

The RanDsomeWare Ransomware is a Trojan that blocks the user's local files by encrypting them. Although current samples of the RanDsomeWare Ransomware don't seem to be extortionist in nature, minimal updates could facilitate such attacks with this Trojan's payload. Use anti-malware programs for protecting your PC from file-encoding threats or uninstalling the RanDsomeWare Ransomware, and backups for guaranteeing that no permanent harm befalls your media.

An Encryption Problem that's Anything but Random

Even free and legal software is corruptible towards harmful and illicit acts, and PC users unsure about the safety of a program never should run it without further attempted analysis. Some of the most publicized examples of 'good' software warping into the con artists profitability are the Hidden Tear and EDA2 families, which Turkish programmer Utku Sen developed for demonstrating non-consensual encryption functions. Now, a newcomer program is showing similar predilections: the RanDsomeWare Ransomware.

Malware researchers haven't seen the RanDsomeWare Ransomware in live distribution or as part of a ransom-collecting campaign, and it seems to be made for helping PC users analyze the basics of a forced encryption solely. When the user opens it, the RanDsomeWare Ransomware displays a simple pop-up warning that forewarns about the encryption feature and recommends running only from within a Virtual Machine environment. Instead of using an exploit to bypass the Windows permissions security, the RanDsomeWare Ransomware prompts the user to grant the RanDsomeWare Ransomware admin access intentionally.

The RanDsomeWare Ransomware's encryption function, once underway, is similar to those of other file-locking threats and encodes different formats of media according to an internal cipher. The '.RDWF' extensions it appends to their names also serve as means of identifying which files will no longer open. Unlike most file-encrypting Trojans, the RanDsomeWare Ransomware doesn't include a ransom message or other means of soliciting payment for the decryption solution.

Decoding a Lesson in Trojan Programming

The RanDsomeWare Ransomware's payload also has another, important detail showing that it's not wrongful oriented: the fact that it uses a static decryption password, instead of a custom-generated one. Typing 'SUPER_SECRET_KEY' in the secondary pop-up that the Trojan loads should recover any encoded content in full. Concerning updates, secure versions of the RanDsomeWare Ransomware or similar threats, malware experts more often recommend using backups for retrieving any blocked files.

The samples of the RanDsomeWare Ransomware shown right now have limited capacity to harm any attentive PC user but do show a working encryption function. Con artists interested in exploiting its code, similarly to EDA2 or Hidden Tear, could make minor updates, remove its warning message, and modify the decryption 'key.' Due to its high potential for abuse, malware experts recommend removing the RanDsomeWare Ransomware with anti-malware services that should detect it as a threat by default.

The user who created the RanDsomeWare Ransomware may not have meant for any harmful purpose. However, when it comes to the threatening software industry, intention often runs up against a brick wall of profit-seeking motives that result in file damage for unfortunate few.

Loading...