Qu'est-ce que le format de fichier BLOWER ?
Un fichier .blower est un fichier normal, tel qu'un document, une photo ou une vidéo, qui a été chiffré par le ransomware Blower. Blower est apparu au début de février 2019 et appartient à la famille de ransomwares STOP/Djvu. Lorsqu'il infecte un ordinateur, il brouille les fichiers avec le chiffrement Salsa20 et ajoute .blower à chaque nom, ainsi report.docx devient report.docx.blower. Comme d'autres variantes de STOP/Djvu, il ne chiffre que les premiers 150 Ko de chaque fichier, ce qui laisse la fin des fichiers volumineux lisible mais toujours inutilisable.
Parallèlement aux fichiers verrouillés, Blower dépose une note de rançon nommée _readme.txt. La note demande 490 $ dans les premières 72 heures, montant qui passe à 980 $, et indique les adresses de contact [email protected] et [email protected]. Pendant le chiffrement, le logiciel malveillant affiche souvent une fausse fenêtre Windows Update et modifie le fichier hosts de Windows pour bloquer les sites web de sécurité. Il se propage généralement via des logiciels piratés, des générateurs de clés, de faux programmes de mise à jour et des pièces jointes d'e-mails malveillants.
Sécurité et sûreté
RISQUE : HIGHA .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.
Détails du format
en brefProgrammes qui ouvrent les fichiers BLOWER
.blower files were locked with a recoverable offline key, then decrypt them back to their original form in place. Détails techniques
spécifications approfondies| Encoding | Salsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable. |
| Byte order | N/A (original file bytes, partially enciphered) |
| Container | Original file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower) |
| Compression | None added by the ransomware; original compression of the source file is preserved in the unencrypted tail |
| Encryption | Salsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail. |
| Typical size | Same as the original file plus a small appended block containing the encryption marker and key/ID |
| Structure | Original file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end. |
| Integrity | None; no integrity field is added. |
| Platforms | Windows |
| Notes | Distributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders. |
| Publié | 2019 (early February) |
| Spécification | www.emsisoft.com |
Conversions BLOWER
Q&R de la communauté
posées par les utilisateursPas encore de questions - soyez le premier à poser une question sur les fichiers BLOWER.