Che cos'è il formato di file BLOWER?
Un file .blower è un file normale, come un documento, una foto o un video, che è stato crittografato dal ransomware Blower. Blower è apparso all'inizio di febbraio 2019 e appartiene alla famiglia di ransomware STOP/Djvu. Quando infetta un computer, rimescola i file con il cifrario Salsa20 e aggiunge .blower a ogni nome, quindi report.docx diventa report.docx.blower. Come altre varianti di STOP/Djvu, crittografa solo i primi 150 KB di ogni file, il che lascia la parte finale dei file di grandi dimensioni leggibile ma comunque inutilizzabile.
Insieme ai file bloccati, Blower rilascia una richiesta di riscatto denominata _readme.txt. La nota richiede 490 $ entro le prime 72 ore, che salgono a 980 $, ed elenca gli indirizzi di contatto [email protected] e [email protected]. Durante la crittografia, il malware mostra spesso una finta finestra di Windows Update e modifica il file hosts di Windows per bloccare i siti web di sicurezza. Di solito si diffonde tramite software crackato, generatori di chiavi, falsi programmi di aggiornamento e allegati e-mail dannosi.
Sicurezza e incolumità
RISCHIO: HIGHA .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.
Dettagli del formato
in sintesiProgrammi che aprono file BLOWER
.blower files were locked with a recoverable offline key, then decrypt them back to their original form in place. Dettagli tecnici
specifiche approfondite| Encoding | Salsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable. |
| Byte order | N/A (original file bytes, partially enciphered) |
| Container | Original file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower) |
| Compression | None added by the ransomware; original compression of the source file is preserved in the unencrypted tail |
| Encryption | Salsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail. |
| Typical size | Same as the original file plus a small appended block containing the encryption marker and key/ID |
| Structure | Original file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end. |
| Integrity | None; no integrity field is added. |
| Platforms | Windows |
| Notes | Distributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders. |
| Rilasciato | 2019 (early February) |
| Specifica | www.emsisoft.com |
Conversioni BLOWER
Domande e risposte della community
chiesto dagli utentiAncora nessuna domanda - sii il primo a chiedere informazioni sui file BLOWER.