BLOWER ファイル形式とは?
.blowerファイルは、Blowerランサムウェアによって暗号化された、文書、写真、ビデオなどの通常のファイルです。Blowerは2019年2月初旬に出現し、STOP/Djvuランサムウェアファミリーに属しています。コンピュータに感染すると、Salsa20暗号を使用してファイルをスクランブルし、各名前に.blowerを追加します。例えば、report.docxはreport.docx.blowerになります。他のSTOP/Djvuの亜種と同様に、各ファイルの最初の150 KBのみを暗号化するため、大きなファイルの末尾は読み取り可能なまま残りますが、依然として使用不可能な状態です。
ロックされたファイルと並んで、Blowerは_readme.txtという名前の身代金要求ノートをドロップします。このノートは、最初の72時間以内に490ドル、その後は980ドルを要求し、連絡先アドレスとして [email protected] と [email protected] を記載しています。暗号化中、このマルウェアはしばしば偽の Windows Update ウィンドウを表示し、セキュリティサイトをブロックするために Windows の hosts ファイルを編集します。通常、ソフトウェアのクラック、キー生成ツール(Keygen)、偽のアップデーター、悪意のあるメールの添付ファイルを通じて拡散します。
セキュリティと安全性
リスク: HIGHA .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.
形式の詳細
概要BLOWER ファイルを開くプログラム
.blower files were locked with a recoverable offline key, then decrypt them back to their original form in place. 技術的詳細
詳細仕様| Encoding | Salsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable. |
| Byte order | N/A (original file bytes, partially enciphered) |
| Container | Original file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower) |
| Compression | None added by the ransomware; original compression of the source file is preserved in the unencrypted tail |
| Encryption | Salsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail. |
| Typical size | Same as the original file plus a small appended block containing the encryption marker and key/ID |
| Structure | Original file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end. |
| Integrity | None; no integrity field is added. |
| Platforms | Windows |
| Notes | Distributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders. |
| リリース日 | 2019 (early February) |
| 仕様書 | www.emsisoft.com |
BLOWER の変換
コミュニティ Q&A
ユーザーからの質問まだ質問はありません。BLOWER ファイルについて最初の質問をしてみましょう。