Wat is het BLOWER-bestandsformaat?
Een .blower-bestand is een normaal bestand, zoals een document, foto of video, dat is versleuteld door de Blower ransomware. Blower verscheen begin februari 2019 en behoort tot de STOP/Djvu ransomware-familie. Wanneer het een computer infecteert, versleutelt het bestanden met het Salsa20-cijfer en voegt het .blower toe aan elke naam, zodat report.docx verandert in report.docx.blower. Net als andere STOP/Djvu-varianten versleutelt het alleen de eerste 150 KB van elk bestand, waardoor het einde van grote bestanden leesbaar maar nog steeds onbruikbaar blijft.
Naast de vergrendelde bestanden plaatst Blower een losgeldbrief genaamd _readme.txt. De notitie vraagt om $490 binnen de eerste 72 uur, oplopend tot $980, en vermeldt de contactadressen [email protected] en [email protected]. Tijdens de versleuteling toont de malware vaak een nep Windows Update-venster en bewerkt het het Windows hosts-bestand om beveiligingswebsites te blokkeren. Het verspreidt zich meestal via gekraakte software, key generators, valse updaters en kwaadaardige e-mailbijlagen.
Beveiliging & veiligheid
RISICO: HIGHA .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.
Formaatdetails
in een notendopProgramma's die BLOWER-bestanden openen
.blower files were locked with a recoverable offline key, then decrypt them back to their original form in place. Technische details
diepe specificaties| Encoding | Salsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable. |
| Byte order | N/A (original file bytes, partially enciphered) |
| Container | Original file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower) |
| Compression | None added by the ransomware; original compression of the source file is preserved in the unencrypted tail |
| Encryption | Salsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail. |
| Typical size | Same as the original file plus a small appended block containing the encryption marker and key/ID |
| Structure | Original file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end. |
| Integrity | None; no integrity field is added. |
| Platforms | Windows |
| Notes | Distributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders. |
| Uitgebracht | 2019 (early February) |
| Specificatie | www.emsisoft.com |
BLOWER conversies
Community V&A
gevraagd door gebruikersNog geen vragen - wees de eerste om iets te vragen over BLOWER-bestanden.