Что такое формат файла BLOWER?
Файл .blower - это обычный файл, например документ, фотография или видео, который был зашифрован программой-вымогателем Blower. Blower появился в начале февраля 2019 года и относится к семейству вымогателей STOP/Djvu. При заражении компьютера он шифрует файлы с помощью Salsa20 и добавляет .blower к каждому имени, так что report.docx превращается в report.docx.blower. Как и другие варианты STOP/Djvu, он шифрует только первые 150 КБ каждого файла, что оставляет «хвост» больших файлов читаемым, но все же непригодным для использования.
Вместе с заблокированными файлами Blower оставляет записку о выкупе с именем _readme.txt. В записке требуется 490 долларов США в течение первых 72 часов (с последующим увеличением до 980 долларов) и указаны контактные адреса [email protected] и [email protected]. Во время шифрования вредоносное ПО часто показывает поддельное окно Windows Update и редактирует файл Windows hosts, чтобы заблокировать доступ к сайтам по безопасности. Обычно оно распространяется через взломанное ПО, генераторы ключей, поддельные обновления и вредоносные вложения в электронной почте.
Безопасность и защита
РИСК: HIGHA .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.
Детали формата
в двух словахПрограммы, открывающие файлы BLOWER
.blower files were locked with a recoverable offline key, then decrypt them back to their original form in place. Технические подробности
глубокая спецификация| Encoding | Salsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable. |
| Byte order | N/A (original file bytes, partially enciphered) |
| Container | Original file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower) |
| Compression | None added by the ransomware; original compression of the source file is preserved in the unencrypted tail |
| Encryption | Salsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail. |
| Typical size | Same as the original file plus a small appended block containing the encryption marker and key/ID |
| Structure | Original file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end. |
| Integrity | None; no integrity field is added. |
| Platforms | Windows |
| Notes | Distributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders. |
| Выпущен | 2019 (early February) |
| Спецификация | www.emsisoft.com |
Конвертации BLOWER
Вопросы и ответы сообщества
спрошено пользователямиВопросов пока нет - станьте первым, кто спросит о файлах BLOWER.