Vad är filformatet BLOWER?
En .blower-fil är en vanlig fil, till exempel ett dokument, foto eller video, som har krypterats av Blower ransomware. Blower dök upp i början av februari 2019 och tillhör ransomware-familjen STOP/Djvu. När den infekterar en dator förvanskas filer med Salsa20-chiffer och .blower läggs till i varje namn, så att report.docx blir report.docx.blower. Precis som andra STOP/Djvu-varianter krypterar den endast de första 150 KB av varje fil, vilket gör att slutet på stora filer förblir läsbart men fortfarande oanvändbart.
Tillsammans med de låsta filerna lämnar Blower ett lösenkrav med namnet _readme.txt. Meddelandet kräver 490 dollar inom de första 72 timmarna, vilket sedan stiger till 980 dollar, och listar kontaktadresserna [email protected] och [email protected]. Under krypteringen visar skadlig kod ofta ett falskt Windows Update-fönster och redigerar Windows hosts-fil för att blockera säkerhetswebbplatser. Det sprids vanligtvis via piratkopierad programvara, nyckelgeneratorer, falska uppdateringar och skadliga e-postbilagor.
Säkerhet & trygghet
RISK: HIGHA .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.
Formatdetaljer
i ett nötskalProgram som öppnar BLOWER-filer
.blower files were locked with a recoverable offline key, then decrypt them back to their original form in place. Tekniska detaljer
djup specifikation| Encoding | Salsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable. |
| Byte order | N/A (original file bytes, partially enciphered) |
| Container | Original file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower) |
| Compression | None added by the ransomware; original compression of the source file is preserved in the unencrypted tail |
| Encryption | Salsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail. |
| Typical size | Same as the original file plus a small appended block containing the encryption marker and key/ID |
| Structure | Original file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end. |
| Integrity | None; no integrity field is added. |
| Platforms | Windows |
| Notes | Distributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders. |
| Släppt | 2019 (early February) |
| Specifikation | www.emsisoft.com |
BLOWER-konverteringar
Frågor & svar
frågat av användareInga frågor än - bli den första att fråga om BLOWER-filer.