[Nulled] » Information security » Avast has released a decryptor for the BianLian ransomware, which is available for public download.
January 23 2023

Avast has released a decryptor for the BianLian ransomware, which is

Avast has released a decryptor for the BianLian ransomware, which is available for public download.

BianLian appeared in August 2022, carrying out targeted attacks in various industries, primarily media, manufacturing and healthcare.

Ransomware is notable for encrypting files at high speeds.

BianLian is written in Go and compiled as a 64-bit Windows executable.

In the ransomware binary file, you can see a lot of lines, including information about the directory structure on the author's computer.

Data is encrypted using AES-256 in CBC mode. The length of the encrypted data reaches up to 16 bytes, as required by the AES CBC cipher.

After execution, BianLian searches for all available disks (from A: to Z:), on which it then searches and encrypts all files whose extension corresponds to one of the 1013 extensions hard-coded in the binary file of the program. 

At the same time, ransomware does not encrypt the file either from the beginning or to the end. Instead, there is a fixed file offset hard-coded in the binary file from which the encryption originates.

The offset varies depending on the sample, but none of the known samples encrypts data from the beginning of the file.

After encrypting the data, the ransomware adds the bianlian extension and a ransom note Look at this instruction.txt to each folder on the PC.

The decryptor can recover files encrypted only by a known variant of BianLian.

New victims may need to find the binary file of the ransomware on their hard drive.

However, this will be problematic because the ransomware deletes itself after encryption.

According to Avast telemetry, common BianLian ransomware file names on the victim's computer include: C:\Windows\TEMP\mativ.exe , C:\Windows\Temp\Areg.exe , C:\Users\%username%\Pictures\windows.exe and anabolic.exe .

When searching for a binary file, it is recommended to pay attention to the EXE file in a folder that usually does not contain executable files, such as %temp%, Documents or Pictures.

You should also check the antivirus storage. The typical size of a BianLian executable file is about 2 MB.

As noted by Avast, the detection of new samples will allow them to update the decoder accordingly.

Warning! You are not allowed to view this text.

Information

Visitors who are in the group Guests they can't download files.
Log in to the site under your login and password or if you are a new user go through the process registrations on the website.

Comments:

This publication has no comments yet. You can be the first!

Information the publication:

Related News

15 January 2023
Information security
🔓 A free decryptor has

🔓 A free decryptor has appeared for the MegaCortex ransomware Bitdefender has released a tool for decrypting files

Read more
16 January 2023
Information security
If Villariba and

If Villariba and Villabaggio had suffered from the MegaCortex ransomware, then they would really have had a

Read more
16 January 2023
Information security
The largest medical

The largest medical facility in Lake Charles (LCMHS), Louisiana was attacked by ransomware, resulting in a leak of

Read more
14 March 2022
Information security / Anonymity on the web
How to securely encrypt

How to securely encrypt the contents of your computer? If you have confidential documents that you would like to

Read more
15 January 2023
Hacking
Anonymous and encrypted

AnonX is a program for downloading and uploading encrypted files. The downloaded archive is stored for one week

Read more

Information

Users of visitor are not allowed to comment this publication.

Site Search

Site Menu


☑ Scripts Software

Calendar

«    May 2024    »
MonTueWedThuFriSatSun
 12345
6789101112
13141516171819
20212223242526
2728293031 

Advertisement

Survey on the website

Evaluate the work of the site
 

Statistics

  • +7 Total articles 5578
  • +13 Comments 3149
  • +34 Users : 4132