<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>sigma Archives - Linux Windows and android Tutorials</title>
	<atom:link href="https://www.osradar.com/tag/sigma/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osradar.com</link>
	<description>tutorials and news and Seurity</description>
	<lastBuildDate>Thu, 21 Jun 2018 20:41:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.8.12</generator>
	<item>
		<title>Sigma Ransomware Locking Infected PCs</title>
		<link>https://www.osradar.com/sigma-ransomware-locking-infected-pcs/</link>
					<comments>https://www.osradar.com/sigma-ransomware-locking-infected-pcs/#respond</comments>
		
		<dc:creator><![CDATA[Mel]]></dc:creator>
		<pubDate>Sun, 10 Jun 2018 04:51:45 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[sigma]]></category>
		<category><![CDATA[sigma ransom]]></category>
		<category><![CDATA[sigma ransomware]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=3977</guid>

					<description><![CDATA[<p>There are hundreds of ransomware running in the wild, taking over systems and asking for a ransom to unlock the system. Recently, a new ransomware – Sigma is spreading from Russia-based IP addresses along with a variety of social engineering techniques. Sigma ransomware attacking method In the present days, email scam is the most efficient [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/sigma-ransomware-locking-infected-pcs/">Sigma Ransomware Locking Infected PCs</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>There are hundreds of ransomware running in the wild, taking over systems and asking for a ransom to unlock the system. Recently, a new ransomware – Sigma is spreading from Russia-based IP addresses along with a variety of social engineering techniques.</p>
<h3>Sigma ransomware attacking method</h3>
<p><img loading="lazy" class="size-full wp-image-3978 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware.png" alt="" width="600" height="400" srcset="https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware.png 600w, https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-300x200.png 300w" sizes="(max-width: 600px) 100vw, 600px" /></p>
<p>In the present days, email scam is the most efficient and effective ways for baiting victims into traps. Sigma is spreading using malicious spam emails. The email contains a statement coming from “United States District Court” with a malicious attachment.</p>
<p><img loading="lazy" class="size-full wp-image-3980 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-spam-email.png" alt="" width="698" height="303" srcset="https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-spam-email.png 698w, https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-spam-email-300x130.png 300w, https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-spam-email-696x303.png 696w" sizes="(max-width: 698px) 100vw, 698px" /></p>
<p>&nbsp;</p>
<p>The email plays with the mind of the target with some emergency strings boasting with fear to increase the curiosity of the victim. There were total 32 Russia-based IP addresses and the attacker registered the specific domain for the campaign.</p>
<h3>Sigma working methods</h3>
<p>The main spreading method is via spam emails. The attachment contains the ransomware that will infect your system.</p>
<p>The trick is, the email tries to earn trust by password protecting the attachment. This way, it forces the target to believe that the attachment is from an authentic source (from the court), a nice mind game the attacker uses.</p>
<p>If macros are turned off on the victim’s machine, it convinces the users for turning it on for running the malicious VBScript. The script then downloads the original Sigma Ransomware payload from the C&amp;C server and saves it into “%temp” folder. The downloaded mimics “svchost.exe” as a legitimate service process.</p>
<p>In the background, the malware downloads more payloads from the server for more power over the system.</p>
<p>It also follows various clever techniques to hide from detection. It even kills itself if it understands the machine as a virtual machine or sandbox. If there’s no file to encrypt, then the malware also deletes itself. If the location of the victim is within Russia or Ukraine, the malware doesn’t infect as well.</p>
<p>In other scenarios, the malware connects with the C&amp;C server, establishes a Tor connection and encrypts the file in the system.</p>
<p>Then, you’ll see the ransom note and the asking for money to unlock your system.</p>
<p><img loading="lazy" class="size-full wp-image-3981 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-ransom-note.png" alt="" width="696" height="392" srcset="https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-ransom-note.png 696w, https://www.osradar.com/wp-content/uploads/2018/06/sigma-ransomware-ransom-note-300x169.png 300w" sizes="(max-width: 696px) 100vw, 696px" /></p>
<h3>How to stay secure</h3>
<p>If you want to stay secure, you have to be careful not to open file attachments from unknown sources, even if the source seems legitimate. Make sure that the source is real, as a sharp look from the email is enough to identify that it’s a spam.</p>
<p>Recently, security researchers discovered a super powerful spyware called InvisiMole. It’s way more sophisticated and improved than any general spyware in lots of cases. <a href="https://www.osradar.com/invisimole-spyware-taking-pictures-and-recording-audio/">Learn more about InvisiMole</a>.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/sigma-ransomware-locking-infected-pcs/">Sigma Ransomware Locking Infected PCs</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/sigma-ransomware-locking-infected-pcs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
