Ransomware
#5
I had a glance at this page: https://diskcryptor.net/wiki/Volume
and the source here https://github.com/smartinm/diskcryptor

it seems that the algo for key derivation from the password is PBKDF2-HMAC-SHA512 ($pass, $salt, 1000)
- https://github.com/smartinm/diskcryptor/...dec.c#L676
- https://github.com/smartinm/diskcryptor/....c#L70-L71

where 1000 is the hard-coded iteration round and salt is stored within the first 64 bytes of the partition/volume (not encrypted see the typedef struct _dc_header and "Salt. Random number used when deriving volume header key. " and "Encryption No" on this page https://diskcryptor.net/wiki/Volume)

This means that you could in theory derive the key and "only" check for the "DCRP" signature in the decrypted header (and if needed the crc32 checksum of the remaining decrypted bytes of the header if you get too many false positives with just the DCRP check).


Messages In This Thread
Ransomware - by galeforce9 - 12-13-2018, 07:07 PM
RE: Ransomware - by Mem5 - 12-13-2018, 07:56 PM
RE: Ransomware - by philsmd - 12-13-2018, 08:06 PM
RE: Ransomware - by galeforce9 - 12-13-2018, 08:12 PM
RE: Ransomware - by philsmd - 12-13-2018, 09:12 PM
RE: Ransomware - by Xanadrel - 12-14-2018, 12:07 AM
RE: Ransomware - by galeforce9 - 12-14-2018, 10:52 AM
RE: Ransomware - by philsmd - 12-14-2018, 11:06 AM
RE: Ransomware - by galeforce9 - 12-14-2018, 11:30 AM
RE: Ransomware - by Banaanhangwagen - 12-14-2018, 11:38 AM
RE: Ransomware - by galeforce9 - 12-14-2018, 01:05 PM
RE: Ransomware - by Nubbin - 12-17-2018, 05:58 PM
RE: Ransomware - by galeforce9 - 12-17-2018, 11:02 PM
RE: Ransomware - by Banaanhangwagen - 12-21-2018, 08:42 AM