User avatar
Jared
Forum Admin
Posts: 3492
Joined: Mon Jan 12, 2015 12:32 pm
Location: Providence, RI
Contact: Website Facebook Twitter Skype YouTube Google+

Android Ransomware that Encrypts JPGs and Video

Thu Feb 28, 2019 1:23 pm

So I've got a rather odd case here that showed up. I've never seen anything quite like it. It's a microSD card from an Android device. Suddenly the pictures all seemed corrupted to the user. The card and filesystem all seem normal, but the opening signature of all the jpgs and video files on the card look like this:

Android Ransomware.jpg


As you can see there is some variance in the opening signature, likely a checksum or key of sorts. But some elements such as the second line of 03 00 00 02 00 00 10 00 00 02 8C 2D 04 09 03 01 as well as the visible code "CONSOLE" are consistent. This is then followed by a few sectors of all zeros before random looking data begins (as you'd expect in a jpg or video).

Has anyone ever come across such an Android ransomware or have any idea which one this might actually be? There doesn't seem to be any ransom notes left behind anywhere.

User avatar
Joep
Data Recovery Noob
Posts: 15
Joined: Wed Jul 12, 2017 3:11 pm

Android Ransomware that Encrypts JPGs and Video

Mon Aug 12, 2019 9:10 am

I see these all the time. I think it is Android file based encryption. Entropy in such files also suggests encryption.

No one was able to point me anywhere, I asked several places, here's one: https://www.reddit.com/r/Smartphonefore ... ncryption/

and here: https://www.reddit.com/r/datarecovery/c ... ncryption/

In an Android developer forum suggested it was Android file based encryption. Without any further info to go on.

And it is my impression it was mostly Samsungs but that may simply be because it is a popular brand.

User avatar
Joep
Data Recovery Noob
Posts: 15
Joined: Wed Jul 12, 2017 3:11 pm

Android Ransomware that Encrypts JPGs and Video

Wed Aug 14, 2019 12:05 pm

I only noticed now your post was from months ago. Curious: Did you ever find more info on this?

User avatar
Jared
Forum Admin
Posts: 3492
Joined: Mon Jan 12, 2015 12:32 pm
Location: Providence, RI
Contact: Website Facebook Twitter Skype YouTube Google+

Android Ransomware that Encrypts JPGs and Video

Thu Aug 15, 2019 8:54 am

No, I explained to the customer that it would end up being an expensive custom job to even attempt recovery and he decided it wasn't worth pursuing it further.

So, I never figuring it out.

User avatar
Joep
Data Recovery Noob
Posts: 15
Joined: Wed Jul 12, 2017 3:11 pm

Android Ransomware that Encrypts JPGs and Video

Thu Aug 15, 2019 10:41 am

I see, thanks for the answer though.

Return to “Cyber Security & Malware”

Who is online

Users browsing this forum: No registered users and 0 guests