{"id":4663,"date":"2016-03-03T10:45:52","date_gmt":"2016-03-03T16:45:52","guid":{"rendered":"https:\/\/www.poweradmin.com\/blog\/?p=4663"},"modified":"2016-09-27T08:26:43","modified_gmt":"2016-09-27T13:26:43","slug":"cryptolocker-file-extension-list","status":"publish","type":"post","link":"https:\/\/www.poweradmin.com\/blog\/cryptolocker-file-extension-list\/","title":{"rendered":"Cryptolocker File Extension List"},"content":{"rendered":"<p><span style=\"font-family: verdana, geneva, sans-serif;\">There is a <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/46361k\/list_of_ransomware_extensions_and_known_ransom\/\" target=\"_blank\" rel=\"nofollow\">thread on Reddit<img class=\"extlink-icon\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/plugins\/external-links-nofollow-open-in-new-tab-favicon\/images\/extlink.png\"><\/a> that lists many known Cryptolocker file extensions (both the extension that the newly-encrypted file gets, and the ransom note file).<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif;\"><a href=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2016\/05\/file-sight-paste-extensions.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-4664 alignright\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2016\/05\/file-sight-paste-extensions-300x236.png\" alt=\"file-sight-paste-extensions\" width=\"300\" height=\"236\" srcset=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2016\/05\/file-sight-paste-extensions-300x236.png 300w, https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2016\/05\/file-sight-paste-extensions.png 592w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\"><\/a>A number of customers have asked to be able to more easily paste this list of file names into the list of file types to watch, which is now possible (currently in the <a href=\"https:\/\/www.poweradmin.com\/products\/file-sight\/download\/preview\/?ref=blog\">6.3 Preview build<\/a>).<\/span><\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif;\">Using lists like this\u00a0can help catch existing Cryptolocker variants, but hackers are always adapting. \u00a0Detecting behavior is better, which we mentioned in a previous blog post is <a title=\"Early Detection and Prevention of CryptoLocker\" href=\"https:\/\/www.poweradmin.com\/blog\/crypto-locker-early-detection-and-prevention\/\">what some of our customers are doing<\/a>.<\/span><\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif;\">The current list is below. \u00a0Note that README.txt is in the list which you\u00a0will have to decide if you want to alert on.<\/span><\/p>\n<h3><span style=\"font-family: verdana, geneva, sans-serif;\"><strong>Cryptolocker Encrypted File Extensions<\/strong><\/span><\/h3>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">*.ecc<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.ezz<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.exx<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.zzz<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.xyz<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.aaa<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.abc<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.ccc<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.vvv<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.xxx<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.ttt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.micro<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.encrypted<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.locked<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.crypto<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*_crypt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.crinf<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.r5a<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.XRNT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.XTBL<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.crypt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.R16M01D05<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.pzdc<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.good<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.LOL!<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.OMG!<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.RDM<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.RRK<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.encryptedRSA<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.crjoker<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.EnCiPhErEd<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.LeChiffre<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.keybtc@inbox_com<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.0x0<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.bleep<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.1999<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.vault<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.HA3<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.toxcrypt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.magic<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.SUPERCRYPT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.CTBL<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.CTB2<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*.locky\u00a0<\/span><\/p>\n<h3><span style=\"font-family: verdana, geneva, sans-serif;\"><strong>Cryptolocker Ransom Filenames<\/strong><\/span><\/h3>\n<p><span style=\"font-family: 'courier new', courier, monospace;\">*HELPDECRYPT.TXT<br>\n *HELP_YOUR_FILES.TXT<br>\n *HELP_TO_DECRYPT_YOUR_FILES.txt<br>\n *RECOVERY_KEY.txt<br>\n *HELP_RESTORE_FILES.txt<br>\n *HELP_RECOVER_FILES.txt<br>\n *HELP_TO_SAVE_FILES.txt<br>\n *DecryptAllFiles.txt<br>\n *DECRYPT_INSTRUCTIONS.TXT<br>\n *INSTRUCCIONES_DESCIFRADO.TXT<br>\n *How_To_Recover_Files.txt<br>\n *YOUR_FILES.HTML<br>\n *YOUR_FILES.url<br>\n *encryptor_raas_readme_liesmich.txt<br>\n *Help_Decrypt.txt<br>\n *DECRYPT_INSTRUCTION.TXT<br>\n *HOW_TO_DECRYPT_FILES.TXT<br>\n *ReadDecryptFilesHere.txt<br>\n *Coin.Locker.txt _secret_code.txt<br>\n *About_Files.txt<br>\n *Read.txt<br>\n <span style=\"color: #ff0000;\">*ReadMe.txt<\/span><br>\n *DECRYPT_ReadMe.TXT<br>\n *DecryptAllFiles.txt <\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*FILESAREGONE.TXT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*IAMREADYTOPAY.TXT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*HELLOTHERE.TXT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*READTHISNOW!!!.TXT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*SECRETIDHERE.KEY <\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*IHAVEYOURSECRET.KEY<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*SECRET.KEY<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*HELPDECYPRT_YOUR_FILES.HTML<br>\n *help_decrypt_your_files.html<br>\n *HELP_TO_SAVE_FILES.txt<br>\n *RECOVERY_FILES.txt<br>\n *RECOVERY_FILE.TXT<br>\n *RECOVERY_FILE*.txt <\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*HowtoRESTORE_FILES.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*HowtoRestore_FILES.txt<br>\n *howto_recover_file.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*restorefiles.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*howrecover+*.txt<br>\n *_how_recover.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*recoveryfile*.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*recoverfile*.txt <\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*recoveryfile*.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*Howto_Restore_FILES.TXT<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*help_recover_instructions+*.txt<\/span><br>\n <span style=\"font-family: 'courier new', courier, monospace;\">*_Locky_recover_instructions.txt<\/span><\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is a thread on Reddit that lists many known Cryptolocker file extensions (both the extension that the newly-encrypted file gets, and the ransom note file). \u00a0 A number of customers have asked to be able to more easily paste this list of file names into the list of file types to watch, which is [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":4664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,13,6,8],"tags":[],"class_list":["post-4663","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptolocker","category-pc-security","category-tech","category-windows"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/4663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/comments?post=4663"}],"version-history":[{"count":5,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/4663\/revisions"}],"predecessor-version":[{"id":4873,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/4663\/revisions\/4873"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/media\/4664"}],"wp:attachment":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/media?parent=4663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/categories?post=4663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/tags?post=4663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}