2013-07-28 - Evolution
Urausy Ransomware - July 2013 Design Refresh - "Summer 2013 Collection"
featured in Urausy |
Patchwork of Urausy July 2013 Design Refresh 2013-07-27 (some are missing) |
No more default Windows Logo, but always pretend this is done with the help of your antivirus (if one) company :
On the Left without antivirus - On the Right with an Antivirus (logo adapt) |
Default "support" Logo 2013-08-24 |
</edit3>
countdown (as in Reveton Winter 2012),
Urausy Countdown in US Design - 2013-07 |
more government representative (not for Germany here (?!) ) and some institution (CIRCL for LU, Mandiant for US). Logos for location where you can find voucher are now rotating.
Here are the Design I was able to gather
United Arab Emirates :
Urausy AE 2013-07 |
Austria :
Urausy AT 2013-07 |
Urausy AU 2013-07 |
Urausy BE 2013-07 |
Urausy BO 2013-07 |
Urausy CA 2013-07 |
Urausy CH 2013-07 |
Urausy CY 2013-07 |
Urausy CZ 2013-07 |
Note : I did no get the one we can see in blog.botfrei.de and which is more in line with the Design Refresh (thx @ericfreyss for the link)
Urausy DE 2013-07-27 |
Thanks to Maxstar here is it :
Urausy DE 2013-07-16 |
Denmark :
Urausy DK 2013-07 |
Urausy EC 2013-07 |
Urausy ES 2013-07 |
Urausy FI 2013-07 |
Urausy FR 2013-07 |
Urausy GB 2013-07 |
Urausy GR 2013-07-29 |
Croatia :
Urausy HR 2013-07 |
Urausy HU 2013-07 |
Urausy IE 2013-07 |
Urausy IT 2013-07 |
Urausy LU 2013-07 |
Urausy LV 2013-07 |
Urausy MX 2013-07 |
Urausy NL 2013-07 |
Urausy NO 2013-07 |
Urausy NZ 2013-07 |
Urausy PL 2013-07 |
Urausy PT 2013-07 |
Urausy RO 2013-07 |
Urausy SA 2013-07 |
Urausy SE 2013-07 |
Urausy SK 2013-07 |
Urausy SL 2013-07 |
Urausy TR 2013-07 |
Urausy US 2013-07 |
Urausy UY 2013-07 |
Some Readings :
Urausy Lockscreen: Your computer will remain locked for 3 days, 11 hours and 20 minutes! - 2013-07-24 - Jaromir Horejsi - Avast
The missing link - Some lights on "Urausy" affiliate - 2013-05-29
Urausy Ransomware - Arab world targeted 2013-04-06
Sample :
Designs (OwnCloud via goo.gl) (CC BY-ND)
14f95d3bce22add22389c9ccd6a6f3f2 (OwnCloud via Goo.gl) from this fiesta attack :
Fiesta Exploit Kit pushing Urausy via CVE-2010-0188 |
<edit2 : 2013-07-29 + GR design />