Avast Decryption Tool for HermeticRansom 1.0.0.769
Author:
Avast
Date: 04/04/2025 Size: 3 MB License: Freeware Requires: 11|10|8|7 Downloads: 921 times ![]() Restore Missing Windows Files |
![]() Download (EXE) Download@MajorGeeks Download@MajorGeeks
|
MajorGeeks: Setting the standard for editor-tested, trusted, and secure downloads since 2001. |
Join the MajorGeeks Mailing List to get the latest updates and exclusive offers!
Avast Decryption Tool for HermeticRansom decrypts the ransomware strain accompanying the data wiper HermeticWiper that has recently been circulating in Ukraine.
The HermeticRansom ransomware avoids encrypting files in Program Files and Windows folders to keep the victim’s PC operational. The ransomware creates a 32-byte encryption key for every file designated for encryption. Files are encrypted by blocks; each block has 1048576 (0x100000) bytes. A maximum of nine blocks are encrypted. Any data past 9437184 bytes (0x900000) is left in plain text. Each block is encrypted by AES GCM symmetric cipher. After data encryption, the ransomware appends a file tail containing the RSA-2048 encrypted file key.
Encrypted file names are given extra suffix:
.[vote2024forjb@protonmail.com].encryptedJB
When done, a file named read_me.html is saved to the user’s Desktop folder:

Similar:
Which Anti-Malware App Is Best and Can It Run Alongside My Antivirus
How to Tell the Difference Between a Virus and a False Positive
How to Manage Windows Defender Antivirus Found Threats
What to Do When Your Norton or McAfee Antivirus Expire
The HermeticRansom ransomware avoids encrypting files in Program Files and Windows folders to keep the victim’s PC operational. The ransomware creates a 32-byte encryption key for every file designated for encryption. Files are encrypted by blocks; each block has 1048576 (0x100000) bytes. A maximum of nine blocks are encrypted. Any data past 9437184 bytes (0x900000) is left in plain text. Each block is encrypted by AES GCM symmetric cipher. After data encryption, the ransomware appends a file tail containing the RSA-2048 encrypted file key.
Encrypted file names are given extra suffix:
.[vote2024forjb@protonmail.com].encryptedJB
When done, a file named read_me.html is saved to the user’s Desktop folder:

Similar:

Top Downloads In Ransomware Removal




