{"id":2013,"date":"2021-02-22T20:03:30","date_gmt":"2021-02-23T01:03:30","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2013"},"modified":"2021-02-22T20:03:31","modified_gmt":"2021-02-23T01:03:31","slug":"vovalex-ransomware-posing-as-windows-utilities","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/","title":{"rendered":"Vovalex &#8211; Ransomware posing as Windows utilities"},"content":{"rendered":"\n<p>A new ransomware called Vovalex is being distributed via pirated software masquerading as popular Windows utilities such as CCleaner. When it comes down to it, all ransomware infections boil down to the same function: encrypting files on a device and then sending a ransom note demanding payment in some way.<\/p>\n\n\n\n<p>According to the security researchers who discovered it, it could be the first ransomware written in D. It should be noted that the D language is fed by others, mainly C ++, with some additions that offer it greater practicality. Vovalex, according to the researchers behind its discovery, would be the first ransomware written in this language. It was first discovered by MalwareHunterTeam.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does Vovalex do and how does it work?<\/h2>\n\n\n\n<p>This threat runs as if it were a legitimate installer. For example from the CCleaner program, as we mentioned earlier. It will then be copied to the system and will begin to encrypt files on the drive and add the .vovalex extension to all of them. Once it has finished its process, and as usual in malware of this type, it adds a ransom note on the Windows Desktop that it will call README.VOVALEX.txt. A simple text file where it informs the victim of how to regain control of the files.<\/p>\n\n\n\n<p>Fortunately, Vovalex is not widely distributed at this time. If threat actors are associated with fake crack sites and adware bundles, similar to how ransomware is distributed, then we may have a bigger problem on our hands, so the best we can do is download only from official pages, as we always say, be very careful when surfing the net and more care when downloading.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/rogue-software-fake-security-programs\/\">Rogue Software \u2013 Fake Security Programs<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new ransomware called Vovalex is being distributed via pirated software masquerading as popular Windows utilities such as CCleaner. When it comes down to it, all ransomware infections boil down to the same function: encrypting files on a device and then sending a ransom note demanding payment in some way. According to the security researchers [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2014,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2013","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vovalex - Ransomware posing as Windows utilities - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Vovalex a new ransomware that is strong with a very important peculiarity and which we must be careful and you know what it does...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vovalex - Ransomware posing as Windows utilities - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Vovalex a new ransomware that is strong with a very important peculiarity and which we must be careful and you know what it does...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-23T01:03:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-02-23T01:03:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/vovalez.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"417\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Vovalex &#8211; Ransomware posing as Windows utilities\",\"datePublished\":\"2021-02-23T01:03:30+00:00\",\"dateModified\":\"2021-02-23T01:03:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/\"},\"wordCount\":293,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/vovalez.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/\",\"name\":\"Vovalex - Ransomware posing as Windows utilities - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/vovalez.jpg\",\"datePublished\":\"2021-02-23T01:03:30+00:00\",\"dateModified\":\"2021-02-23T01:03:31+00:00\",\"description\":\"Vovalex a new ransomware that is strong with a very important peculiarity and which we must be careful and you know what it does...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/vovalez.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/vovalez.jpg\",\"width\":800,\"height\":417},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vovalex-ransomware-posing-as-windows-utilities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vovalex &#8211; Ransomware posing as Windows utilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vovalex - Ransomware posing as Windows utilities - Truxgo Server Blog","description":"Vovalex a new ransomware that is strong with a very important peculiarity and which we must be careful and you know what it does...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/","og_locale":"es_MX","og_type":"article","og_title":"Vovalex - Ransomware posing as Windows utilities - Truxgo Server Blog","og_description":"Vovalex a new ransomware that is strong with a very important peculiarity and which we must be careful and you know what it does...","og_url":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-02-23T01:03:30+00:00","article_modified_time":"2021-02-23T01:03:31+00:00","og_image":[{"width":800,"height":417,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/vovalez.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Vovalex &#8211; Ransomware posing as Windows utilities","datePublished":"2021-02-23T01:03:30+00:00","dateModified":"2021-02-23T01:03:31+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/"},"wordCount":293,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/vovalez.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/","url":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/","name":"Vovalex - Ransomware posing as Windows utilities - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/vovalez.jpg","datePublished":"2021-02-23T01:03:30+00:00","dateModified":"2021-02-23T01:03:31+00:00","description":"Vovalex a new ransomware that is strong with a very important peculiarity and which we must be careful and you know what it does...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/vovalez.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/vovalez.jpg","width":800,"height":417},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Vovalex &#8211; Ransomware posing as Windows utilities"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2013","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2013"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2013\/revisions"}],"predecessor-version":[{"id":2018,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2013\/revisions\/2018"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2014"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}