{"id":2912,"date":"2021-05-31T22:14:21","date_gmt":"2021-06-01T03:14:21","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2912"},"modified":"2021-05-31T22:14:21","modified_gmt":"2021-06-01T03:14:21","slug":"zeppelin-ransomware-targetting-large-companies","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/","title":{"rendered":"Zeppelin Ransomware targetting large companies"},"content":{"rendered":"\n<p>Discovered and seen for the first time in the first ten days of November 2019. ZEPPELIN is a malicious program and a variant of the Buran ransomware. Systems infected with this malware have their data encrypted so that the cybercriminals behind the infection can demand payment for the decryption tools \/ software. During the encryption process, ZEPPELIN adds file names with a random extension, using the hexadecimal numbering system. <\/p>\n\n\n\n<p>It is said to be the latest variant of the Vega lockers. But what sets it apart from its predecessors is that it targets regions of Europe and the US That&#8217;s pretty weird. Vega lockers used to primarily target Russia. But Zeppelin ends its function if it is in systems of Russia or associated regions.<\/p>\n\n\n\n<p>The text file contains the ransom message, which informs victims that their data has been encrypted. It claims that all important data (such as documents, photos, databases, and other files) has been encrypted. The message goes on to say that manual decryption is impossible and the only way to decrypt files is by purchasing a unique private key from the ZEPPELIN developers. An email address is included to establish contact. Furthermore, users are cautioned not to rename encrypted files or attempt to decrypt them with third party software as this can lead to permanent data loss.<\/p>\n\n\n\n<p><strong><em>Zeppelin can be deployed in EXE format in a DLL or run through PowerShell and can be configured with different features:<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Registration of the IP and location of the victims.<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Persistent on reboot.<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Remove of backup copies.<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Stopping specific processes.<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Unlocks files that are running or locked to be able to encrypt them. <\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Auto-delete: deletes the executable and registry entries.<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Privilege elevation &#8211; The malware will attempt to elevate privileges at startup.<\/p>\n\n\n\n<p>Unfortunately, in most cases of ransomware infections, decryption without the involvement of those responsible for the encryption is impossible, unless the malware in question is still under development and \/ or has certain flaws \/ bugs. Regardless, you are strongly advised not to contact or comply with the ransom demands of cyber criminals as we always say as, it is never safe to get your information back.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/darkside-is-a-malware-that-is-aimed-at-big-companies\/\">Darkside is a Malware that is aimed at big companies<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/cyber%e2%80%8b%e2%80%8battacks-that-financial-companies-have-suffered\/\">Cyber\u200b\u200battacks that financial companies have suffered<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Discovered and seen for the first time in the first ten days of November 2019. ZEPPELIN is a malicious program and a variant of the Buran ransomware. Systems infected with this malware have their data encrypted so that the cybercriminals behind the infection can demand payment for the decryption tools \/ software. During the encryption [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2914,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,16],"tags":[36,105],"class_list":["post-2912","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-ransomware","tag-cybersecurity","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Zeppelin Ransomware targetting large companies - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Ransomware is always on the lookout, today it&#039;s time to see one that targets large companies which is known as Zeppelin ransomware......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Zeppelin Ransomware targetting large companies - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Ransomware is always on the lookout, today it&#039;s time to see one that targets large companies which is known as Zeppelin ransomware......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-01T03:14:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Zeppelin.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"840\" \/>\n\t<meta property=\"og:image:height\" content=\"390\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Zeppelin Ransomware targetting large companies\",\"datePublished\":\"2021-06-01T03:14:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/\"},\"wordCount\":380,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Zeppelin.jpg\",\"keywords\":[\"Cybersecurity\",\"Ransomware\"],\"articleSection\":[\"Cybersecurity\",\"Ransomware\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/\",\"name\":\"Zeppelin Ransomware targetting large companies - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Zeppelin.jpg\",\"datePublished\":\"2021-06-01T03:14:21+00:00\",\"description\":\"Ransomware is always on the lookout, today it's time to see one that targets large companies which is known as Zeppelin ransomware......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Zeppelin.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Zeppelin.jpg\",\"width\":840,\"height\":390},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/zeppelin-ransomware-targetting-large-companies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Zeppelin Ransomware targetting large companies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Zeppelin Ransomware targetting large companies - Truxgo Server Blog","description":"Ransomware is always on the lookout, today it's time to see one that targets large companies which is known as Zeppelin ransomware......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/","og_locale":"es_MX","og_type":"article","og_title":"Zeppelin Ransomware targetting large companies - Truxgo Server Blog","og_description":"Ransomware is always on the lookout, today it's time to see one that targets large companies which is known as Zeppelin ransomware......","og_url":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-01T03:14:21+00:00","og_image":[{"width":840,"height":390,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Zeppelin.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Zeppelin Ransomware targetting large companies","datePublished":"2021-06-01T03:14:21+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/"},"wordCount":380,"commentCount":2,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Zeppelin.jpg","keywords":["Cybersecurity","Ransomware"],"articleSection":["Cybersecurity","Ransomware"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/","url":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/","name":"Zeppelin Ransomware targetting large companies - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Zeppelin.jpg","datePublished":"2021-06-01T03:14:21+00:00","description":"Ransomware is always on the lookout, today it's time to see one that targets large companies which is known as Zeppelin ransomware......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Zeppelin.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Zeppelin.jpg","width":840,"height":390},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/zeppelin-ransomware-targetting-large-companies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Zeppelin Ransomware targetting large companies"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2912","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2912"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2912\/revisions"}],"predecessor-version":[{"id":2929,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2912\/revisions\/2929"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2914"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2912"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2912"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2912"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}