Threat Database Ransomware 'hnumkhotep@india.com' Ransomware

'hnumkhotep@india.com' Ransomware

By GoldSparrow in Ransomware

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 8
First Seen: January 6, 2017
Last Seen: March 6, 2020
OS(es) Affected: Windows

The 'hnumkhotep@india.com' Ransomware is a ransomware Trojan that is used to force computer users to pay large sums to recover their files, which are taken hostage by this threat. The 'hnumkhotep@india.com' Ransomware belongs to the same family as the Globe Ransomware, a family that is notable for leaving very short ransom notes and for carrying out a simple, but effective ransomware attack. The 'hnumkhotep@india.com' Ransomware first appeared in the initial days of 2017. There is little to distinguish the 'hnumkhotep@india.com' Ransomware from other members of the Globe Ransomware family of encryption ransomware Trojans. The 'hnumkhotep@india.com' Ransomware may spread using corrupted email attachments that use macros to download and install corrupted content on the victim's computer. DOC files that use corrupted macros have become one of the preferred distribution methods for ransomware since Summer 2016.

Assimilating the 'hnumkhotep@india.com' Ransomware Infection

The 'hnumkhotep@india.com' Ransomware has been spread with pornographic materials, as well as through spam email messages that use social engineering tactics to trick computer users into opening the attached file. The corrupted DOC files use a macro that makes the Windows operating system download and runs an executable file hosted on a remote server. This executable file is the 'hnumkhotep@india.com' Ransomware's Trojan dropper, which drops the 'hnumkhotep@india.com' Ransomware files onto the victim's computer. This distribution method may bypass anti-virus programs, as well as the Windows User Control. A good way to prevent it from being carried out is to disable automatic execution of macros. Once the 'hnumkhotep@india.com' Ransomware is installed, it is placed in the victim's Temp folder under a random name. The 'hnumkhotep@india.com' Ransomware and other Globe Ransomware variants may be disguised as PDF files or image files of different types, a method designed to make it difficult to find the files associated with this threat.

How the 'hnumkhotep@india.com' Ransomware Carries out Its Attack

The 'hnumkhotep@india.com' Ransomware attack is straightforward, unlike other threats that include full-disk encryption or even DDoS attack. The 'hnumkhotep@india.com' Ransomware simply encrypts the victim's files using the AES-256 encryption, then encrypts the private key using the RSA-512 encryption. The decryption key is hosted on the 'hnumkhotep@india.com' Ransomware's Command and Control servers, under the control of the people responsible for this attack. Without the decryption key, it may become impossible to recover the encrypted files. The 'hnumkhotep@india.com' Ransomware takes the victim's files hostage, demanding the payment of a large ransom in exchange for the decryption key necessary to unlock the affected files. The encryption method is strong, making it impossible with current technology to decrypt the affected files. The same encryption technology that is used to keep computer users' online communications secure and software developers' intellectual property safe is applied in this case for harmful purposes.

How the 'hnumkhotep@india.com' Ransomware Demands Its Ransom

The files affected by the 'hnumkhotep@india.com' Ransomware will have the file extension '.hnumkhotep@india.com.hnumkhotep,' making it simple to find out which files have been encrypted during the 'hnumkhotep@india.com' Ransomware attack. The files that have been encrypted by the 'hnumkhotep@india.com' Ransomware will become unreadable and will show up on Windows Explorer as blank icons since Windows Explorer is incapable of creating thumbnails for these encrypted files. The people responsible for the 'hnumkhotep@india.com' Ransomware attack ask that victims email them at the 'hnumkhotep@india.com' to receive payment instructions. The ransom amount associated with the 'hnumkhotep@india.com' Ransomware is approximate $200 USD and should be paid in BitCoins. However, malware researchers advise against paying the 'hnumkhotep@india.com' Ransomware ransom. The people responsible for the attack are just as likely to ignore the victim, ask for more money, or deliver a decryption key that doesn't work as it should to restore the victim's files. Even if the result is positive, however, paying the 'hnumkhotep@india.com' Ransomware ransom allows these people to continue creating ransomware Trojans and finance other ill-minded activities.

Trending

Most Viewed

Loading...