Threat Database Ransomware 1more Ransomware

1more Ransomware

A new hurtful threat tracked as the 1more Ransomware is capable of encrypting numerous file types, effectively locking users from accessing their own data. Important documents, PDFs, databases, archives, images, photos, etc., will be locked via an uncrackable cryptographic algorithm and left in an unusable state. The operators of the 1more Ransomware will then try to extort their victims for money, in exchange for a promise to help with the restoration of the files.

Whenever the 1more Ransomware encrypts a file, it also changes that file's name to a significant degree. First, the 1more Ransomware appends an ID string generated for the specific victim. Then, it adds the '1moredec@gmail.com' email address, which is controlled by the attackers. Finally, '.1more' is placed as a new file extension. When the threat has completed the encryption of all targeted file types, it will create a text file named 'unlock-info.txt' on the infected device. Inside this file, victims will find a ransom note with instructions from the hackers.

The ransom-demanding message states that the amount of the demanded ransom will depend on the time it takes the victims of the threat to contact the cybercriminals. Two email addresses are mentioned in the note - the main one is '1moredec@gmail.com,' while '1moredec@mailfence.com' serves as a backup. The threat actors express their willingness to decrypt 1 file for free. However, the chosen file must not be above 1MB in size and should not contain any valuable information.

The full text of 1more Ransomware's note is:

'All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail; 1moredec@gmail.com
Write this ID in the title of your message :
In case of no answer in 24 hours write us to theese e-mails: 1moredec@mailfence.com
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
'

The 1more Ransomware belongs to the VoidCrypt Ransomware family.

Trending

Most Viewed

Loading...