Threat Database Ransomware Angry Ransomware

Angry Ransomware

Cybercriminals have created another threatening malware variant based on the ever-growing VoidCrypt Ransomware family. Tracked by infosec researchers as the Angry Ransomware, the threat is capable of leaving the infected devices in a dire state. Indeed, victims will lose access to the majority of the data stored on the system with any documents, PDFs, photos, archives, databases, etc., all being encrypted with an uncrackable cryptographic algorithm.

It is likely that the first signs of the Angry Ransowmare's presence that the affected users will notice are going to be the changes made by the threat to the original names of the encrypted files. The Angry Ransomware will first append an ID string generated for the specific victim. The malware will then add an email address - 'senha116@keemail.me' controlled by its operators. Finally, '.Angry' will be appended as a new file extension. When all target file types on the breached device have been processed, the Angry Ransomware will create a text file named 'unlock-info.txt.' As its name suggests, the file contains a ransom note with instructions from the attackers.

The ransom-demanding message tells users that they must pay a ransom to the cybercriminals to receive a supposed decryptor tool. The note fails to mention the exact sum demanded by the hackers, but it does state that only payments made in Bitcoin will be accepted. To receive additional instructions, the affected users are expected to contact the threat actors via the two email addresses found in the note - 'senha116@keemail.me' and 'senha120@onionmail.org.' Apparently, before paying the ransom, victims can send a single file to the cybercriminals to be decrypted for free. According to the note, the chosen file must not contain any important information and should not exceed 1MB in size.

Angry Ransomware's full ransom note is:

'All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail; senha116@keemail.me
Write this ID in the title of your message : -
In case of no answer in 24 hours write us to theese e-mails: senha120@onionmail.org
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
'

Related Posts

Trending

Most Viewed

Loading...