'Bitcoinrush@imail.com' Ransomware
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Threat Level: | 100 % (High) |
| Infected Computers: | 4 |
| First Seen: | August 30, 2016 |
| Last Seen: | October 24, 2025 |
| OS(es) Affected: | Windows |
The Bitcoinrush@imail.com Ransomware falls into the category of a cryptomalware that is designed to encrypt the data of the user and demand ransom for the release of a decryptor. The Bitcoinrush@imail.com Ransomware is an Encryption Trojan that may be delivered to users via spam mail and corrupted links. The payload of the Bitcoinrush@imail.com Ransomware may be packed as a ZIP, RAR, PDF and DOCX file. The Bitcoinrush@imail.com Ransomware is a variant of the Troldesh Ransomware, and its operators may push their product as a message from your bank and a payment notification from Amazon. That way, many users may be willing to open spam emails from unknown senders and run the Bitcoinrush@imail.com Ransomware.
Computer users that are infected with the Bitcoinrush@imail.com Ransomware will find the ransom note in "How to decrypt your files.txt" that is placed on the desktop. The Bitcoinrush@imail.com Ransomware is programmed to encrypt the contents of the default user library and targeted file types on connected drives. An analysis of the Bitcoinrush@imail.com Ransomware shows that it can lock the following data containers:
.3GP, .7Z, .APK, .AVI, .BMP, .CDR, .CER, .CHM, CONF, .CSS, .CSV, .DAT, .DB, .DBF, .DJVU, .DBX, .DOCM, ,DOC, .EPUB, .DOCX .FB2, .FLV, .GIF, .GZ, .ISO .IBOOKS,.JPEG, .JPG, .KEY, .MDB .MD2, .MDF, .MHT, .MOBI .MHTM, .MKV, .MOV, .MP3, .MP4, .MPG .MPEG, .PICT, .PDF, .PPS, .PKG, .PNG, .PPT .PPTX, .PPSX, .PSD, .RAR, .RTF, .SCR, .SWF, .SAV, .TIFF, .TIF, .TBL, .TORRENT, .TXT, .VSD,.WMV, .XLS, .XLSX, .XPS, .XML, .CKP, ZIP, .JAVA, .PY, .ASM, .C, .CPP, .CS, .JS, .PHP, .DACPAC, .RBW, .RB, .MRG, .DCX, .DB3, .SQL, .SQLITE3, .SQLITE, .SQLITEDB, .PSD, .PSP, .PDB, .DXF, .DWG, .DRW, .CASB, .CCP, .CAL, .CMX, .CR2.
The Bitcoinrush@imail.com Ransomware will add a custom extension to your files that looks like this .id-[eight random characters].bitcoinrush@aol.com.xtbl. For example, predator.jpeg will be converted to predator.jpeg.id-[NLLM4N7X].bitcoinrush@aol.com.xtbl. The operators of the Bitcoinrush@imail.com Ransomware do rely on the victim's feedback to negotiate the ransom. The note "How to decrypt your files.txt" has the following message:
'DECRYPT FILES EMAIL Bitcoinrush@aol.com or Bitcoinrush@imail.com'
Affected PC users are likely to be directed to deliver payment via the Bitcoin digital cryptocurrency. In most cases, the ransom is between 0,5 BTC and 1,5 BTC. You might have to transfer from $290 to $860 to receive a decryptor. Experts advise against paying the ransom because you may not receive a working decryption software and lose your money and files. We recommend using backup images and archives to recover your data. But first, clean your PC with a trusted anti-malware tool. You should consider integrating services like Google Drive and Dropbox into your system to make cryptomalware less of a threat.
SpyHunter Detects & Remove 'Bitcoinrush@imail.com' Ransomware
File System Details
| # | File Name | MD5 |
Detections
Detections: The number of confirmed and suspected cases of a particular threat detected on
infected computers as reported by SpyHunter.
|
|---|---|---|---|
| 1. | file.exe | 606e63272566893ecd5b1801bf2191b8 | 2 |