Threat Database Ransomware Chily Ransomware

Chily Ransomware

The Chily Ransomware is a harmful threat that could have a devastating impact on the computers it infiltrates successfully. Once activated, the threat will run an encryption process that will lock most of the files stored on the breached devices. Victims will lose access to many of their important files, including documents, PDFs, photos, images, archives, databases and many others. The locked files will have '.[Chily@Dr.Com]' appended to their names as a new extension.

When the Chily Ransomware has finished encrypting the target files, it will proceed to deliver two ransom notes with instructions for its victims. The main ransom-demanding message will be dropped as a file named 'Read Me.Hta,' while a secondary message will be displayed as a new desktop background image. The background message simply tells the affected users to establish contact with the attackers by sending an email to the three provided addresses - 'chily@tuta.io,' 'Chily@Dr.Com,' and 'chily65@proton.me.'

The main ransom note contains additional details. It states that the cybercriminals are willing to decrypt up to 3 files for free. However, the files chosen by the victims must be less than 5 MB in total size and should not contain important information. The note also warns against using third-party decryption tools, as they could cause irreversible damage to the locked files.

The full text of Chily Ransomware's note is:

'All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC.
If you want to restore them, write us to the e-mails: chily@tuta.io and Chily@Dr.Com and chily65@proton.me

(for the fastest possible response, write to all 3 mails at once!)

Write this ID at the beginning of your message:

You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 3 files for free decryption. The total size of files must be less than 5Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.'

The message displayed as a desktop background is:

'All your files have been encrypted due to a security problem with your PC.
'If you want to restore them, write us to the e-mails: chily@tuta.io and Chily@Dr.Com and chily65@proton.me'

Related Posts

Trending

Most Viewed

Loading...