Threat Database Ransomware Ransomware Ransomware

By GoldSparrow in Ransomware

The '' Ransomware is an encryption ransomware Trojan that seems to be a variant from the Globe Imposter family of ransomware. The '' Ransomware carries out a typical version of these attacks, encrypting the victim's files using a highly efficient encryption algorithm and then demanding that the victim pays a costly ransom in exchange for the decryption key necessary to restore the affected files. Since ransomware threats like the '' Ransomware are becoming more common in the wild increasingly, it is important that computer users take preemptive steps to ensure that their data and computers are protected from the '' Ransomware and similar threats.

The Dream that can Become a Nightmare

The '' Ransomware is being delivered to victims through the use of corrupted email attachments mainly. Victims may receive spam email messages with PDF or Microsoft Word files attached that use bad embedded macro scripts to download and install the '' Ransomware onto the victim's computer. The '' Ransomware behaves nearly identically to the countless other variants in its same threat family.

The '' Ransomware will use a strong encryption algorithm to encrypt the victim's files, making them inaccessible. The '' Ransomware will mark the files it encrypts with the file extension '.DREAM,' which will be added to the end of each affected file's name. The '' Ransomware will encrypt numerous file types, including images, audio, video, spreadsheets, and other user-generated files, all the while avoiding the Windows system files and applications that would prevent the victim from using the affected computer to pay the '' Ransomware's ransom. A few examples of the files that may become corrupted after attacks like the '' Ransomware include:

.3dm, .3g2, .3gp, .7zip, .aaf, .accdb, .aep, .aepx, .aet, .ai, .aif, .as, .as3, .asf, .asp, .asx, .avi, .bmp, .c, .class, .cpp, .cs, .csv, .dat, .db, .dbf, .doc, .docb, .docm, .docx, .dot, .dotm, .dotx, .dwg, .dxf, .efx, .eps, .fla, .flv, .gif, .h, .idml, .iff, .indb, .indd, .indl, .indt, .inx, .jar, .java, .jpeg, .jpg, .js, .m3u, .m3u8, .m4u, .max, .mdb, .mid, .mkv, .mov, .mp3, .mp4, .mpa, .mpeg, .mpg, .msg, .pdb, .pdf, .php, .plb, .pmd, .png, .pot, .potm, .potx, .ppam, .ppj, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .prel, .prproj, .ps, .psd, .py, .ra, .rar, .raw, .rb, .rtf, .sdf, .sdf, .ses, .sldm, .sldx, .sql, .svg, .swf, .tif, .txt, .vcf, .vob, .wav, .wma, .wmv, .wpd, .wps, .xla, .xlam, .xll, .xlm, .xls, .xlsb, .xlsm, .xlsx, .xlt, .xltm, .xltx, .xlw, .xml, .xqx, .xqx, .zip.

The '' Ransomware's Ransom Demand

The '' Ransomware will demand a ransom payment from its victims so that they can receive in return the tool that will make it possible to recover the lost data. The '' Ransomware's ransom note is contained in an HTML file named 'how_to_back_files.html.' which will be dropped on the infected computer's desktop. The full text of the '' Ransomware's ransom note reads:

To recover data you need decryptor. To get the decryptor you should:
Send 1 crypted test image or text file or documents to (Or alternate mail
In the letter include your personal ID (look at the beginning of document).
We will give you the decrypted file and assign the price for decryption all files. After we send you instruction how to pay for decrypt and after payment you will receive a decryptor and instructions. We can decrypt one file in quality the evidence that we have the decoder.'

Although the people responsible for the '' Ransomware may be capable of decrypting the victim's files, it is not guaranteed that they will help the victim recover the affected files. Furthermore, paying the '' Ransomware ransom allows these people to continue creating and distributing these threats. Instead of cooperating with them, it is important for computer users to take preventive steps to protect their computers, such as using a security software that is fully up-to-date and having file backups on unmapped places.


Most Viewed
