Threat Database Ransomware Health Ransomware

Health Ransomware

The Health Ransomware appends the following pattern to the files it affects:

File_name.[file_extension].id[random_characters].[loading66@tuta.io].health

The random characters comprise the victim’s unique ID, while loading66@tuta.io should presumably be the crooks' contact address. The latter also is present in the ransom note, which shows up both as a text ("info.txt") and an HTML ("info.hta") file.

The .hta note is detailed and expressive:

'All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail: loading66@tuta.io

Write this ID in the title of your message 1E857D00-3289

Or text in the messenger Telegram: @Help24_7

You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.

Free decryption as guarantee

Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins

The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.

hxxps://localbitcoins.com/buy_bitcoins

Also you can find other places to buy Bitcoins and beginners guide here:

hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!

Do not rename encrypted files.

Do not try to decrypt your data using third party software, it may cause permanent data loss.

Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

The text note is much more concise and to the point:

!!!All of your files are encrypted!!!

To decrypt them send e-mail to this address: loading66@tuta.io.

Our online operator is available in the messenger Telegram: @Help24_7'

The required ransom amount varies depending on how fast you pay. The ransom note does not specify any concrete numbers, which leads us to suggest that you would not know how much to pay unless you contact the crooks at play using either of the two provided communication channels. We recommend against paying them a single dime because of the uncertainty of the outcome. Cybercriminals have become notorious for breaking their decryption promises, and they've been building upon their reputation to this day.

The Health Ransomware is a crypto-virus belonging to the popular Phobos Ransomware family. At present, there is no working decryption tool for Health Ransomware. It's a severe threat you should avoid at any cost. To prevent any data loss in the event of a Health Ransomware attack, don't forget to back up your data on external drives regularly. Should you still get hit by the Health Ransomware, use professional anti-malware tools to remove it from your system, then make sure to get real-time protection against further potential infections before restoring your data from previous backups.

Related Posts

Trending

Most Viewed

Loading...