Threat Database Ransomware icrypt@cock.li Ransomware

icrypt@cock.li Ransomware

By GoldSparrow in Ransomware

The icrypt@cock.li Ransomware is a variant of the Crysis ransomware. Much like other ransomware, this threat acts in a similar way, encrypting the files that are often opened by users, such as photos, audio files, documents and more. Once those are encrypted, ticrypt@cock.li Ransomware will rename them and give them the .monro extension, as well as drop a document called 'FILES ENCRYPTED.txt' as well as 'Info.hta.' The last two are ransom notes that warn the users of the encryption and give them the contact email containing the instructions on what to do. The text in the ransom notes is as follows:

'All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, wrote us to the e-mail icrypt@cock[dot]li
Write this ID in the title of your message
In case of no answer in 24 hours write us to theese emails: icrypt@cock[dot]li
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.
Free decryption as a guarantee

Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived) and files should not contain valuable information. (databases, backups, large excel sheets, etc.)'

Trending

Most Viewed

Loading...