Threat Database Ransomware Irfk Ransomware

Irfk Ransomware

Cybersecurity researchers have detected another threatening variant from the prolific STOP/Djvu ransomware family. The new threat is named Irfk Ransomware and although it doesn't exhibit any significant improvement over the other variants of the STOP/Djvu family, its ability to cause damage should not be underestimated. More examples of ransomware threats are Hep, Mallox and Rugi.

If Irfk is deployed on the targeted devices successfully, it will initiate a strong encryption process. As a result, the vast majority of files stored there - documents, PDFs, archives, databases, etc., will be rendered unusable and inaccessible. All affected files will have '.irfk' appended to their original names as a new file extension. Upon encrypting all suitable files, the threat will proceed to drop its ransom note. The instructions from the attackers will be placed inside a newly-created text file named '_readme.txt.'

Irfk Ransomware's Demands

It appears the Irfk Ransomware uses the same template for its ransom-demanding message as the rest of the threats from this family. It states that the sum victims must pay to receive the required decryption key and software tool is $980. However, if the users establish contact within the first 72 hours of the ransomware attack, the price will supposedly be dropped down by 50% to $490.

The note also mentions that the hackers are willing to demonstrate their ability to restore the locked data by decrypting a signal non-important file for free. According to the note, users will have to message one of the two provided email addresses - 'manager@mailtemp.ch' and 'helprestoremanager@airmail.cc.'

The entire set of instructions dropped by Irfk Ransomware is:

'ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-dFmA3YqXzs
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
manager@mailtemp.ch

Reserve e-mail address to contact us:
helprestoremanager@airmail.cc

Your personal ID:'

Trending

Most Viewed

Loading...