Threat Database Ransomware IWAN Ransomware

IWAN Ransomware

The IWAN Ransomware is a new threat used in ransomware operations. The attackers aim to deploy it on the targeted computers and then lock the victim's files stored there. IWAN is capable of encrypting a large array of file types, including documents, PDFs, archives, databases and more. Affected users will no longer be able to access the locked files.

Analysis has revealed that IWAN is part of the STOP/Djvu malware family. As such, it exhibits the typical characteristics of a variant from this ransomware family. The IWAN Ransomware appends its own file extension to the affected files - '.iwan,' and then creates a text file named '_readme.txt' that contains a ransom note.

Threat's Demands

The note dropped by IWAN Ransomware follows the pattern associated with the STOP/Djvu threats. It states that victims will have to pay $980 to the attackers if they want to restore the locked data. However, if users establish contact with the cybercriminals within the first 72 hours of the ransomware attack, the ransom will supposedly be slashed in half to $490.

Victims also are allowed to send 1 encrypted file that will be unlocked and returned. The file must not contain any valuable information. The ransom note mentions two email addresses that can be used for communication with the hackers - 'manager@mailtemp.ch' and 'helpmanager@airmail.cc.'

The entire text contained in the '_readme.txt' file is:

'ATTENTION!

Don’t worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-fhnNOAYC8Z
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don’t get answer more than 6 hours.

To get this software you need write on our e-mail:
manager@mailtemp.ch

Reserve e-mail address to contact us:
helpmanager@airmail.cc
.'

Related Posts

Trending

Most Viewed

Loading...