Moresa Ransomware

By GoldSparrow in Ransomware

The Moresa Ransomware is a file cryptor Trojan that was discovered on April 21st, 2019. The Moresa Ransomware may be listed in AV databases as STOP-Moresa Ransomware as well. The Moresa Ransomware is not a new cyber-threat, and it has been categorized as a variant of the STOP Djvu Ransomware that is a member of the STOP Ransomware family. The Moresa Ransomware is a slightly modified copy of the STOP Djvu Ransomware, which made classification relatively easy, but the Trojan removes system backups, and the users may be unable to restore their data. The Moresa Ransomware Trojan is known to delete Shadow Volume snapshots and encipher databases. The Moresa Ransomware behaves as most threats in the class, and you can expect to lose access to audio records, video, family photos, presentations, spreadsheets, eBooks and PDFs. The cyber-threat was named after the file marker found on enciphered data, namely the '.moresa' extension. For example, 'Larharyhma-Villi yo.mp3' is renamed to 'Larharyhma-Villi yo.mp3.moresa.' The ransom message is presented as '_readme.txt' that is usually located on the desktop. The '_readme.txt' file includes the following text:

Don't worry my friend, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:

Your personal ID:
[random characters]'

Removing the Moresa Ransomware should not be too difficult when you are using a respected computer security tool. We recommend you to boot data backups instead of paying money to the ransomware actors. You may not get a decoder even if you pay hundreds of dollars. Do not forget to backup your data as often as possible and take advantage of cloud services. Threats like the Moresa Ransomware are ineffective against prepared PC users.

1 Comment

now that my computer is infected and my sdata encrypted what would your advices serve
I need a solution to restore my data not a lesson of moral


Most Viewed