By GoldSparrow in Ransomware

The Ransed Ransomware is an encryption ransomware Trojan. These threat infections are designed to encrypt the victims' data, and then demand a ransom payment from the victim in exchange for the means to recover the affected files. The most common way in which the Ransed Ransomware may be delivered is through the use of corrupted email attachments that make use of corrupted macro scripts to download and install the Ransed Ransomware on the victim's computer. Once the Ransed Ransomware enters a computer, it will encrypt the victim's data and carry out the rest of its attack.

The Peculiar Ransom Message Displayed by the Ransed Ransomware

After the Ransed Ransomware manages to infiltrate a computer, it will encrypt the victim's files using the AES and RSA encryptions. The Ransed Ransomware will add the file extension 'ransed' to the end of each affected file's name. Since the Ransed Ransomware uses a strong encryption algorithm, the files encrypted in the attack may not be recoverable without the decryption key. Once the Ransed Ransomware has encrypted victims' data, it will display a ransom note in the form of a pop-up program window. This ransom note, with a black background, contains the following nonsensical text:

'Imfao u just got rekt by RANSED it'd be a shame if i encrypted your files...
aaand it's done.
u might be worried and so do I.
if u no pay say goodbye to ur files
rip u m8
lol w8 u can recover ur files
it will cost u 25 dollars 🙂
btw u pay with BITCOIN k?
head over to that thing.....>
and go to the 'Unlock' tab
gg ez

The Ransed Ransomware and Its Payment Process

The Ransed Ransomware ransom of $25 USD is not high particularly, considering that most ransomware Trojans demand payment that ranges between $500 and $1500 USD. However, there is no evidence that the people responsible for the Ransed Ransomware are keeping their word and providing the decryption key to computer users that make the ransom payment. PC security researchers advise computer users to make sure that they protect their data with a backup system rather than paying the ransom since paying these fees also allows con artists to continue creating and developing these threats. Apart from its ransom note, the Ransed Ransomware also will include information on what Bitcoin is and how to purchase it since this is the preferred method used for these payments due to its anonymous nature. The following is the text that appears when computer users click on the link next to 'head over to that thing:'

'wut is bitcoin
u dont know what is bitcoin? rly?
Bitcoin is a form of digital currency, created and held electronically. No one controls it. Bitcoins aren't printed, like dollars or euros - they're produced by people, and increasingly businesses, running computers all around the world, using software that solves mathematical problems.
It's the first example of a growing category of money known as cryptocurrency.
What makes it different from normal currencies?
Bitcoin can be used to buy things electronically. In that sense, it's like conventional dollars, euros, or yen, which are also traded digitally.
However, bitcoin's most important characteristic, and ...

how can i get bitcoins
Surprisingly, it's still not cosy to buy bitcoins with your credit card or PayPal, depending on your jurisdiction.
This is because such transactions can easily be reversed with a phone call to the card company (ie 'chargebacks'). Since it's hard to prove any goods changed hands in a transfer of bitcoins, exchanges avoid this payment method and so do most private sellers.
However, the options have recently grown for consumers in some countries.
In the US, Coinbase, and Circle offer purchases with credit cards. Bittylicious, CoinCorner and Coinbase offer this service in the UK, accepting 3D Secure-enabled credit and debit cards on the Visa and MasterCard networks…'

Dealing with the Ransed Ransomware

The best shield against ransomware Trojans like the Ransed Ransomware is having backup copies of your files. A reliable security program also should be used to ensure that you can remove the Ransed Ransomware or block it from being installed. Since the Ransed Ransomware can be delivered using spam email attachments, learning how to handle this content safely also is essential.


