Threat Database Ransomware Reqg Ransomware

Reqg Ransomware

Users have to be on the lookout for yet another threat spawned from the incredibly prolific STOP/Djvu malware family. It appears that STOP/Djvu has remained among the top picks of cybercriminals when it comes to generating new variants. Understandably, Reqg Ransomware lacks any major improvements over the rest of the variants from the STOP/Djvu family. However, it is still capable of causing great devastation to any system it manages to infect.

The threat executes an encryption process with the goal of locking nearly all of the files stored on the compromised device. Users will suddenly lose their access to any documents, PDFs, archives, databases and more. Gaining back the precious data would involve paying a ransom, or at least that is what the cybercriminals are hoping for - to extort their victims for money.

Technical Details

Whenever the Reqg Ransomware encrypts a file, it also marks it by changing the original filename. The threat does so by appending '.rerq' as a new extension. Upon completing its encryption routine, the malware will create a file carrying a set of instructions for the victims. This ransom note will be delivered as a text file named '_readme.txt.'

Ransom Note Overview

As a whole, the ransom message generated by Reqg Ransomware is consistent with the ransom notes of other STOP/Djvu variants. It states that to receive the decryption key needed to restore the locked data, users will have to wire the sum of $980 to the hackers. However, if the affected users reach out and establish contact with the hackers within the first 72 hours following the ransomware infection, the demanded payment will be slashed in half to $490. The hackers also promise to unlock a single file for free. The two email addresses mentioned in the note as communication channels are 'manager@mailtemp.ch' and 'managerhelper@airmail.cc.'

The full text of the note is:

'ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
htxxps://we.tl/t-jTbSQT8ApY
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
manager@mailtemp.ch

Reserve e-mail address to contact us:
managerhelper@airmail.cc

Your personal ID:'

Trending

Most Viewed

Loading...