Udla Ransomware

Udla Ransomware Description

A threat belonging to the STOP/Djvu family, the Udla Ransomware can cause significant damage to the system it manages to compromise. Ransomware threats are created with the purpose of encrypting the victim's data and leaving it in an unusable state. Typically, they use strong cryptographic algorithms to ensure that the locked files cannot be recovered without assistance from the attackers.

As part of its actions, the Udla Ransomware will modify the names of all locked documents, PDFs, archives, databases and more. The specific file extension used to mark the encrypted data is '.udla.' In addition, a text file named '_readme.txt' will be created on the breached devices. The file will carry a ransom note with instructions from the cybercriminals.

Ransom Note's Overview

The ransom-demanding message left by Udla doesn't deviate from the established STOP/Djvu pattern. The attackers state that to send a decryptor tool and the necessary decryption key victims must pay them a ransom of $980. That initial sum can apparently be brought down by 50% to $490 if the affected users initiate communication with the hackers in the first 72 hours of the Udla Ransomware infection.

Two email addresses that can be used to message the threat actors can be found in the note. The main one is 'support@sysmail.ch,' while 'supportsys@airmail.cc' is relegated to the role of a backup address. Victims are also told that they can attach a single encrypted file to be decrypted for free.

The entire text of Udla Ransomware's note is:

'ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-fnn5kv33Vv
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@sysmail.ch

Reserve e-mail address to contact us:
supportsys@airmail.cc

Your personal ID:'