Threat Database Ransomware YOUR_LAST_CHANCE Ransomware

YOUR_LAST_CHANCE Ransomware

By CagedTech in Ransomware

With the growing popularity of ransomware threats, cybersecurity researchers spot more and newer file-encrypting Trojans daily. One of the last uncovered ransomware threats that have emerged is the dramatically named YOUR_LAST_CHANCE Ransomware. This newly discovered ransomware threat is a variant of the Cry36 Ransomware.

Infection and Encryption

It is not clear what the propagation method used in the spreading of the YOUR_LAST_CHANCE Ransomware is. Some experts believe that the authors of the YOUR_LAST_CHANCE Ransomware may be employing some of the most common infection vectors like the spam email campaigns, infected pirated applications downloaded from unsecured websites, and bogus software updates. Once the YOUR_LAST_CHANCE Ransomware finds its way into your system, it will start the attack by implementing a scan. The scan’s goal is to determine the location of the files, which the YOUR_LAST_CHANCE Ransomware will lock. Next, the YOUR_LAST_CHANCE Ransomware will start the encryption process. When this data-locking Trojan encrypts a file, it changes its filename by adding a ‘.YOUR_LAST_CHANCE’ extension at its end. This means that a file, which was named ‘space-cat.mp3’ previously will be renamed to ‘space-cat.mp3.id_<VICTIM ID>_.YOUR_LAST_CHANCE’ where the ‘VICTIM ID’ is a uniquely generated ID for every user that falls victim to this ransomware threat.

The Ransom Note

After the encryption process is completed, the YOUR_LAST_CHANCE Ransomware will drop a ransom note called ‘_RESTORE FILES_.txt,’ which is pretty concise. It states:

’*** ALL YOUR WORK AND PERSONAL FILES HAVE BEEN ENCRYPTED ***

To decrypt your files you need to buy the special software ñ "Nemesis decryptor"
You can find out the details/buy decryptor + key/ask questions
by email: your_last_chance_help@protonmail.com, your_last_chance_help@elude.in OR yourlastchancehelp@cock.li

IMPORTANT!
DON'T TRY TO RESTORE YOU FILES BY YOUR SELF, YOU CAN DAMAGE FILES!
If within 24 hours you did not receive an answer by email, be sure to write to
Jabber: your_last_chance@thesecure.biz

Your personal ID: -‘

In the note, the attackers do not disclose what the ransom fee is. They provide four email addresses where the victim can contact them for further instructions – ‘your_last_chance_help@protonmail.com,’ ‘your_last_chance@thesecure.biz,’ ‘yourlastchancehelp@cock.li,’ and ‘your_last_chance_help@elude.in.’

We would advise you strongly against contacting ransomware authors and cyber crooks in general. These are not trustworthy people, and it is wiser to keep your distance from them. It is fundamental that you download and install a reputable anti-malware application that will wipe off the YOUR_LAST_CHANCE Ransomware from your PC and prevent such accidents in the future.

Trending

Most Viewed

Loading...