A ransomware-as-a-service virus, calling itself DotRansomware has appeared on the deep web. The virus has been created in English and is highly modifiable. It also uses AES encryption algorithm to encode the files on the victims’ computers. This encryption is sophisticated and generates a unique decryption key. The virus comes with it’s custom sales page which is oriented primarily towards selling it to people who want to infect users with it. The ransomware virus uses the TOR networking system to infect various users and hence remain untraceable. In case you have been infected by DotRansomware, recommendations are to read the following material and learn what DotRansomware exactly performs and how to neutralize it and try getting back the data.
|Short Description||The malware is offered online as a part of a scheme to distribute it in a final variant for 50% of the ransom the victims pay for their files encrypted by the virus.|
|Symptoms||The user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension .locked has been used but may be changed with different versions.|
See If Your System Has Been Affected by DotRansomware
Malware Removal Tool
|User Experience||Join our forum to Discuss DotRansomware.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
How Does DotRansomware Spread
This particular virus is advertised online to absolutely everyone who has access to some particular areas of the deep web. This means that DotRansomware may spread depending on what the cyber-criminal decides. Typically most cyber-criminals choose e-mail spam messages with deceitful content, like the example picture below shows:
Such e-mails aim to get the user to open malicious e-mail attachment which is the infection malware that downloads the payload of DotRansomware, in this hypothetical scenario.
However, there are many other methods by which this ransomware infection could infect users:
- Via fake installers or updates downloaded from shady websites.
- If the user activates a fake patch for cracking unlicensed software, usually downloaded from torrent websites.
- Via other malware that has previously infected a computer.
- Via potentially unwanted program (PUP) that aims to perform an infection via multiple different advertisements, redirects or pop-ups.
DotRansomware – Further Analysis
The virus has been uploaded on a TOR-based web page and as soon as you open it, the terms of the developers immediately become evident:
The cyber-criminals offer as much as half of the extorted money paid by the victim to the one who distributes their own version of DotRansomware. The registration process of the virus is also quite simple. All one needs to begin infecting is a BitCoin address. As tempting as it sounds, this is quite the risk and at the end, trusting cyber-criminals is never a good idea at all.
During the infection process, DotRansomware may drop multiple malicious files on the computers it compromises. The files may have different names and may be located in different Windows folders, for example:
The official file extension of the DotRansomware virus is .locked, but the ransomware may undergo some changes, it really depends on how it is configured:
Image Source: id-ransomware.blogspot.bg
Amongst the files types this virus encrypts are around 400 different files that are connected with various programs that are used on a daily basis:
→.001, .1dc, .3ds, .3fr, .7z, .a3s, .acb, .acbl, .accdb, .act, .ai, .ai3, .ai4, .ai5, .ai6, .ai7, .ai8, .aia, .aif, .aiff, .aip, .ait, .anim, .apk, .arch00, .ari, .art, .arw, .asc, .ase, .asef, .asp, .aspx, .asset, .avi, .bak, .bar, .bay, .bc6, .bc7, .bgeo, .big, .bik, .bkf, .bkp, .blob, .bmp, .bsa, .c, .c4d, .cap, .cas, .catpart, .catproduct, .cdr, .cef, .cer, .cfr, .cgm, .cha, .chr, .cld, .clx, .cpp, .cr2, .crt, .crw, .cs, .css, .csv, .cxx, .d3dbsp, .das, .dat, .dayzprofile, .dazip, .db, .db0, .dbf, .dbfv, .dcr, .dcs, .der, .desc, .dib, .dlc, .dle, .dlv, .dlv3, .dlv4, .dmp, .dng, .doc, .docm, .docx, .drf, .dvi, .dvr, .dwf, .dwg, .dxf, .dxg, .eip, .emf, .emz, .epf, .epk, .eps, .eps2, .eps3, .epsf, .epsp, .erf, .esm, .fbx, .ff, .fff, .fh10, .fh11, .fh7, .fh8, .fh9, .fig, .flt, .flv, .fmod, .forge, .fos, .fpk, .fsh, .ft8, .fxg, .gdb, .ge2, .geo, .gho, .gz, .h, .hip, .hipnc, .hkdb, .hkx, .hplg, .hpp, .hvpl, .hxx, .iam, .ibank, .icb, .icxs, .idea, .iff, .iiq, .indd, .ipt, .iros, .irs, .itdb, .itl, .itm, .iwd, .iwi, .j2k, .java, .jp2, .jpe, .jpeg, .jpf, .jpg, .jpx, .js, .k25, .kdb, .kdc, .kf, .kys, .layout, .lbf, .lex, .litemod, .lrf, .ltx, .lvl, .m, .m2, .m2t, .m2ts, .m3u, .m4a, .m4v, .ma, .map, .mat, .max, .mb, .mcfi, .mcfp, .mcgame, .mcmeta, .mdb, .mdbackup, .mdc, .mddata, .mdf, .mdl, .mdlp, .mef, .mel, .menu, .mkv, .mll, .mlx, .mn, .model, .mos, .mp, .mp4, .mpqge, .mrw, .mrwref, .mts, .mu, .mxf, .nb, .ncf, .nef, .nrw, .ntl, .obm, .ocdc, .odb, .odc, .odm, .odp, .ods, .odt, .omeg, .orf, .ott, .p12, .p7b, .p7c, .pak, .pct, .pcx, .pdd, .pdf, .pef, .pem, .pfx, .php, .php4, .php5, .pic, .picnc, .pkpass, .png, .ppd, .ppt, .pptm, .pptx, .prj, .prt, .prtl, .ps, .psb, .psd, .psf, .psid, .psk, .psq, .pst, .ptl, .ptx, .pwl, .pxn, .pxr, .py, .py, .qdf, .qic, .r3d, .raa, .raf, .rar, .raw, .rb, .rb, .re4, .rgss3a, .rim, .rofl, .rtf, .rtg, .rvt, .rw2, .rwl, .rwz, .sav, .sb, .sbx, .sc2save, .sdf, .shp, .sid, .sidd, .sidn, .sie, .sis, .skl, .skp, .sldasm, .sldprt, .slm, .slx, .slxp, .snx, .soft, .sqlite, .sqlite3, .sr2, .srf, .srw, .step, .stl, .stp, .sum, .svg, .svgz, .swatch, .syncdb, .t12, .t13, .tar, .tax, .tex, .tga, .tif, .tiff, .tor, .txt, .unity3d, .uof, .uos, .upk, .vda, .vdf, .vfl, .vfs0, .vpk, .vpp_pc, .vst, .vtf, .w3x, .wallet, .wav, .wb2, .wdx, .wma, .wmo, .wmv, .wotreplay, .wpd, .wps, .x3f, .xf, .xl, .xlk, .xls, .xlsb, .xlsm, .xlsx, .xvc, .xvz, .xxx, .ycbcra, .yuv, .zdct, .zip, .ztmp
These important files are rendered no longer openable and the virus also has a ransom note which can be customized. Malware researchers believe that it may be somehow connected to Unlock26 ransomware – a relatively new virus that hit the wild recently.
Remove DotRansomware and Try Getting Back the Files
In case you have been infected by an instance of this ransomware infection on your computer, the first deal of business is to immediately back up the encrypted files.
Then, experts recommend removing this ransomware infection from your computer with the one and only purpose of creating a safe environment to try the methods In step “2. Restore files encrypted by DotRansomware” below. In case you have difficulties in manually removing this ransomware infection from your computer, reccomendations are to focus on scanning your computer with an advanced anti-malware software. It will fully remove all files associated with this threat and make sure to protect your computer in the future as well.
Manually delete DotRansomware from your computer
Note! Substantial notification about the DotRansomware threat: Manual removal of DotRansomware requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.
Automatically remove DotRansomware by downloading an advanced anti-malware program
Globe2 Ransomware Decryption Instructions
In order to successfully decrypt files enciphered by globe ransomware you are going to need several details to begin with. First, you will need an original file and an encrypted file.
In case you cannot find one, make sure to browse through the default wallpaper folder of the same version of your Windows OS. Here is an example of the location of the default folders for wallpapers for different Windows versions:
After having located an original and an encrypted file, make sure to download the decrypter by clicking on the download button below:
Make sure to save the decrypter somewhere easy to find and open it. Then follow the steps below:
Step 1: Drag and drop the encrypted file and the original file together into the decrypter, like the animated image below demonstrates:
Step 2: The decrypter will begin a brute forcing sequence. Simply wait until your key has been discovered:
Step 3: After this, click on OK and the main interface of the decrypter should appear. From it, choose Add Files to add all the files that you wish to be deciphered.
Step 4: After you have added your files, click on the Decrypt button so that the decrypter can begin the deciphering operation.
At this point you will begin to see on the live feed at the middle of the decrypter’s interface which files were successfully decoded:
Globe2 Ransomware – The Bottom Line
As a summary of this virus, it is nothing special since malware researchers have managed to almost immediately decode it. But bear in mind that there are many other dangerous ransomware viruses out there that exist for couple of years now and no decryption solution has been released yet. This is why it is always a benefit to know how to protect yourself from malware of the file encryption type.
We have prepared several simple tips that you can follow and stay safe in the future: