@Gheto
Hello, apologies for the late reply.
Horse4444 is indeed another version of .ox4444 (GlobeImposter) ransomware.
The ransom note is absolutely the same, including the emails, too.
Unfortunately there is still no decryption tool for both of them as far as we know.
Did you try the older GlobeImposter Decryptor developed by EMSIsoft?
You can download it from the
GlobeImposter Decryptor link here or from the official EMSIsoft website.
It was made for a previous version and the prerequisites needed (taken from the EMSIsoft site):
"
The decrypter requires access to a file pair consisting of one encrypted file and the original, unencrypted version of the encrypted file to reconstruct the encryption keys needed to decrypt the rest of your data."
Would you mind sharing how did you get your system infected?
And also good luck with the decryptor, although it is very old and I kind of doubt that it will work. It even might mess with your files, so do a backup (if you already haven't) just in case.
Do backups from now on - they are the most reliable thing for recovery from ransomware attacks.
Kind Regards,
Execute