« Last post by Execute on June 22, 2017, 06:04:03 pm »
Hello, @ZMan.

Yes, this is confirmed by malware researchers to be the new variant of MOLE ransomware and it appends the .MOLE02 extension like you have shown in the attached picture.

You can find a thorough analysis of the virus here:

Best Regards,
« Last post by ZMan on June 14, 2017, 06:03:16 pm »
Does this look more like a different mole file that the standard mole going around? I can't find much on this virus, any links are sources would be usefully if you can give any.

Hmm, that is quite interesting. Sad that you couldn't recover files with Recuva. Just don't reformat the drive so you could keep trying such Data Recovery programs. That is indeed helpful information, but can't really remember a ransomware that did that. If I remember anything I will be sure to write about it here.
Thanks for your reply, the new names files are numbers and letters without any sense, and also the extension of the archives are the same.
Also, the archives are stored in a hard external disc (usb conexion), and no message is showing after the attack.
All it's very strange but after using a recovery tool to missing archives, I could descover that the original archives were deleted at the same time were created the new encrypted archives (the time of the two actions are the same). Unfortunately, I could'n recover the original archives with the program RECUVA (and also another more that I tred).
I hope this information add data to your diagnosis. I read your suggested article, but don't match with my case.
I ran the decrypter program on a small portion of encrypted files and it worked!! I am now going to work on decrypting a larger set of files we had saved in case a decryption program was created that worked. There are a huge set of files we were waiting on to decrypt that will save us a lot of headache in the future. A BIG THANKS goes out to the creators of the decryption program.!!
There is now a DECRYPTION TOOL released for the .wallet variant of Dharma ransomware!
It might work for the Sanctions virus, so you should definitely try it!

Check out the instructions for it in the article:
Decrypt .wallet Encrypted Files for Free (Dharma Update 2017)

Best Regards,
« Last post by Ankurstellar01 on May 17, 2017, 06:04:30 am »
 you can also look for Stellar Data recovery tools they are easy to use and install.
 have a look Even you can get offer and a free version to check.
« Last post by Abhi on May 15, 2017, 07:18:20 pm »
Me to is waiting for the solution of that ransomeware ..... encryption ! ..... i have backup my encypted files ..
i have tryed Brute for But useless  :( :( :(
