Jump to content
Posted 02 June 2017 - 11:04 AM
Posted 02 June 2017 - 12:12 PM
The sendspace link has a matching pair as well as the ransom note (with an email address for one: email@example.com
The ransomware is not recognized on ID ransomware. We are still trying to assist in recovering a malware example from the client to link to the topic.
Posted 02 June 2017 - 01:01 PM
Posted 02 June 2017 - 01:26 PM
Yep, definitely looks new. The only lead we have so far is I put a hunt out for the ".maysomware" variant a few weeks ago. Exact same note and contact info.
I've pointed ID Ransomware to this topic for it. Only had a small handful of submissions for it so far from US, Taiwan, UK, and Ukraine.
If I have helped you and you wish to support my ransomware fighting, you may support me here.
0 members, 0 guests, 0 anonymous users