He posted the image that appears after visiting the Tor link that the ransomware provides. The ProofPoint researcher Darian Huss is the discoverer of this new ransomware. The Payment Site of Alma Locker RansomwareĪt the end of the ransom note the victims see link to a TOR site and a link to download a decryptor that will decrypt some files as a proof that it is working. The following image represents the ransom note of Alma Locker ransomware: Instead of the word in the brackets victims will see the same randomly generated characters that are appended to the encrypted files. The following information represents the victims unique ID and how to unlock the encrypted files. First, the ransom note states: “Your files are encrypted!”. The files in folders that contain the following strings may remain unaffected.Īt the end of the encryption process, the victim will see a ransom note on the display.
0 Comments
Leave a Reply. |