What is the DATAF LOCKER Ransomware?
DATAF LOCKER is a new malicious tool that belongs to the ransomware subcategory of malware.
DATAF LOCKER encrypts files on a system that it infects, rendering their contents scrambled and unreadable. Once encrypted, files receive the ".dataf" extension and their names are changed. The encryption process will make a file that was originally called "document.pdf" turn into "document.pdf.dataf" once it has been fully encrypted.
The ransomware will scramble the contents of databases, media files, archive files and documents. Once the encryption algorithm completes its work, the DATAF LOCKER ransomware drops its ransom demands in a text file with the name "How To Restore Your Files.txt". The ransom note expects the victim to contact the ransomware authors using Tor chat, providing a login and password for it. The full note reads as follows:
----------- ( Hello! ) ------------->
****BY DATAF L**OCKER****
What happend?
----------------------------------------------
Your computers and servers are encrypted, backups are deleted from your network and copied. We use strong encryption algorithms, so you cannot decrypt your data.
But you can restore everything by purchasing a special program from us - a universal decoder. This program will restore your entire network.
Follow our instructions below and you will recover all your data.
If you continue to ignore this for a long time, we will start reporting the hack to mainstream media and posting your data to the dark web.
What guarantees?
----------------------------------------------
We value our reputation. If we do not do our work and liabilities, nobody will pay us. This is not in our interests.
All our decryption software is perfectly tested and will decrypt your data. We will also provide support in case of problems.
We guarantee to decrypt one file for free. Go to the site and contact us.
How to contact us?
----------------------------------------------
Using TOR Browser ( hxxps://www.torproject.org/download/ ):
tor chat: hxxp://tiurksxrhrefu6uzunlkpugr5rzejfeptxr4pauvsyzp4mlzuqmiatad.onion/feDJtT2hZC5X2ICH2Qq8
login: -
Password: -
----------------------------------------------
!!! DANGER !!!
DO NOT MODIFY or try to RECOVER any files yourself. We WILL NOT be able to RESTORE them.
!!! DANGER !!