EAF Ransomware

ransomware

The EAF ransomware is a new strain of malware that was recently spotted by researchers. The ransomware does not appear to belong to any specific family of ransomware, at least under initial observation.

EAF would encrypt popular file types, leaving the contents unreadable. The encrypted files would get a prefix and a suffix added to their original look. A file formerly called "document.docx" would turn into "[encoderdecryption@yandex.ru][alphanumeric string]document.docx.EAF" upon encryption.

The prefix appended to the file is the email of the ransomware operator, followed by the unique victim ID string generated by the ransomware. The appendix is just an additional, fixed .EAF extension.

Once encryption completes, the ransom note is dropped inside "#FILES-ENCRYPTED.txt" - a plain text file placed on the desktop.

The full ransom note goes as follows:

ATTENTION!

At the moment, your system is not protected.

We can fix it and restore files.

To get started, send a file to decrypt trial.

Don't pay any money, when we didn't decrypt trial file.

You can trust us after opening the test file.

To restore the system write to this address:

Email 1: encoderdecryption at yandex dot ru

Email 2: encoderdecryption at gmail dot com

May 26, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.