Edw Ransomware

ransomware

The Edw ransomware is a new file-encrypting malware variant that does not seem to belong to any major family of ransomware clones.

The ransomware appends the ".edw" extension to the names of encrypted files, as well as two strings containing the victim's ID and the contact email used by the ransomware's maker. This means that a file named "photograph.jpg" will become "photograph.jpg.id-alphanumeric string.[edward22w.aol.com].edw". It's safe to assume that the extension matches the name chosen by the ransomware's author - Edward.

The Edw ransomware encrypts media, document and archive file types, leaving them unopenable. The ransom note is both dropped inside a file named "FILES ENCRYPTED.txt" and displayed inside a pop-up window that shows up when encryption completes. Here is the ransom demand in full:

YOUR FILES ARE ENCRYPTED

Don't worry,you can return all your files!

If you want to restore them, follow this link:email edward22w at aol dot com YOUR ID [alphanumeric string]

If you have not been answered via the link within 12 hours, write to us by e-mail:edward22w at tutanota dot com

Attention!

Do not rename encrypted files.

Do not try to decrypt your data using third party software, it may cause permanent data loss.

Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

June 28, 2022
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.