What is ESCANOR Ransomware?
A new ransomware variant has been spotted in the wild, and it seems to be linked with an existing malware strain. The new ransomware is dubbed the ESCANOR ransomware and it may have ties to the malware known as EscanorRAT - a remote access trojan kit sold on the dark web.
The ESCANOR ransomware appends the ".ESCANOR" extension to encrypted files and will scramble almost every document, executable, archive and database or media file found on connected drives.
Once encryption is complete, the ransomware drops its ransom demands inside a plain text file called "HELP_DECYPT_YOUR_FILES.txt". The full ransom note goes as follows:
Oops All Of your important files were encrypted Like document pictures videos etc..
Don't worry, you can return all your files!
All your files, documents, photos, databases and other important files are encrypted by a strong encryption.
How to recover files?
RSA is a asymmetric cryptographic algorithm, you need one key for encryption and one key for decryption so you need private key to recover your files. It’s not possible to recover your files without private key.
The only method of recovering files is to purchase an unique private key.Only we can give you this key and only we can recover your files.
What guarantees you have?
As evidence, you can send us 1 file to decrypt by email We will send you a recovery file Prove that we can decrypt your file
Please You must follow these steps carefully to decrypt your files:
Send $980 worth of bitcoin to wallet: [alphanumeric string]
after payment,we will send you Decryptor software
contact email: hxxp://www.escanor-re.com/
Your personal ID:








