Police_Decrypt0r Ransomware
Police_Decrypt0r is the name of a new strain of ransomware.
The new variant will encrypt files on the victim system, leaving them unusable. Once encrypted, files receive the new ".CRYPT" extension. In this way, a file originally called "document.docx" will transform into "document.docx.CRYPT" once the ransomware has encrypted it. Affected file types include media, archive, document and database files.
Once the ransomware finishes encrypting the system, it deposits its ransom demands inside a plain text file named "Police_Decrypt0r.txt". The ransom demand is for 0.05 Bitcoin - a modest sum implying either a ransomware in its testing phase or a small-time cybercriminal.
The ransomware also displays a pop-up window with the text "You only have 5 hours to complete the payment, if the payment isn'5 submitted by tomorrow night, we'll brick your enctire system."
The full contents of the ransom note file are as follows:
Police_Decrypt0r
Your important files are encrypted...
CYBER.POLICE American national security agency
Remaining time:
Bitcoin address:
[alphanumeric string]
Your documents, photos, databases, important data were encrypted
How to pay and unlock your files
Send 0.05 BTC to [alphanumeric string]
After payment,contact us get your decryption
Email:crypt31 at proton dot me
Obviously the ransomware has nothing to do with the US NSA and it's a weird choice of name, given its obviously criminal activity.








