Police_Decrypt0r Ransomware

ransomware

Police_Decrypt0r is the name of a new strain of ransomware.

The new variant will encrypt files on the victim system, leaving them unusable. Once encrypted, files receive the new ".CRYPT" extension. In this way, a file originally called "document.docx" will transform into "document.docx.CRYPT" once the ransomware has encrypted it. Affected file types include media, archive, document and database files.

Once the ransomware finishes encrypting the system, it deposits its ransom demands inside a plain text file named "Police_Decrypt0r.txt". The ransom demand is for 0.05 Bitcoin - a modest sum implying either a ransomware in its testing phase or a small-time cybercriminal.

The ransomware also displays a pop-up window with the text "You only have 5 hours to complete the payment, if the payment isn'5 submitted by tomorrow night, we'll brick your enctire system."

The full contents of the ransom note file are as follows:

Police_Decrypt0r

Your important files are encrypted...

CYBER.POLICE American national security agency

Remaining time:

Bitcoin address:

[alphanumeric string]

Your documents, photos, databases, important data were encrypted

How to pay and unlock your files

Send 0.05 BTC to [alphanumeric string]

After payment,contact us get your decryption

Email:crypt31 at proton dot me

Obviously the ransomware has nothing to do with the US NSA and it's a weird choice of name, given its obviously criminal activity.

July 12, 2022
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.