Pouu Ransomware is a New Djvu Clone

ransomware

Pouu is a type of ransomware that belongs to the Djvu family. It encrypts data and adds the ".pouu" extension to filenames, as well as creating a "_readme.txt" file with instructions for victims. Our malware researchers discovered Pouu while analyzing samples uploaded to VirusTotal.

When Pouu infects a system, it renames files by adding the ".pouu" extension at the end of each filename - for example, "1.jpg" becomes "1.jpg.pouu". It is possible that Pouu is being distributed alongside other malicious programs such as RedLine or Vidar.

The ransom note provides contact details and payment information, claiming that victims must email datarestorehelp@airmail.cc or support@freshmail.top if they want to recover their files within 72 hours - after this time period, the price of decryption software and key will double from $490 to $980. Furthermore, it states that victims can send one encrypted file for free decryption before purchasing decryption tools.

Victims should be aware that paying the ransom does not guarantee that their files will be recovered. It is recommended to back up important data regularly and use reliable security software to protect against ransomware attacks.

The Pouu ransomware full ransom note

The note produced by Pouu reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-GTrvfBi8hs
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@freshmail.top

Reserve e-mail address to contact us:
datarestorehelp@airmail.cc

Your personal ID:

How can ransomware like Pouu get into your computer?

Ransomware is a type of malicious software that can infect your computer and encrypt your data, making it inaccessible until you pay a ransom. It is typically spread through malicious emails or websites, and can be difficult to detect as it often disguises itself as legitimate software. Once installed, ransomware will lock down your files and demand payment in exchange for the decryption key. Victims are usually instructed to pay the ransom in cryptocurrency such as Bitcoin or Ethereum.

It is important to take steps to protect yourself from ransomware attacks. Make sure that you have up-to-date antivirus software installed on all of your devices, avoid clicking on suspicious links or downloading unknown files, and back up important data regularly so that you can restore it if necessary. Additionally, be aware of phishing emails which may contain malicious attachments or links that could lead to ransomware infection.

How can you keep your data safe from a possible ransomware attack

To keep your data safe from a possible ransomware attack, it is important to take steps to protect yourself. Make sure that you have up-to-date antivirus software installed on all of your devices and scan regularly for any malicious programs. Avoid clicking on suspicious links or downloading unknown files, as these could be malicious and lead to ransomware infection. Additionally, be aware of phishing emails which may contain malicious attachments or links.

It is also important to back up important data regularly so that you can restore it if necessary. You should store backups in an external hard drive or cloud storage service, and make sure that the backups are not connected to your computer when they are not in use. This will ensure that if your computer does become infected with ransomware, the backups will remain unaffected and you can restore them without having to pay the ransom.

January 16, 2023