Saba Ransomware is a Djvu Clone That Seeks Files For Encryption

ransomware

During our examination of malware samples, we came across Saba, which is a ransomware variant belonging to the Djvu ransomware family. Saba encrypts files and modifies their filenames by appending the ".saba" extension. It also generates a ransom note in the form of a text file named "_readme.txt".

For instance, Saba changes the filename of "1.jpg" to "1.jpg.saba" and "2.png" to "2.png.saba", among others. It is worth noting that Djvu ransomware variants are frequently distributed alongside information stealers such as Vidar and RedLine.

The ransom note created by Saba provides two email addresses (support@freshmail.top and datarestorehelp@airmail.cc), directing victims to contact the attackers within 72 hours to avoid an increase in the ransom payment. The initial payment amount is $490, but failing to act within the specified time limit will result in an increased payment of $980 for the decryption tools.

Moreover, the ransom note emphasizes that it is impossible to recover encrypted files without purchasing the decryption software and a unique key from the attackers. The note also mentions a free decryption offer for a single file, but the file cannot contain important information.

Saba Ransom Note Asks for $480 in Initial Ransom

The full Saba ransom note follows the usual Djvu template, asking for $480 in ransom and threatening to double that amount in three days. The full note reads as follows:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-iN0WoEcmv0
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@freshmail.top

Reserve e-mail address to contact us:
datarestorehelp@airmail.cc

Your personal ID:

How is Ransomware Like Saba Usually Distributed by Threat Actors?

Threat actors typically distribute ransomware like Saba through various methods, including:

  • Malicious email attachments - Ransomware can be spread through email attachments, especially those from unknown or suspicious sources. These attachments may contain a disguised executable file or a malicious macro that, when opened, triggers the ransomware infection.
  • Malvertising - Attackers can use malicious ads, often on high-traffic websites, to distribute ransomware. These ads can appear legitimate but, when clicked, redirect users to a site that downloads the ransomware onto their system.
  • Exploiting software vulnerabilities - Attackers can exploit known software vulnerabilities to deliver ransomware to systems that have not installed the latest security patches and updates.
  • Social engineering - Attackers can use various social engineering tactics to trick users into downloading and installing ransomware. For instance, attackers may create fake software updates or antivirus alerts that, when clicked, actually download ransomware onto the system.
  • Pirated software - Pirated software is often bundled with malware, including ransomware. Downloading and installing such software from untrusted sources can lead to a ransomware infection.

It is crucial to be vigilant and cautious when downloading or opening attachments, clicking on links, or downloading software. Keeping antivirus software up-to-date, installing security patches and updates, and creating regular backups of important files can also help protect against ransomware like Saba.

May 2, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.