Yalohol Ransomware
A new member of the Spora ransomware family joins the ranks of Spore variants. The new clone is called the Yalohol ransomware.
Yalohol behaves as all ransomware does - it will encrypt files on the infected system, leaving them unopenable and largely useless. Upon encryption, the ransomware adds a multi-string extension to the old file name. The added strings include the victim's ID, the contact email used by the ransomware operator and the ".0MFD" string. This means that a file formerly named "document.txt" will turn into "document.txt[ID=[alphanumeric string]-Mail=yalohol9@gmail.com].0MFD."
The affected file types are the usual - largely any file that is not essential to the functioning of the OS. This includes documents, media and archive files as well as databases.
The ransom demands are dropped inside two files - "ReadMe_Now!.hta" and "Read_Me!_.txt". The full contents of the plain text go as follows:
All Your Files Encrypted And Sensitive Data Downloaded (Financial Documents,Contracts,Invoices etc.. ).
To Get Decryption Tools You Should Buy Our Decrption Tools And Then We Will Send You Decryption Tools And Delete Your Sensitive Data From Our Servers.
If Payment Is Not Made We have to Publish Your Sensitive Data If Necessary Sell Them And Send Them To Your Competitors And After A While Our Servers Will Remove Your Decrypion Keys From Servers.
Your Files Encrypted With Strongest Encryption Algorithm So Without Our Decryption Tools Nobody Can't Help You So Do Not Waste Your Time In Vain!
Your ID: -
Email Address: yalohol9@gmail.com
In Case Of Problem With First Email Write Us E-mail At : yalohol@cyberfear.com
Send Your ID In Email And Check Spam Folder.
This Is Just Business To Get Benefits, If Do Not Contact Us After 48 Hours Decryption Price Will x2.
What Guarantee Do We Give You ?
You Should Send Some Encrypted Files To Us For Decryption Test.
---------------------------------------------------
Attention!
Do Not Edit Or Rename Encrypted Files.
Do Not Try To Decrypt Files By Third-Party Or Data Recovery Softwares It May Damage Files.
In Case Of Trying To Decrypt Files With Third-Party Sofwares,This May Make The Decryption Harder So Prices Will Be Rise.
---------------------------------------------------
How To Buy Bitcoin :
Buy Bitcoin Instructions At LocalBitcoins :
hxxps://localbitcoins.com/guides/how-to-buy-bitcoins
Buy Bitcoin Instructions At Coindesk And Get More Info By Searching At Google :
hxxps://www.coindesk.com/learn/how-can-i-buy-bitcoin/








