Home Malware Programs Ransomware 'Insane@airmail.cc' Ransomware

'Insane@airmail.cc' Ransomware

Posted: January 19, 2018

Threat Metric

Ranking: 19,217
Threat Level: 2/10
Infected PCs: 45
First Seen: July 16, 2023
Last Seen: July 19, 2023
OS(es) Affected: Windows

The 'Insane@airmail.cc' Ransomware is a file locker, which might be found in corrupted e-mail messages, which contain misleading messages, and a harmful file attached. Often, the file attachment might look like a harmless archive or document, but its execution might lead to the infection with the 'Insane@airmail.cc' Ransomware or other threat. When this particular ransomware is executed on a computer, the 'Insane@airmail.cc' Ransomware will use a background process to scan the local hard drive and look for specific file formats that it has been programmed to encrypt silently. The 'Insane@airmail.cc' Ransomware's targets are quite diverse – documents, images, other media, spreadsheets, archives, backups, databases, etc.

Whenever the threat encrypts a file successfully, it will append the ‘.[insane@airmail.cc].insane' extension to its name. In addition to this, it will drop a text-file, 'How_decrypt_files.txt,' which the victims must open to find out what they need to do to recover their files. The authors of the 'Insane@airmail.cc' Ransomware are unlikely to offer a free solution, and chances are that their victims will be asked to pay hundreds if not thousands of dollars in exchange for specialized decryption software. You should not agree to pay money to the anonymous hackers behind this project because it is likely that they will end up tricking people out of their money.

Some anti-virus product vendors have marked the 'Insane@airmail.cc' Ransomware as a member of the BTCWare Ransomware family, but this is not yet confirmed. The advice to victims of the 'Insane@airmail.cc' Ransomware is to disregard the demands of the attacker and, instead, proceed to remove this threatening software with the help of a trustworthy anti-malware scanner. Once this step is complete, they should look for alternative software and techniques, which might help them get some files back.

Technical Details

Additional Information

The following URL's were detected:
ordergoodonline.shop
Loading...