Home Malware Programs Ransomware Donald Trampo Ransomware

Donald Trampo Ransomware

Posted: May 4, 2017

Threat Metric

Threat Level: 10/10
Infected PCs: 50
First Seen: May 4, 2017
OS(es) Affected: Windows



The Donald Trampo Ransomware is a Trojan that can encrypt your files to make associated programs unable to open them. Its attacks also include substantial changes to filenames and the creation of messages asking you to contact its threat actor, which may be part of a ransom negotiation. For dealing with this threat, malware experts suggest backing up your files, using standard security protocols to prevent infections, and removing the Donald Trampo Ransomware with in-depth system scans from your anti-malware applications.

The Trojan with a Geographical Identity Crisis

Back in February, malware analysts saw a campaign using a minor variant of a prior Trojan, re-branded with the name of TrumpLocker Ransomware. It perhaps is surprising that, since then, not that many politically-themed threats are under analysis. The Donald Trampo Ransomware is one of the first to break that lull, with a name implying Russian origins, but a distribution pattern that reaches over Europe and North America.

As for its payload, the Donald Trampo Ransomware is nothing more than a file-encrypting Trojan, similar to Hidden Tear or EDA2. Its executable may disguise itself as adult erotic content or a Web-browsing add-on, allowing it to gain system access once the user downloads and launches it. As usual for threats of this type, malware analysts find no symptoms arising from the Donald Trampo Ransomware, at first, with its encryption attacks taking place in the background.

The Donald Trampo Ransomware locks documents, pictures, and other formats of non-essential data by enciphering them with an encryption algorithm, reordering their internal file data. The Trojan also modifies their filenames with extensions consisting of a string of sixteen numeric characters, its admin's contact address, and the '.info' tag. Last, it also hijacks the Windows desktop, replacing it with another message pointing the victim towards the contact address.

Pushing Politics out of Your PC

The components of the Donald Trampo Ransomware verifiable by malware experts point to this Trojan being another variant of the webmafia@asia.com Ransomware, which is a recent member of the Dharma Ransomware family. Any users with encrypted content may want to avail themselves of free decryption software for that family, before trying any recovery options that necessitate paying a con artist's ransom. Nonetheless, neither choice is optimal in comparison to taking security steps that prevent infections and storing backups that let you recover without needing to decode anything that this Trojan is locking.

The most visible of the Donald Trampo Ransomware's symptoms are limited to loading after the worst damage to your files is finalized. Just over a dozen brands of anti-malware products can detect this threat, which, usually, will arrive with misleading names implying that it's safe for you to open. Users scanning their new files with anti-malware programs that could delete the Donald Trampo Ransomware immediately are less at risk of losing documents, pictures, and other media.

The Donald Trampo Ransomware may be of Russian creation or, simply, a Trojan built with mocking reference to ongoing political rumors. Whatever the case might be, it already is proving itself as a real danger to PC users on both sides of the Atlantic.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 716.8 KB (716800 bytes)
MD5: d971ace1a9209e1f1a6ceaf61b62a49c
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 1, 2017
file.exe File name: file.exe
Size: 697.34 KB (697344 bytes)
MD5: 057a4e354e1007b0048ca6af000f0717
Detection count: 38
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 4, 2017
Loading...