Home Malware Programs Ransomware ImSorry Ransomware

ImSorry Ransomware

Posted: May 30, 2017

Threat Metric

Threat Level: 10/10
Infected PCs: 64
First Seen: May 30, 2017
OS(es) Affected: Windows


The ImSorry Ransomware is a Trojan that can block you from opening your files by encrypting them, which it uses to support its demands for ransom money. Victims who can't recover with backups should contact professional anti-malware researchers for help with decryption. Otherwise, remove the ImSorry Ransomware with any trusted brand of anti-malware software to prevent any more damage to your files.

Receiving Apologies While Being Held Up

Although even con artists can have second thoughts about breaking the law, usually, the underlying motivations of greed and opportunism prove stronger than any sense of morality. Sometimes, such conflicting sentiments even are seen in the act of the wrongdoing itself, such as the extortionist messages left by file-blocking Trojans. The ImSorry Ransomware is a new sample of such threats, with sharply rising detection rates from counteractive security solutions over the past week.

While its family is unknown, the ImSorry Ransomware operates similarly to elder file-encrypting threats like Hidden Tear. The ImSorry Ransomware searches the compromised PC's directories for PDF documents, ZIP archives, and other data not related to the OS and encodes it using a cipher. The Trojan also appends every locked file with the '.imsorry' extension, a tag malware experts only are seeing inside of the ImSorry Ransomware's campaign.

The ImSorry Ransomware then creates two messages containing its ransom-collecting parameters, in both Notepad TXT and a pop-up window. Although both notes include the demands for 500 USD in Bitcoins, the pop-up also includes other features to make the payment easier to the victim, such as a decryption key input field and a secondary backup feature that may be meant to limit damage from any unintended decryption problems.

Twenty-One Days to Make the Wrong Decision

While its author shows limited signs of professionalism, the ImSorry Ransomware does include some minor social engineering techniques to help encourage ransoms. Although the ImSorry Ransomware offers the victim three weeks to pay before the author deletes your decryption key, users with encrypted content always should check for public domain decryption solutions before resorting to Bitcoin ransoms. Paying a ransom in full never guarantees that the threat actor will restore your data, and cryptocurrencies like Bitcoin aren't subject to traditional refund policies.

The ImSorry Ransomware targets victims using the English language and doesn't appear to be the product of a non-native speaker. Other than these clues, few signs offer clear evidence of what installation exploits the ImSorry Ransomware may be using. Malware experts recommend that you back up your PC's valuable content and scan suspicious files (such as e-mail attachments) with anti-malware applications that could delete the ImSorry Ransomware and block its encryption routine.

The ImSorry Ransomware may apologize after the fact, but its repentance is skin-deep. With its ransoms costing hundreds of dollars, any PC users not protecting their systems adequately shouldn't place their hopes in the good-will of this Trojan's creator.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 205.82 KB (205824 bytes)
MD5: 859fe9dc1478333916c9a94253f93dd2
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 30, 2017
Loading...