Home Malware Programs Ransomware 'Suppteam01@india.com' Ransomware

'Suppteam01@india.com' Ransomware

Posted: October 19, 2016

Threat Metric

Threat Level: 10/10
Infected PCs: 588
First Seen: October 19, 2016
Last Seen: July 10, 2022
OS(es) Affected: Windows

The 'Suppteam01@india.com' Ransomware is a file encryption threat whose lock screen is very similar to the one used by the CryptoLocker Ransomware, one of the most threatening and widely spread pieces of ransomware that malware researchers have come across. The variant of the 'Suppteam01@india.com' Ransomware that was discovered in a corrupted e-mail attachment uses the RSA-2048 encryption to lock the files of its victims, and after the encryption of the victim's data has been completed, the ransomware displays a lock screen that tells users that they need to pay a ransom fee if they want to recover their data. The ransom note also contains two e-mail addresses that can be used to contact the perpetrators of the attack – suppteam01@india.com and suppteam01@yandex.ru.

The lock screen warns victims that their decryption key will not be stored for longer than 120 hours, and failing to pay the ransom fee before the deadline forces the attackers to destroy the unique decryption key permanently. The amount of the ransom fee may vary, but in one of the analyzed samples, the victims were asked to pay 2.05 BTC in exchange for their files. This ransom fee is quite large, and victims of the 'Suppteam01@india.com' Ransomware should not agree to send any money to the attackers. Ransomware operators are con artists who are just looking to take the money of their victims, and then stop answering their messages, therefore leaving them with a large number of unrecoverable files.

The bad news is that the encryption method that the 'Suppteam01@india.com' Ransomware uses appears to be flawless, and there's no way to decrypt the files locked by this threat. The only viable way to recover the data that the 'Suppteam01@india.com' Ransomware encrypts is to use a recent backup that contains the original versions of the lost files. If this is not possible, then we suggest that victims of the 'Suppteam01@india.com' Ransomware use an advanced anti-malware product to clean their computers and prevent the threat from encrypting more files.

Loading...