Donkeyhot Ransomware ๐ (. Donkeyhot File) โ Removal Guide
What Is Donkeyhot Virus? the Renaming Will Be Done According to the Following Scheme: [Victimid]. [Icq_Contact]. Donkeyhot. in the Process of Encryption, a...
What is Donkeyhot virus?
The renaming will be done according to the following scheme: [victimID].[ICQ_contact].DONKEYHOT. In the process of encryption, a file entitled, for example, โreport.docxโ will be turned into โreport.docx.[5deecd3145].[ICQ_DONKEYHOT].DONKEYHOTโ.
In each folder with the encoded files, a #HOW_TO_DECRYPT#.txt file will be created. It is a ransom money note. Therein you can find information about the ways of paying the ransom and some other remarks. The ransom note most probably contains a description of how to buy the decryption tool from the Donkeyhot developers. You can obtain this decoding tool after contacting ICQ contact via email. That is pretty much the scheme of the crime.
| Name | Donkeyhot Virus |
| Extension | .DONKEYHOT |
| Ransomware note | #HOW_TO_DECRYPT#.txt |
| Contact | ICQ contact |
| Detection1 | Win32/Injector.EJDH, MSIL/Shutdowner.CA, Trojan:Win32/Anomaly!C |
| Symptoms | Your files (photos, videos, documents) get a .DONKEYHOT extension and you canโt open them. |
| Fix Tool | See If Your System Has Been Affected by Donkeyhot virus |
The #HOW_TO_DECRYPT#.txt file accompanying the Donkeyhot ransomware provides the following dispiriting information:
Hello my dear friend! Unfortunately for you, a major IT security weakness left you open to attack, your files have been encrypted If you want to restore them, write to our mail: Best option is to write us via ICQ live chat which works 24/7: @DONKEYHOT Install ICQ software on your PC or on your smartphone search for \"ICQ\" in Appstore / Google market Write to our ICQ @DONKEYHOT hxxps:// Attention! * Do not rename encrypted files. * Do not try to decrypt your data using third party software, it may cause permanent data loss. * We are always ready to cooperate and find the best way to solve your problem. * The faster you write, the more favorable the conditions will be for you. * Our company values its reputation. We give all guarantees of your files decryption, such as test decryption some of them. We respect your time and waiting for respond from your side. Tell your MachineID: - and LaunchID: - SENSITIVE DATA ON YOUR SYSTEM WAS DOWNLOADED. IF YOU DON\'T WANT YOUR SENSITIVE DATA TO BE PUBLISHED YOU HAVE TO ACT QUICKLY. Data includes: - Employees personal data, CVs, DL, SSN. - Complete network map including credentials for local and remote services. - Private financial information including: clients data, bills, budgets, annual reports, bank statements. - Manufacturing documents including: datagrams, schemas, drawings in solidworks format - And more...
In the picture below, you can see what a directory with files encrypted by the Donkeyhot looks like. Each filename has the โ.DONKEYHOTโ extension added to it.
How did Donkeyhot ransomware end up on my PC?
Nowadays, there are three most exploited methods for criminals to have ransomware working in your digital environment. These are email spam, Trojan introduction and peer networks.
If you access your mailbox and see letters that look like familiar notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose mailer is unknown to you, beware of opening those emails. They are most likely to have a malicious item enclosed in them. So it is even more dangerous to open any attachments that come with emails like these.
Another option for ransom hunters is a Trojan virus model2. A Trojan is a program that gets into your computer disguised as something legal. Imagine, you download an installer of some program you want or an update for some service. But what is unboxed turns out to be a harmful agent that compromises your data. Since the installation file can have any name and any icon, youโd better be sure that you can trust the resource of the stuff youโre downloading. The optimal way is to trust the software developersโ official websites.
As for the peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So youโd better be using trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded objects with the antivirus as soon as the downloading is done.