Mapo Outsider Ransomware (. Mapo Files Restore + Decrypt)
About Outsider Ransomwareoutsider Ransomware Encrypts Server and Customer Computers Using Aes">1 Encryption, and Then Requires a Ransom of $900 in Bitcoins">2...
About Outsider Ransomware
Outsider ransomware encrypts server and customer computers using AES">1 encryption, and then requires a ransom of $900 in BitCoins">2 to restore the files. It was first disclosed by the viral researcher GrujaRS">3.Outsider virus creates a file “MAPO-README.txt” with a buyback message in each folder where there are encrypted files.
It can be spread by hacking through an insecure RDP configuration, using email spam and malicious attachments, deceptive downloads, botnets, exploits, web injects, fake updates, repackaged and infected installers.
- MS Office documents
- OpenOffice
- Text files
- Databases
- Images
- Music
- Videos
- ISO-files
- Archives
-------------------------------------------------------------------------------------------- ! STRICTLY FORBIDDEN TO USE NON-ORIGIN DECRYPTION TOOLS OR MODIFYING ENCRYPTED FILES - DATA WILL BE LOST ! -------------------------------------------------------------------------------------------- Due vulnerability in your system all of the files have been protected with RSA Private Key to safe them from unathorized 3rd party access. To RESTORE all of your files back, please follow this few steps: 1. MAPO service charges a payment for file decryption; 2. After payment being processed, contact us and provide your PC id-key; 3. Receive your unique decryption tool; 4. Run the decryption tool and successfully restore all your files back to normal state. We guarantee: 100% Successful restoring of all files 100% Satisfaction guarantee 100% Safe and secure service As a proof of our trusted decryption service, you can send us 1 file and get it decrypted for free. -------------------------------------------------------------------------------------------- ! STRICTLY FORBIDDEN TO USE NON-ORIGIN DECRYPTION TOOLS OR MODIFYING ENCRYPTED FILES - DATA WILL BE LOST ! ! ONLY MAPO DECRYPTION TOOL CAN RESTORE YOUR FILES ! -------------------------------------------------------------------------------------------- Our email: Payment type: Bitcoin Your PC ID-KEY: XXXXXXXXXXXXXXXXXX -------------------------------------------------------------------------------------------- / MAPO (c) 2019
-------------------------------------------------------------------------------------------- ! STRICTLY FORBIDDEN TO USE NON-ORIGIN DECRYPTION TOOLS OR MODIFYING ENCRYPTED FILES - DATA WILL BE LOST ! -------------------------------------------------------------------------------------------- Your server have been attacked by an Unathorized user. All your files have been encrypted with RSA Private Key to safe them from unathorized 3rd party access. To RESTORE all your files back, please follow this few steps: 1. PP-EUS service charges a payment for file decryption; 2. After payment being processed, provide us your server id-key 3. Receive your unique decryption tool; 4. Run the decryption tool and successfully restore all your files back to normal state. We guarantee: 100% Successful restoring of all files 100% Satisfaction guarantee 100% Safe and secure service As a proof of our trusted decryption service, you can send us 1 file and get it decrypted for free. -------------------------------------------------------------------------------------------- ! STRICTLY FORBIDDEN TO USE NON-ORIGIN DECRYPTION TOOLS OR MODIFYING ENCRYPTED FILES - DATA WILL BE LOST ! ! ONLY OUR DECRYPTION TOOL CAN RESTORE YOUR FILES ! -------------------------------------------------------------------------------------------- Contact us: Payment type: Bitcoin Our wallet: 19k8MNYRjVvkcozePZLnBhftrvGPfeugmN Your server ID-KEY: XXXXXXXXXXXXXXXXXXXXXX For any questions: ProtonProject EUS © 2019
Stages of Outsider ransomware infection
- Once launched, the cryptoware executable connects to the Command and Control server (С&C). Consequently, it obtains the encryption key and the infection identifier for the victim’s PC. The data is transferred under the HTTP protocol in the form of JSON.
- If С&C is unavailable (in times when the PC is not connected to the Internet of the server does not respond), the cryptoware applies the directly specified encryption key concealed in its code and performs the autonomous encryption. In this case, it is possible to decrypt the files without paying the ransom.
- The cryptoware uses rdpclip.exe to replace the legitimate Windows file and for implementing the attack on the computer network.
- Upon successful file encryption, the cipherer is autonomously removed by means of the delself.bat command file.