• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Monro Ransomware

October 5, 2018Simeon Georgiev

Recently, ransomware removal analysts manage to uncover a new cyber threat. As users reported their loss of access to crucial data, a ransomware by the name of Monro was found to be the culprit. Users were tricked into downloading the malicious payload of the ransomware from spam emails where attachments in the .docx and .pdf formats carried the ransomware’s infection components.

The ransomware also propagates through various websites on the internet, especially the ones with weak security and websites that encourage users to download freeware. Hence, the probability of a Monro Ransomware attacking your PC depends highly on your internet behavior.

Post-infection, the ransomware goes in the Temp folder of Windows where it takes certain liberties with the OS. Subsequently, it locks the files in a computer. These files are modified with an added extension of “id-[victim’s_ID].[[email protected]].monro”. For example, if you have a file with the name of “graduation_pic.png” in your computer that cannot be opened or accessed, then it may appear as “graduation_pic.png.id-2D769A55.[[email protected]].monro”.

The encryption utilizes the cryptographic algorithm by the name of AES (Advanced Encryption Standard). The ransomware is smart enough to delete the copies of shadow volume of the encrypted files, which makes the ransomware removal and recovery process complex.

After the successful completion of the encryption process, two additional files are created: A text document named “FILES ENCRYPTED.txt” and a HTML application “Info.hta”.  These files entail the ransom note.

Like other ransom notes, the note begins with the acknowledgment that the ransomware has encrypted the user’s data. An email address of [email protected] is provided for communication where an ID – provided in the ransom note – has to be put in the subject line of the email. Ransom is asked in the form of Bitcoin while the exact amount is stated to be informed via email. The note ends with a warning against any attempt at ransomware removal.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Honolulu-Based Medical Facility Attacked Next post McAfee Report for the Ransomware Space

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.