Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Hello! here in Argentinian .spfre ransomware (Press Ransomware)


  • This topic is locked This topic is locked
1 reply to this topic

#1 SystemDaemon

SystemDaemon

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  

Posted 27 March 2024 - 01:41 PM

Hello world
 
I like to know more about press ransomware and I'm here to share my experience and know more.
 
RECOVERY NFO.txt
 
 

Hello! 
 
We're sorry, but your data are stolen and encrypted.
In case of nonpayment - all sensitive information will be sold or made publicly accessible.
Compared to other ransomware we charge a lot less, so don't be stingy!
If you pay - we will provide you with decryption software and remove your data from our servers. We work honesty!   
Warning! Do not delete or modify any files, it can lead to recovery problems!
 
You can contact us using TOX messenger without registration and SMS hxxps://tox.chat/download.html
Tox ID:  
 
 
Send us your KeyID and 2 files with SIMPLE extensions(jpg,xls,doc, etc... not databases!) and low sizes(max 2 mb) for free decryption.
        Use hxxps://ufile.io
 
Good luck!
 
 
Key Identifier: 
LolQ21b


Edited by quietman7, 27 March 2024 - 03:03 PM.
Put quotebox around quoted material - Hamluis. Deactivated links. ~ OB


BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 27 March 2024 - 03:01 PM

Any files that are encrypted with Press Ransomware will have an .press, .dwarf, .spfre extension appended to the end of the encrypted data filename and typically leave files (ransom notes) named RECOVERY NFO.txt as explained here by Amigo-A (Andrew Ivanov).
 
rivitna (Andrey Zhdanov) may be able to help victims but you need to contact him privately.

If you have become a victim of this ransomware, write to me PM.

 
There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.

Rather than have everyone with individual topics, it would be best (and more manageable for staff) if you posted any more questions, comments or requests for assistance in the above support topic discussion...it includes experiences by experts, IT consultants, victims and company representatives who have been affected by ransomware infections. To avoid unnecessary confusion, this topic is closed.
 
Thanks
The BC Staff


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users