Donald Trampo Ransomware
Posted: May 4, 2017
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Threat Level: | 10/10 |
---|---|
Infected PCs: | 50 |
First Seen: | May 4, 2017 |
---|---|
OS(es) Affected: | Windows |
The Donald Trampo Ransomware is a Trojan that can encrypt your files to make associated programs unable to open them. Its attacks also include substantial changes to filenames and the creation of messages asking you to contact its threat actor, which may be part of a ransom negotiation. For dealing with this threat, malware experts suggest backing up your files, using standard security protocols to prevent infections, and removing the Donald Trampo Ransomware with in-depth system scans from your anti-malware applications.
The Trojan with a Geographical Identity Crisis
Back in February, malware analysts saw a campaign using a minor variant of a prior Trojan, re-branded with the name of TrumpLocker Ransomware. It perhaps is surprising that, since then, not that many politically-themed threats are under analysis. The Donald Trampo Ransomware is one of the first to break that lull, with a name implying Russian origins, but a distribution pattern that reaches over Europe and North America.
As for its payload, the Donald Trampo Ransomware is nothing more than a file-encrypting Trojan, similar to Hidden Tear or EDA2. Its executable may disguise itself as adult erotic content or a Web-browsing add-on, allowing it to gain system access once the user downloads and launches it. As usual for threats of this type, malware analysts find no symptoms arising from the Donald Trampo Ransomware, at first, with its encryption attacks taking place in the background.
The Donald Trampo Ransomware locks documents, pictures, and other formats of non-essential data by enciphering them with an encryption algorithm, reordering their internal file data. The Trojan also modifies their filenames with extensions consisting of a string of sixteen numeric characters, its admin's contact address, and the '.info' tag. Last, it also hijacks the Windows desktop, replacing it with another message pointing the victim towards the contact address.
Pushing Politics out of Your PC
The components of the Donald Trampo Ransomware verifiable by malware experts point to this Trojan being another variant of the webmafia@asia.com Ransomware, which is a recent member of the Dharma Ransomware family. Any users with encrypted content may want to avail themselves of free decryption software for that family, before trying any recovery options that necessitate paying a con artist's ransom. Nonetheless, neither choice is optimal in comparison to taking security steps that prevent infections and storing backups that let you recover without needing to decode anything that this Trojan is locking.
The most visible of the Donald Trampo Ransomware's symptoms are limited to loading after the worst damage to your files is finalized. Just over a dozen brands of anti-malware products can detect this threat, which, usually, will arrive with misleading names implying that it's safe for you to open. Users scanning their new files with anti-malware programs that could delete the Donald Trampo Ransomware immediately are less at risk of losing documents, pictures, and other media.
The Donald Trampo Ransomware may be of Russian creation or, simply, a Trojan built with mocking reference to ongoing political rumors. Whatever the case might be, it already is proving itself as a real danger to PC users on both sides of the Atlantic.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:file.exe
File name: file.exeSize: 716.8 KB (716800 bytes)
MD5: d971ace1a9209e1f1a6ceaf61b62a49c
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 1, 2017
file.exe
File name: file.exeSize: 697.34 KB (697344 bytes)
MD5: 057a4e354e1007b0048ca6af000f0717
Detection count: 38
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 4, 2017
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.