NegozI is file-encrypting virus ransomware that uses AES-256 algorithm to encrypt your files. The ransom amount is huge 5 Bitcoins, which is currently about $3300. NegozI encrypts following file types: documents, images, game files, e-mails. Ransomware adds extension .evil to every encrypted file and also creates files "decrypt_your_files.txt" and "decrypt_your_files.html", that contain instructions to pay the ransom and decrypt files.
SecureCrypted (Apocalypse) is file-encrypting virus that demands ransom (0.5 and 1.5 Bitcoin) to decrypt infected files. Such type of threats is also called ransomware. After infection virus starts encrypting files of following extensions: .txt, .docx, .xlsx, .jpg, .png, .pdf and other. Those files are usually sensitive documents, photos, reports, books and other file types, that are important to regular people. Ransomware adds extension .SecureCrypted to every encrypted file and also creates files "yourfilename.Contact_Here_To_Recover_Your_Files.txt", that contains instructions to recover those files.
7ev3n Ransomware is a type of malware that was created to play on people’s fears and squeeze money for the creators. The ransomware once it arrived on the system encrypts the files and changes their extension to .r5a. When the encryption is finished the malware displays the pop-up message with the explanation of the situation and with further instructions.
LeChiffre Ransomware is drifting on the Internet since 2015 but hasn’t been closely analyzed until recently. The latest researches showed that the ransomware is surprisingly simple by its formation. To run this ingenious client the malware creators should launch it on a hijacked server to override the files for encryption. The encrypted files may be distinguished by the extension changed to .lechiffre. After the end of encryption process the cyber criminals will wipe all traces of their presence and leave the note with explanations and demands.
JobCrypter is a threat that belongs to the groups of ransomware. It is designed to affect files on the infected system and encrypt them demanding payment for the restoration. JobCrypter originates in France, however it has already spread around the world. JobCrypter works in the similar way with other ransomware: it detects the files with most popular extensions and encrypts them adding .locked extension, after which the malware creates a text file.