New Globe version – Grapn206@india.com – is here
It seems that the authors of Globe ransomware have been on a roll as they recently introduced Grapn206@india.com virus. This new version has been named so after the appended file extensions – .grapn206 or .grapn206@india.com. Such recent activity alerts the virtual reality of exercising more caution while surfing the vast spaces of the Web. If you were reckless enough to open the infected spam attachment, we recommend you to start Grapn206@india.com removal right away. Since the authors decided to compete with other ransomware in the market, the new versions of Globe, such as Duhust, x3m Globe ransomware, and Kyra virus, present a riddle for IT experts. Only when you remove Grapn206@india.com fully, shift to data recovery procedure. FortectIntego is one of the options to eliminate the virus fully. More information is provided below.
Taking a look back at previous versions, the developers remains loyal to employing the encryption technique – AES-256 and RSA-1024 algorithms. Likewise, the data is encoded with a public key and the only viable method to decrypt is to acquire the private key. At least, that is what the authors of Grapn206@india.com malware want you to think so. As we have already advised users on multiple other file-encrypting cases, it is futile to expect the retrieval of the files since the racketeers earn millions of dollars from users desperately trying to return the files. As the cases of Locky, Cerber, and CryptoLocker reveal, few reports exist of returned data. What is more, Grapn206@india.com ransomware is another product of notorious gang of hackers who continuously have struck the virtual community with @india.com themed file-encrypting viruses.

Interestingly, that the ransomware binary lies in lolka.exe1. It is likely to hide in a counterfeited spam email which was sent from an official institution. After the execution, the payload is extracted, and the malware starts its misdeed. It targets the files in several locations:
- %AppData%
- %Roaming%
- %Temp%
- %Local%
- %User’s Profile%
- %Windows%
The transmission preferences
Like other @india.com viruses, this cyber infection mainly fishes for new victims via spam messages. Recently, as the notorious viruses rocketed again, there has been a surge in spam emails. Beware of fake Amazon, eBay or other shopping-related emails. Cyber criminals forge a message and ask to open the attachment containing important information about the delivered goods. Alternatively, some crooks employ psychological terror to make victims comply with their demands. Even if you spot the email from OPM or FBI or shopping website, look for some grammar mistakes and typos. Moreover, in some cases, even the sender‘s email might alert you to stay vigilant. Likewise, you might lower the risk of Grapn206@india.com hijack. Verify the sender before proceeding further.
Terminating Grapn206 malware
Taking into account Globe‘s evolving versions, manual elimination might not give expected results. In that case, we recommend you to opt for automatic Grapn206@india.com removal method. For that reason, you will require an anti-spyware application, for example, FortectIntego or MalwarebytesMalwarebytes. They are perfectly compatible with anti-virus utilities. Thus, after you install the malware removal application, update and run the scan. Likewise, it will able to remove Grapn206@india.com virus completely. If you notice that the malware locked your screen or you simply cannot run the security programs, do not panic and use the following instructions to regain access.
Was this guide helpful?
3 comments