Authors of Arena virus promise to decrypt files as soon as victims pay the ransom

Arena ransomware is a file-encrypting virus that is associated with the Dharma ransomware family. Ransomware usually gets inside the system via malicious email and starts data encryption. Once this procedure is over, all files are locked with .id-[ID].sindragosa@bigmir.net].arena file extension.
Following data encryption, the ransomware creates a FILES ENCRYPTED.txt document. It’s a ransom note that provides information about data encryption. According to the crooks, the only data decryption option – paying the ransom[1]. However, paying them might lead to money loss, so it is not recommended by security experts.
| Name | Arena ransomware |
| Type | File-locking virus, crypto-malware |
| File extension | .arena appended to each of the personal files |
| Ransom note | FILES ENCRYPTED.txt and a pop-up window titled Macgregor@aolonline.top |
| Detection | TR/Dropper.Gen, Trojan.Ransom.Crysis.E, Ransom-Dharma!F315C5467A60, Ransom.Win32.CRYSIS.SM, W32.Ransom.Gen, etc. More on Virus Total |
| Malware removal | Use reputable anti-malware software to eliminate the virus |
| System fix | Once ransomware is deleted, we recommend performing a full system scan with FortectIntego to avoid Windows reinstallation |
The message says that users have to contact cyber criminals:
all your data has been locked us
You want to return?
write email sindragosa@bigmir.net
Hackers obviously want the victim to buy Bitcoins and transfer them to their Bitcoin wallet[2] address. Once it's done, the decryption key should be delivered to the victim. Unfortunately, the Zondervirus.nl team says[3] that criminals cannot be trusted, so after paying the ransom, you might be left out with piles of encrypted files and no ways to decipher them.
Indeed, we receive victims' reports that hackers demanded even more money and did not receive a promised decryptor. Therefore, do not pay the ransom no matter how important your files are to you.
Hackers behind ransomware might scam you
Recently, we received information from a computer user who suffered from a virus attack. After contacting developers via sindragosa@bigmir.net, he was asked to pay 500 euros for data recovery, but criminals asked to transfer the same sum of money two more times. However, after spending 1500 euros, a victim did not receive a decryption key.
Therefore, we want to warn that this malware is created only for swindling the money from the computer users. Instead of keeping their promise, hackers demand to pay for more money and leave you without a possibility to decrypt files. Thus, do not waste your time and money dealing with cyber criminals.
Instead of paying the ransom, concentrate on Arena ransomware removal. We strongly recommend using anti-malware tools to complete the task, as it is the easiest and safest way to eliminate the ransomware.
Ransomware removal is a complicated task that can be completed by advanced IT experts and malware analysts only, so you shouldn’t attempt to remove the virus on your own.
Otherwise, such attempts can cause even more damage to your computer or convert your data into useless space-taking junk. To remove the virus, prepare your PC by rebooting it into Safe Mode with Networking (see instructions provided below) and use a software like FortectIntego or MalwarebytesMalwarebytes to identify and eliminate the threat.

CryptoMix Arena malware's relation with Crysis ransomware group
The beginning of the new academic year supposedly brought new inspiration to malware developers as well. Interestingly, this time, the developers of two well-known malware families – Crysis/Dharma and CryptoMix – presented quite a riddle for IT researchers.
They introduced the two latest versions of their root viruses. However, both of them append .arena file extension. Nonetheless, despite this feature, it is possible to tell a difference. Crysis variant will attach .id-[id].[email].arena form of attachment. The CryptoMix version renames the file with a hexadecimal string containing the same extension.
The contact information is also different. Crysis variant indicates chivas@aolonline.top and macgregor@aolonline.top email addresses for contact information while CryptoMix variant presents ms.heisenberg@aol.com. [4] What is more, the latest version is also much bothersome than the previous editions. It is programmed to delete shadow volume copies.
Besides the users' interface, the Crysis variant also launches the FILES ENCRYPTED.txt file with a brief note to contact the perpetrator. The rival version uses the _HELP_INSTRUCTION.TXT file to output ransom-demanding messages. At the moment, there is no decryption available for both versions. You can restore the data with the assistance of backups[5]. Whether you are infected with the Dharma variant or CryptoMix one, remove it and only then proceed to the data recovery procedure.
Ransomware might attack from malicious email attachment
The infamous ransomware family is known to be distributed via malicious emails that deliver deceiving messages with a file attached to them. Once the victim opens the infected file, Dharma roots into the computer system and destroys victim’s files using a sophisticated encryption.
This procedure can be reversed, sadly, only using a decryption key. Without the decryption key, there is no way to restore files.
You shouldn’t blame cyber security experts for not creating a decryption tool – encryption is an extremely secure method to protect files, so there is no wonder why it is used to keep military-grade secrets private. Usually, the one who encrypts files is the only one who knows how to decrypt them.
However, variants of Dharma ransomware can infiltrate your system alongside illegal downloads such as software cracks or with the help of exploit kits placed on compromised websites.
To protect your PC, use anti-malware software, create a backup and do not forget to get those software updates on time. You shouldn’t delay Windows updates, no matter how annoying they might seem to you.
Ransomware elimination steps
We have prepared a guide on how to remove Arena virus securely. The first thing that you need to do is to choose the software you’re going to use for removing the virus. Our recommendation is FortectIntego, SpyHunterCombo Cleaner and MalwarebytesMalwarebytes. If you have security software installed on your computer already, restart your PC into Safe Mode with Networking, install updates for your antivirus or anti-malware tool and let it scan your computer system thoroughly.
If you do not have security software yet, you can download it from the Internet after rebooting your PC into Safe Mode. Please use trustworthy software for ransomware removal.
Did this guide help?
Be the first to comment