Estemani ransomware – a file-locking threat that adds no extension to encrypted data

Estemani ransomware is a ransom-demanding malware that emerged at the second have of August and appears to encrypt data by adding no appendix to the file names. However, criminals focus on English-speaking users and aim to launch an English-based ransom message that comes in a text document named HOW_DECRYPT_FILES.txt. The spreaders of Estemani virus announce that various files have been locked with the mixture of RSA 2048 and Salsa20[1] algorithms and the only way to reverse them back to their previous states is by purchasing the decryption software straightly from the hackers for a price of 0.75 BTC. Additionally, the estemaniii@airmail.cc email address is provided as the way to contact the crooks.
| Name | Estemani |
|---|---|
| Type | Ransomware |
| Appendix | No extension is added to the locked files |
| Note | HOW_DECRYPT_FILES.txt |
| Price | 0.75 BTC is urged for the data recovery software |
| estemaniii@airmail.cc is the way to contact the hackers | |
| Target | English-speaking people |
| Cipher used | RSA 2048 and Salsa20 |
| Removal | Use FortectIntego to discover all malware-laden objects on your computer system. Continuously, use only automatical software to remove the ransomware virus |
Estemani ransomware might carry a more complex module than we might think. For example, some ransom-demanding threats are capable of erasing Shadow Volume Copies and making the decryption process harder to carry out so that the victims will end up buying the crooks' offered decryption software instead.
In addition, some malware such as Estemani ransomware can carry other malware attached to themselves. This way you can end up with a notorious Trojan horse or cryptocurrency miner on your computer system. Avoid such dangerous possibility by terminating the ransomware virus immediately.
Besides, do not fall for believing in the claims that are provided by Estemani ransomware as you cannot be guaranteed that by paying the demanded ransom price you will truly receive the decryption tool. Here is how the message looks like:
Greetings,
We are pleased to announce successful encryption of your machine.
All the hosts in your network have been encrypted with FUD and powerful encryption algorithm(s) – RSA-2048 + Salsa20.
Any attempt to decrypt data by yourself is futile.
Read more:Wikipedia · ENRSA cryptosystem
The RSA (Rivest–Shamir–Adleman) cryptosystem is a family of public-key cryptosystems, widely used for secure data transmission. The initialism "RSA" comes from the surnames of Ron Rivest, Adi Shamir and Leonard Adleman, who publicly described the algorithm in 1977. An equivalent system was developed secretly in 1973 at Government Communications Headquarters (GCHQ), the British signals intelligence agency, by the English mathematician Clifford Cocks. That system was declassified in 1997.
Read on Wikipedia →Wikipedia · ENSalsa20
Salsa20 and the closely related ChaCha are stream ciphers developed by Daniel J. Bernstein. Salsa20, the original cipher, was designed in 2005, then later submitted to the eSTREAM European Union cryptographic validation process by Bernstein. ChaCha is a modification of Salsa20 published in 2008. It uses a new round function that increases diffusion and increases performance on some architectures.
Read on Wikipedia →
The cost for decryption begins from 0.75 Bitcoins (BTC) and depends on your business size.
Email address: estemaniii@airmail.cc
HOST ID: XXCLO***
To avail decryption software and service send details about unique HOST ID and the contact email address and Follow the instructions for hassle free decryption process.
Note: The Host ID and Email addresses are unique and private. Any leak of information will result in direct ban to our services.
We won’t be responding to any communications about free decryption. We follow simple business policy – No Money! No Decryption.
Estemani ransomware removal can be carried out with the help of automatical software. However, first, you have to reboot in Safe Mode with Networking to ensure that no malicious processes are running on your computer system. Continuously, perform a full machine scan with FortectIntego to locate all malware-laden objects.

Estemani ransomware is not the type of program to play with as the longer you keep it on your computer, the bigger the damage might be. Besides, keep in mind that you might find malicious processes left by this malware in the Windows Task Manager and Windows Registry[2] sections in the form of entries, keys, files, tasks, etc.
After you remove Estemani ransomware, you can take a look at the data recovery software that we have provided at the end of this article. Furthermore, note that precautionary measures for avoiding similar incidents in the future are necessary to take. Keep on reading and figure out what kind of steps you can take to move towards full machine safety.
Email spam – the most liked place by ransomware spreaders
Experts from Virusai.lt[3] claim that email spam campaigns are the ones that spread ransomware viruses and other malware forms very often. Due to this fact, it is very important to manage all of your received emails. This means, identifying the sender, checking the message for possible grammar mistakes, scanning all attached files with antivirus software.
In addition, the malicious payload can be delivered through unsecured domains of gambling, online-dating, gaming, and porn-watching websites. Here you need to be careful of questionable-looking hyperlinks and adverts. However, the best thing to do would be not to visit such directories ever at all.
Continuously, installing reliable security software into your computer system is also a necessary step to take. Choose a reputable tool and ensure that you update it regularly, otherwise, the program might start failing.

Estemani ransomware removal + decryption process
Estemani ransomware removal is a necessary step to take before you start thinking about data recovery possibilities. Note that the automatical technique is the only way to get rid of the dangerous cyber threat as manual elimination has been found to be an unsafe and struggling task for many users. Besides, scanning the entire system for potential infection sources is also a good thing to do. Carry out the process with FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes.
After you remove Estemani ransomware and infection strings are lurking in your system no more, you can start viewing data restoring solutions that are presented below this paragraph. Besides, keep in mind that you have to protect your future information also. For this purpose, purchasing a portable drive and keeping files there is a good choice to make. Also, you can drag copies of important data to a remote server, for example, iCloud or Dropbox.
Did this guide help?
Be the first to comment