14x ransomware – a new file-encrypting computer virus from the Dharma family

14x ransomware is a cryptovirus whose sole purpose is to extort money in the form of cryptocurrency for encrypting files on victim devices with a military-grade coding algorithm. During the encryption, all non-system data (databases, backups, documents, pics, and so on) are renamed by adding .id- appointed user ID.[axitrun@cock.li].14x extension to their original filenames.
Like all cryptoviruses from the Dharma ransomware family, as soon as the file locking is done, 14x virus generates two types of ransom notes, a pop-up window, and FILES ENCRYPTED.txt text files that are placed on the desktop. This type of note's main goal is to convince the victim that there's no chance to regain the data apart from purchasing a decryption toolkit from the assailants.
| name | 14x ransomware |
|---|---|
| type | Ransomware, cryptovirus |
| family | Dharma |
| Ransom note | FILES ENCRYPTED.txt, pop-up window |
| Appointed file extension | .id- appointed user ID .[axitrun@cock.li] .14x extension |
| criminal contact info | axitrun@cock.li, axitrun@tutanota.com |
| Distribution | Spam emails, file-sharing platforms, deceptive ads |
| virus removal | Reliable anti-malware software should be used to eliminate any malware completely |
| System Repair | Fix any system irregularities caused by the cryptovirus by using a powerful system repair tool like the FortectIntego app |
Cybercriminals use ransom notes to persuade their victims into meeting their demands. Various techniques are being used in these notes, such as a countdown timer indicating how much time has left the pay the ransom, discounts on the payoff amount if paid during a specific interval of time, and others.
Ransom notes from the developers of 14x ransomware are quite short and uninformative, as neither the amount nor the preferred payment methods are specified. However, we can speculate the assailants would like the ransom to be paid in cryptocurrency Bitcoins.
Message in the pop-up window states:
YOUR FILES ARE ENCRYPTED
Don't worry,you can return all your files!
If you want to restore them, follow this link:email axitrun@cock.li YOUR ID –
If you have not been answered via the link within 12 hours, write to us by e-mail:axitrun@tutanota.com
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
Whereas this message can be found in the FILES ENCRYPTED.txt ransom note:
all your data has been locked us
You want to return?
write email axitrun@cock.li or axitrun@tutanota.com
Victims of ransomware attacks should avoid paying the demanded money. Nor should they contact their assailants even to please their curiosity by finding out what the ransom sum might be. Money gained from ransomware victims inspires hackers to infect more computers and provides finances to do that. Despite this, it is understandable that some users might not have another choice.

However, if you decide to pay, keep in mind that the following scenarios may occur:
- Threat actors behind the attack disappear
- No decryption tool/key is delivered
- The sent decryption software doesn't work
- More malware is sent, further infecting the device
- More money is asked to be forwarded
The FBI asks[1] to stop paying the criminals, as it's the only way to stop ransomware spread. So, therefore, we urge our readers to remove 14x ransomware from their infected computers. Use dependable anti-malware software such as MalwarebytesMalwarebytes or SpyHunterCombo Cleaner to accomplish this task properly.
Having in mind that usually, file-locking parasites make various changes to the Windows Registry and other key system settings and files, we recommend using the FortectIntego app to revert them, so your device wouldn't exhibit any abnormal behavior.
Avoiding one of the biggest nesting grounds of ransomware – file-sharing platforms
Cybercriminals are constantly creating more improved malware delivery techniques, such as drive-by downloads,[2] where the soon to be victims don't even have to click on anything when redirected to a malicious site with malware scripts embedded in the website itself.
Still, our research shows that one of the most widespread methods to deliver ransomware payload files is by using file-sharing platforms. Threat actors prefer this technique for several reasons. One of them is that no one is scanning the uploaded/shared content, so all kinds of malware can sit there for an extended period of time.
Cyberthieves think of an alluring name that would catch a user's eye, such as unlocked commercial software or a crack (illegal activation tool) for the latest game, and share it. As soon as a user downloads such a camouflaged file, an infection starts if anti-malware software doesn't prevent it.
We suggest withholding from using file-sharing platforms, especially the popular torrent websites like The Pirate Bay, eMule, and others. Support your desired software developers by purchasing their products either directly from them or official distributors.
Directions for 14x ransomware removal with anti-malware software
14x ransomware has many previous versions such as Hub virus, Aol virus, yoAD virus, Bip virus, and others. And all of them should be eliminated from the infected devices the same way, by using a trustworthy anti-malware software such as MalwarebytesMalwarebytes or SpyHunterCombo Cleaner.

Although manual 14x ransomware removal is possible, it's not recommended to less experienced users as it might be a tough task to take on. Perform a full system scan with anti-malware tools and delete any suspicious files that the software detects.
Once you remove 14x ransomware, the next step is to take care of the system's health since cryptoviruses tend to modify various system files, which could lead to irregular system performance. Experts[3] suggest using the FortectIntego system repair app to fix any system-related issues.
Did this guide help?
Be the first to comment