FileEncrypted ransomware – a dangerous crypto-virus that that demands payment in Bitcoin for file release

FileEncrypted ransomware is a file locking virus that was first spotted by security researchers in late July 2018. The malware uses AES-256[1] to lock up files and ads .FileEncrypted appendix. As soon as data is encrypted, the ransomware connects to Command & Control server, when then sends back a unique personal key and delivers a ransom note READ_TO_DECRYPT.html or FILES_ENCRYPTED.html. Victims are then informed about what happened to their data, and what should be done next. Hackers also provide a contact email (160505@tt3j2x4k5ycaa5zt.onion) and a bitcoin wallet address which should be used to pay 1BTC. According to security specialists, FileEncrypted ransomware is a variant of Cryptgh0st virus.
| Summary | |
| Name | FileEncrypted |
| Type | Ransowmware |
| A variant of | Cryptgh0st |
| File extension | .FileEncrypted |
| Encryption algorithm | AES-256 |
| Contact email | 160505@tt3j2x4k5ycaa5zt.onion |
| Ransom size | 1BTC |
| Distribution | Spam emails, malicious websites, etc. |
| Decryptable? | No |
| Detection and elimination | Use FortectIntego or MalwarebytesMalwarebytes |
FileEncrypted ransomware is capable of entering machines only when its main executable is launched. Unfortunately, hackers often use various tricks to make victim initiate this action. Criminals often send out malicious payloads hidden inside the phishing emails,[2] or inject them into file-sharing sites. Thus, being attentive online reduces the risk of FileEncrypted infection tremendously.
As soon as the FileEncrypted virus enters the device, it performs a scan to locate personal files. The targeted data includes:
- Databases
- MS Office documents
- Pictures
- Image files
- Video files, etc.
After locating files, the ransomware ads .FileEncrypted extension and replaces its name with random characters. For example, picture.jpg would be turned into isaj14dds.FileEncrypted. From this point, none of the data is accessible anymore, and users need to pay ransom for its release.
Cybercrooks demand 1 BTC for file release, as it is stated in the ransom note:
YOUR FILES HAVE BEEN ENCRYPTED USING A STRONG ALGORITHM.
YOUR IDENTIFICATION IS –
SEND 1 BTC TO THE FOLLOWING BITCOIN WALLET ADDRESS 1EATMEBVDRmUPjaBeN9hsoj2ffFiUKArma
AND AFTER PAY SEND EMAIL TO 160505@tt3j2x4k5ycaa5zt.onion SENDING YOUR IDENTIFICATION AND BITCOIN TRANSACTION ID TO RECOVER THE KEY NECESSARY TO DECRYPT YOUR FILES
Nevertheless, users should never agree to pay and remove FileEncrypted ransomware instead.
Hackers actively disagree with FileEncrypted removal, and state that the access to files will be permanently lost if such attempt is performed. Do not listen to them, as you can get your data back from backups or try third-party tools (we explain how to use them below).
However, we do not recommend trying to get rid of FileEncrypted ransomware manually. Malware performs multiple changes to the computer and professional help is required to recover its full functionality. Therefore, pick anti-virus software (such as FortectIntego or MalwarebytesMalwarebytes) and perform a full system scan.

Beware of spam emails – they might hide ransomware virus inside
Users are typically unaware of how malware is injected into machines, that is why they are so careless about it. Unfortunately, once it is in, reverting the damage might be impossible. Therefore, it is vital to know how to protect yourself from dangerous viruses like ransomware.
Security researchers[3] urge users to follow these simple security tips:
- Be suspicious of every email you find in your inbox. Many phishing emails are easily recognizable, although some of them can trick even those who are relatively tech-savvy. Thus, do not open attachments or click links inside an email before making sure that they are legitimate;
- Make use of a reliable anti-virus program and keep it updated at all times;
- Keep your operating system and other installed software updated;
- Do not visit questionable websites and do not click on dubious advertisements;
- Keep a backup of your files.
By following these simple rules, you will be able to minimize the chances of getting infected with a devastating computer virus.
Eliminate FileEncrypted ransomware using security software
FileEncrypted removal might be difficult, as some crypto-viruses may block proper operation of security software. Nevertheless, it is possible to bypass this functionality by entering Safe Mode with Networking mode. In this mode, only essential drivers are launched for the system to operate, so the functionality of malware is disabled.
Do not try to remove FileEncrypted ransomware manually, as the virus made several changes to your system. To revert them, you need an extensive computing knowledge. Therefore, leave this process to powerful security software, such as FortectIntego or MalwarebytesMalwarebytes.
As soon as .FileEncrypted elimination is performed, you could get your data back by using backups or by using third-party software.
Did this guide help?
Be the first to comment