GlobeImposter 2.0 ransomware is a dangerous old cryptovirus that keeps spreading in 2021

GlobeImposter 2.0 is a file-encrypting virus that is an updated version of Globe Imposter. The previous ransomware is a copycat of Globe ransomware. This file-encrypting malware has numerous versions, and the recent one was detected in March 2019. Once installed on the system, GlobeImposter 2.0 virus might bring the cmd.exe file to the system, inject dubious registry keys in the Windows Registry, and starts encrypting all data that is found on the infected computer system.
The most recent variant of this ransomware appends the .{mattpear@protonmail.com}MTP extension to each locked document. It also delivers a ransom message to inform the user about the secret encryption and discuss all matters about the decryption key's price. If you are infected with this dangerous ransomware, you are very likely to receive a message named HOW_OPEN_FILES.hta or how_to_back_files.html.
| Name | GlobeImposter 2.0 |
|---|---|
| Previous version | Globe Imposter |
| Extension | .{mattpear@protonmail.com}MTP is the latest one. The virus can also append extensions such as .rose, .ocean, .pizdec, .Dragon4444 etc. |
| Ransom note | HOW_OPEN_FILES.hta or how_to_back_files.html |
| Ransom | Crooks demand BTC currency |
| Distribution | Unsafe pages, spam messages, and their infected payload |
| Decryption | Some files can be recovered with the original decryptor |
| Detection possibilities | FortectIntego can help you by detecting malicious content in the infected system |
It is also known for other very active file extensions added to the encrypted files. One of the most widespread was .Dragon4444 file extension that has encrypted thousands of victim files and left them helplessly reading the note saying
YOUR FILES ARE ENCRYPTED !!!
TO DECRYPT, FOLLOW THE INSTRUCTIONS:
To recover data you need decrypt tool.
To get the decrypt tool you should:
1.In the letter include your personal ID! Send me this ID in your first email to me!
2.We can give you free test for decrypt few files (NOT VALUE) and assign the price for decryption all files!
3.After we send you instruction how to pay for decrypt tool and after payment you will receive a decryption tool!
4.We can decrypt few files in quality the evidence that we have the decoder.DO NOT TRY TO DO SOMETHING WITH YOUR FILES BY YOURSELF YOU WILL BRAKE YOUR DATA !!! ONLY WE ARE CAN HELP YOU! CONTACT US:
China.helper@aol.com
The appearance of new versions of GlobeImposter 2.0 is related to the fact that malware researchers immediately crack the code of ransomware and create decryption software. Thus, criminals have nothing else left to do, just to try again. The first poor copy of Globe was quickly beaten by the security team from the Emsisoft[1].
Experts found the flaw in the virus’ code and used it to create a decryption software. The second version of the ransomware[2] continues the work of the predecessor. However, crooks created several more updates for Globe Imposter and they have been spreading throughout the Internet sphere nowadays.
Globe Imposter 2.0 virus aims at 34 file types, including documents, text files, pictures, multimedia, etc. Using AES cryptography, it locks targeted files with one of these files extensions:
|
|
The original version of Globe Imposter 2 present data recovery instructions in HOW_OPEN_FILES.hta file which is dropped on the system as soon as encryption process is over. However, other variants might use different names of a ransom note. For instance, the latest version delivers the how_to_back_files.html file.

In the ransom note, crooks demand to pay from 1 to 10 Bitcoin and send a screenshot to the alex_pup@list.ru. However, security experts noticed that cybercriminals use numerous other emails to communicate with the victims. Some of them might be:
- keepcalmpls@india.com;
- happydaayz@aol.com;
- strongman@india.com;
- byd@india.com;
- xalienx@india.com;
- 511_made@cyber-wizard.com;
- btc.me@india.com;
- parbergout@keemail.me;
- parbergout@india.com.
The GlobeImposter 2.0 ransomware ransom message looks like this:
Your files are encrypted!
Your personal ID
***
All your important data has been encrypted. To recover data you need decryptor.
To get the decryptor you should:
pay for decrypt:
site for buy bitcoin:
Buy 1 BTC on one of these sites
1. https://localbitcoins.com
2. https://www.coinbase.com
3. https://xchange.cc
bitcoin adress for pay:
jlHqcdC83***:
Send 1 BTC for decrypt
After the payment:
Send screenshot of payment to alex_pup@list.ru . In the letter include your personal ID (look at the beginning of this document).
After you will receive a decryptor and instructions
Attention!
• No Payment = No decryption
• You realy get the decryptor after payment
• Do not attempt to remove the program or run the anti-virus tools
• Attempts to self-decrypting files will result in the loss of your data
• Decoders other users are not compatible with your data, because each user's unique encryption key'
However, after GlobeImposter 2.0 ransomware attack, we do not recommend rushing to learn everything about buying and transferring demanded Bitcoins[3]. We clearly understand that paying the ransom may seem like the only possibility to get back all your pictures, photos, audio or movie collections, or other important documents. However, there are many cases when developers of the ransomware took the money and left victims without their files.
In order to save money, you should concentrate on the GlobeImposter 2.0 removal instead of data recovery. The previous version was quickly decrypted; hence, the chances are high that the decrypter for the second variant will be created as well. Meanwhile, you can use alternative recovery methods.
The only safe way to remove GlobeImposter 2.0 virus is to employ professional security software. We highly suggest dedicating this task for FortectIntego. If you cannot install or update the security tool, you have to disable this crypto-malware first. The instructions at the end of the article will show you how to do it.

Malicious spam emails are the main ransomware distribution method
The majority of the file-encrypting viruses use the same distribution campaigns, and malicious spam emails stay the number one method. Many computer users still cannot differentiate between safe and infected emails[4]. Indeed, sometimes cyber criminals manage to create perfect copies of official emails.
However, safe emails rarely end up in the spam folder. What is more, fake emails often lack credentials, have lots of grammar or spelling mistakes, and might be sent from a suspicious email address. The affected emails usually have subject lines or attached documents named as “Payment Receipt,” “Invoice,” “Voice Message Attached” or “Scanned Image.” Thus, always double-check the information before opening these files.
Globe Imposter 2.0, as well as other ransomware viruses, might spread via infected websites, malware-laden ads[5] or exploit kits too. Therefore, you should not visit suspicious and potentially dangerous sites, avoid clicking ads that offer great deals and especially software updates or downloads. Lastly, strengthen your computer’s privacy by installing a reliable antivirus program.[6]
Delete GlobeImposter 2.0 ransomware automatically
Just like other file-encrypting viruses, this malicious program has to be removed using reputable security software. For the GlobeImposter 2.0 removal we recommend FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These professional tools are capable of identifying and deleting malicious programs effectively. Additionally, they are able to detect all components that might be missed by the human eye.
If you cannot install or run security software, you should reboot the computer to the Safe Mode with Networking. This method helps to disable the virus and perform automatic elimination. We want to point out that trying to delete malicious components manually may lead to irreparable damage to the system. So, you should clean your PC with reputable software only and remove GlobeImposter 2.0 virus without causing any further harm to your machine.
Did this guide help?
3 comments
pank
I hope they wont create a third and successful version of the virus
Allit
It wasnt hard to remove
renata
it would be nice to get a decrypter...