Horsia ransomware – a new strain of the infamous Scarab ransomware virus

Horsia ransomware is a file-encrypting malware[1] that belongs to the group of Scarab. It renders AES cryptography and appends a .horsia@airmail.cc file extension to targeted data. The attacked PC users are provided with a HOW TO RECOVER ENCRYPTED FILES.TXT file, which contains contact information and payment instructions. Criminals urge victims to email them asap via horsia@airmail.cc or saviour@airmail.cc addresses and transfer an indicated sum of money in Bitcoin cryptocurrency.
| Name | Horsia |
|---|---|
| Type of malware | Ransomware |
| Contact information | horsia@airmail.cc or saviour@airmail.cc |
| File extension appended | .horsia@airmail.cc |
| Ransom note | HOW TO RECOVER ENCRYPTED FILES.TXT |
| Distribution | Necurs botnet, malicious spam email attachments, fake software installers, etc. |
| Elimination | Download FortectIntego and run a full system scan to eliminate all ransomware components. |
Most of the Scarab ransomware versions, including Scarab-Amnesia, and Scarab-Crypto, Scarab-Please, Scarab-Decrypts, and others are disseminated on the Internet via Necurs botnet,[2] 7Zip files attached to spam email messages, fake Java, Adobe Flash Player updates, hacked RPD, and other misleading ways. Horsia ransomware is not an exception. Its developers can try to distribute it using one or several methods. Therefore, protect yourself by installing a professional anti-malware program and keeping the OS up-to-date.
For the ransomware to get inside, PC's owner's interference is needed. In other words, the user has to run Horsia ransomware virus payload, which may be named as horsia.exe or another randomly named .exe file.
Once activated, the ransomware runs malicious scripts to install itself to the system and then runs through system's files to detect compatible file extensions. Based on the data collected about Scarab, Horsia virus is expected to lock most of the file types with the .horsia@airmail.cc file extension. Subsequently, the icons of the encrypted files are greyed featuring no file-presenting image.
The ransomware generates the ransom note called HOW TO RECOVER ENCRYPTED FILES.TXT by default. Typically, it can be found on the desktop, but crooks often inject it in each system's folder to make sure that the victim sees it. The ransom note contains the following information:
=======================================
________________________________
/ __/ / / __ / / __ / / __/ / __/ / __ /
/ __ / / /_/ / / _/ /__ / _/ /_ / __ /
\/ __/ \___/ \/\__\ \___/ \___/ \/ __/
=======================================
Your files are now encrypted!
Your personal identifier:
6A02000000000000***C4BFD00
All your files have been encrypted due to a security problem with your PC.
Now you should send us an email with your personal identifier.
This email will be as confirmation you are ready to pay for a decryption key.
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us.
After payment, we will send you the decryption tool that will decrypt all your files.
Contact us using this email address: horsia@airmail.cc
If you don't get a reply or if the email dies, then contact us to saviours@airmail.cc
Free decryption as a guarantee!
Before paying you can send us up to 3 files for free decryption.
The total size of files must be less than 10Mb (non-archived), and files should not contain valuable information (databases, backups, large excel sheets, etc.).How to obtain Bitcoins?
* The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins,' and select the seller by payment method and price:
https://localbitcoins.com/buy_bitcoins
* Also you can find other places to buy Bitcoins and beginners guide here:
http://www.coindesk.com/information/how-can-i-buy-bitcoinsAttention!
* Do not rename encrypted files.
* Do not try to decrypt your data using third-party software; it may cause permanent data loss.
* Decryption of your files with the help of third parties may cause increased price (they add their fee to our), or you can become a victim of a scam.
=======================================
Although crooks try to prove to be credible, do not fall for the trick. They claim to decrypt three files encrypted by Horsia ransomware virus for free. These files should not exceed 10Mb and should not be archived. We believe that they will send those three files for you. However, there's still no guarantee that paying the ransom will save the rest of your files.
To protect yourself from both file and money loss, we strongly recommend you to remove Horsia from the system right after the attack. You can do that with the help pf FortectIntego, SpyHunterCombo Cleaner, MalwarebytesMalwarebytes or another reputable anti-virus program.
Upon Horsia removal, try to retrieve your files using alternative methods. First of all, we would strongly recommend you to contact Doctor Web[3] via emte@adc-soft.com. In April 2018, the company officially announced being able to decrypt some of the Scarab ransomware versions. For this purpose, the owner of the compromised PC should send a ransom note and 3-4 encrypted files.
In case Horsia decryptor suggested by Doctor Web did not work, you still have many possibilities to get your files back. For more information, refer to the data decryption section at the end of this post.

Developers rely on spam in particular
Just like the original version, this ransomware relies on spam (7Zip and similar attachments), fake Java and Adobe Flash installers, unprotected remote desktop services, and other stealthy malware distribution strategies.
The most successful campaign to deliver the malicious file to potential victims is spam. Crooks present the infected email attachments directly into people's inboxes and resent them in a tricky manner impersonating authorities or well-known companies.
Typically, crypto-malware developers do not confine their programs to one distribution mean. Thus, cybersecurity experts[4] recommend people to mind online security tips to keep yourself safe. First of all, do not take every email for granted. Second of all, bypass doubtful pop-up ads and avoid installing software and updates from unconfirmed sources.
Get rid of Horsia ransomware
The only one possibility to initiate Horsia removal – run a full system scan with a reputable anti-virus. Before the scan, don't forget to update your anti-virus to the latest version available. Besides, restart your PC into Safe Mode with Networking.
Upon successful removal, follow data recovery instructions that are given down below. You can use third-party data recovery tools, exploit Volume Shadow Copies or Previous Windows versions.
Did this guide help?
Be the first to comment