LANDSLIDE ransomware – a cryptovirus from a group that calls itself a “King Of Ransom”

LANDSLIDE ransomware is a cryptovirus that encrypts all data on the computer (backups, pictures, documents, archives) except for the system files and then demands a ransom for the promised decryption tools. This file-locking parasite uses AES and RSA[1] military-grade algorithms to accomplish the encoding.
At the very moment that the ransomware virus accesses a computer system, it starts the encryption, during which all non-system files on the device are renamed, appending a three-part extension. The first two parts of it consisting of an email address of the cybercriminals ([nataliaburduniuc96@gmail.com]) and the appointed victim ID ([id = ********]) are plated at the front of the file name. The .LANDSLIDE extension is appended at the end, right after the original file extension.
As soon as all of the personal data is encrypted and renamed, .LANDSLIDE file virus generates two ransom notes – a pop-up window, titled ReadThis.hta, and a text file, named ReadThis.txt. The message in both ransom notes is identical. You can see both of them at the bottom of this paragraph.
| name | LANDSLIDE ransomware, .LANDSLIDE file virus |
|---|---|
| type | Ransomware |
| Ransom note | Two ransom notes with identical content are created – ReadThis.hta and ReadThis.txt |
| Appended file extension | All non-system files are appended with a triple extension: [nataliaburduniuc96@gmail.com].[id = 01234567].filename.file_extension.LANDSLIDE |
| Preferred payment method | Cryptocurrency Bitcoins |
| Criminal contact details | Hackers provide two emails to contact them – nataliaburduniuc96@gmail.com and aliseoanal@gmail.com |
| Malware Removal | Victims shouldn't doubt for a second before removing the cryptovirus with a powerful anti-malware software |
| System fix | We recommend using the FortectIntego tool after malware removal to find and fix any registry or other irregularities within the system settings |
Within the ransom note, creators of LANDSLIDE ransomware let their victims know that all their data was encrypted and that the only way to unlock is by purchasing their decryption tool. To establish some fake trust between each other, they offer free decryption of one file from the infected computer. The file shouldn't exceed 200KB.
As usual with this type of malware, developers of the LANDSLIDE virus want to be paid in a cryptocurrency called Bitcoins. They school their victims to search on Google on how to obtain this cryptocurrency. Bitcoin wallet would be sent after the users establish contact.
To do that, the cybercriminals provide two email addresses. First, the victims should write to nataliaburduniuc96@gmail.com, but if they don't hear back from the LANDSLIDE ransomware makers within 24 hours, the victims should try sending another email to aliseoanal@gmail.com. The usual threats not to try renaming or decrypting the files aren't submitted.
As always, we strongly advise against establishing contact with cybercriminals. Instead, we suggest the victims remove LANDSLIDE ransomware from their infected computers and look for other data recovery options. To make sure malware is removed correctly, it should be done with trustworthy anti-malware apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.

Experts[2] recommend using a system repair software like the FortectIntego tool right after LANDSLIDE ransomware removal to ensure that computers' registry and other essential core settings and system files are unaffected by the cryptovirus.
Developers of the LANDSLIDE virus that call themselves King of ransom send this message with their ransom note:
Your SERVER / COMPUTER is encrypted by us! _
Hello Admin / Guest!
[ENCRYPTER] => All your data is encrypted by us ..
[ENCRYPTER] => Your Server Unique ID: [D2C85 ***]
[ENCRYPTER] => Do you want to decrypt your data?
[ENCRYPTER] => To trust us, first send us a 100-200 KB file,
we will decrypt it to build trust for you.
[AFTERTRUST] => What should you do after building trust?
Help
(
All your data is encrypted,
If your data is important and you want to decrypt it,
You must pay the bitcoin amount set by us,
Send a message to our emails first, after pricing, us and your trust,
Do a Google search to buy bitcoins,
For example: “Buy bitcoins in rubles”.
After purchasing Bitcoin, you must
transfer the Bitcoin to our wallet,
After payment, the decryption tool will be sent to you
along with how to execute it properly
)
ENCRYPTER @ server ~ $ To contact us, first send a message to our first email.
[FiRsT Email:] nataliaburduniuc96@gmail.com
ENCRYPTER @ server # If your email is not answered after 24 hours, our email may be blocked.
So send a message to our second email.
[SeCoNd email:] aliseoanal@gmail.comKing of ransom
LANDSLIDE Ran$omW4rE
Avoiding one of the most common ransomware distribution – file-sharing platform
Malware could be hidden in many places on the internet, but ransomware like Lisp, CryLock, Weui, etc., are mainly hidden in file-sharing platforms such as The Pirate Bay, BitTorrent, and others. Pages like these are used by cybercriminals because they can camouflage their creations as any something that would catch the eyes of soon to be victims.
Hackers disguise ransomware as the latest game cracks,[3] pirated software, game cheat codes, and so on. Malware could be downloaded to your device as any file type – .exe, .jpg, .txt, .zip, .pdf, etc. We advise refraining from using these kinds of sites altogether. Support your beloved game or software developers by purchasing their products either directly from them or their official distributors.

LANDSLIDE virus removal guide from affected computers
All malware should be dealt with swiftly with the help of professional anti-malware software as manual elimination isn't easy. Remove LANDSLIDE ransomware with time-proven apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to ensure that the cryptovirus with all of its particles are truly and properly deleted.
Unfortunately, LANDSLIDE ransomware removal will not unlock the encrypted personal files, but that doesn't mean that the victims should doubt for a second to delete it. Take care of the device's overall health and look for other data recovery options. Try using our suggestions at the bottom of this article.
When it comes to system repair, we recommend using a powerful FortectIntego system tune-up tool to perform a full system scan to find and repair any alterations that the file-locking parasite could have done to the computer's settings, such as the system registry and other.
Did this guide help?
Be the first to comment