Msf ransomware – a cryptovirus that renames files by appending a triple extension

Msf ransomware is a computer virus that encrypts all data on an infected machine, encrypts it, and then demands a ransom. This cryptovirus renames all personal files by appending a triple extension to their original filenames. This extension consists of appointed user ID, criminal's contact details in brackets [metasploit@post.com], and the .msf appendix.
After the encryption process, the malware creates ransom notes. One shows up as a pop-up window; others are scattered around the infected device as text files, named FILES ENCRYPTED.txt. Both ransom notes contain instructions and cybercriminals' contact information.
Msf virus belongs to the Dharma ransomware family that has been frightening everyday computer users since 2016. Our study shows that at least one new member of this family is spotted each week. Cryptoviruses from this lineage have their similarities but have their differences too.
| name | Msf ransomware |
|---|---|
| type | Ransomware |
| Family | Dharma ransomware |
| Ransom note | FILES ENCRYPTED.txt and a pop-up window |
| Appended file extension | All original filenames appended with a specific user ID, metasploit@post.com, .msf extension |
| Criminal contact info | metasploit@post.com, metato3sploit@gobv2.eu |
| Infection removal | Ransomware should be removed with professional anti-malware software to ensure its complete elimination |
| System health | System repair tools like the FortectIntego should be used to take care of the health of the device to ensure it's running smoothly |
Like all of its predecessors, such as GLB, SUKA, ZIN, and many others, text ransom notes of Msf ransomware are uninformative and only provide contact details. The pop-up window gives a lot more insight into what's going on. Cybercriminals start off by stating that all data was encrypted, and they're the only ones that can undo that.
Two emails are provided to establish contact – metasploit@post.com, metato3sploit@gobv2.eu, and the victims are urged to do it fast because the ransom price depends on that. Although the amount isn't specified, the assailants would like to be paid in cryptocurrency Bitcoins. Cybercriminals provide extensive details about how to obtain them.
To persuade infected computer users into paying the ransom, the criminals offer a free decryption guarantee. Victims may choose one file from the infected device and send it to the creators of the Msf virus. They would decrypt it and send it back, thus providing proof that such a decryption tool exists.
There might be other data recovery options available. Victims of cyberattacks should never meet the perpetrators' demands because that finances their research for more sophisticated means of infection and motivates them to increase the frequency of their attacks.
Run a full system scan and remove Msf ransomware with professional and trustworthy anti-malware software like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. Malware might sometimes disrupt the normal function of security tools, so you might be forced to access Safe Mode with Networking – we explain how below. Keep in mind that the scan should be performed with the most up-to-date versions of the security software, otherwise malware might not be detected.

File-locking viruses are capable of corrupting various system files and settings. To undo those changes, it is highly recommended to perform a system sweep with Windows repair tools like the FortectIntego, which might revert all alterations with a push of a button.
Message in the text file ransom note (FILES ENCRYPTED.txt):
all your data has been locked us
You want to return?
Write email metasploit@post.com or metato3sploit@gobv2.eu
Creators of Msf virus show this message in the pop-up window:
All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail metasploit@post.com
Write this ID in the title of your message –
In case of no answer in 24 hours write us to theese e-mails:metato3sploit@gobv2.eu
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.
Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
File-sharing platforms – a lair for malware
From RDP attacks to spam emails, there are different ways malware could get access to your devices. Cybercriminals bend over backward to finding new ways and trying to trick everyday computer users. One of the most common ways to get infected is to use file-sharing platforms like torrent sites.
Torrent sites are a very suitable place for cybercriminals to hide their “products” because no one is inspecting what's uploaded and being offered. Hackers can camouflage ransomware as new game cracks, pirated software, or anything else that would catch the attention of an unaware user.
Ransomware could be hidden as practically any file type – .zip, .rar, .jpeg, .docx, .txt, etc. As soon as a torrent with an infectious file is downloaded, the infection might start within minutes. So for your own safety, please refrain from using file-sharing platforms.
Guide to remove Msf ransomware with anti-malware tools
Having any kind of malware[1] on your devices is a very big risk, as having one type of malware can lead to further infections. One of the most important things for computer users to evade malware is to have reliable anti-malware software like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner to watch their backs.

We recommend users to remove Msf ransomware with either of the two aforementioned or similar apps. Research shows,[2] that 58 of 70 anti-virus engines caught this cryptovirus and prevented infections. This reiterates the need for trustworthy software.
Malware might damage the system registry and other core settings and files, so after Msf ransomware removal, experts[3] recommend performing a system tweaking with powerful system repair tools like the FortectIntego to undo these modifications.
Did this guide help?
Be the first to comment