PayDay ransomware is a cryptovirus that delivers a new version of file-encrypting malware in 2019 that demands for 200$

PayDay ransomware is a malicious program spotted spreading at the end of 2016 and continuously releasing new versions up til 2019. Originally, it targets Portuguese computer users. However, hackers keep releasing this crypto malware all over the world. One of the variants – Sexy ransomware was discovered in November 2017 but after that more versions have surfaced. Payday virus is based on the HiddenTear[1] and uses AES cryptography. While the first version appends .sexy, other version attaches .[email]-id-id.payday file extension or appendix formed in a ransom character pattern with 6 letters to each encoded file. You may recover access to your data by using either standard or brute-force HiddenTear decryptor. But malicious actors modify their products to make them immune to previously released decryption tools. The newest variant of PayDay ransomware delivers HOW_TO_DECRYPT_MY_FILES.txt file as a ransom note and demands 200$ for decryptor.
| Name | PayDay ransomware |
|---|---|
| Type | Cryptovirus |
| Ransom note | HOW_TO_DECRYPT_MY_FILES.txt; !! RETURN FILES !!.txt |
| Known since | 2016 |
| Ransom amount | 200$ |
| File extension | .[email]-id-id.payday; .sexy; .random-6-letters |
| Cryptography | AES encryption algorithm |
| Distribution | Spam email attachments |
| Elimination | Use powerful antivirus to remove PayDay virus and clean the system using FortectIntego |
While PayDay encrypts data, you might notice system slowdowns. The computer can slow down for many different reasons, and ransomware is definitely not the first thing that comes to mind.
Once the PayDay ransomware virus renders all target files into useless pieces of data, it creates a HyperText Markup Language format file called !!!!!ATENÇÃO!!!!!.html and saves it on user’s desktop. The ransom note opens via a web browser and explains (in Portuguese) that files have been encrypted, and now the victim needs to pay up if he/she wants to see or use them ever again.
The PayDay malware asks for R$950, which is approximately 286 USD. The virus refuses to receive the ransom in any other currency but Bitcoins, as this way authors of this ransomware can receive money and stay anonymous. Perpetrators leave a contact email address in case the victim wants to ask something – CatSexy@protonmail.com.
You shouldn’t fall for ransomware threats and get rid of this virus as soon as you can because it is yet another decryptable HiddenTear variant. Remove PayDay using guidelines given below and then prepare for data decryption process, which will convert all .sexy files into normal ones.
To eliminate this crypto-malware, you have to obtain a professional antivirus or malware removal tool, such as FortectIntego or MalwarebytesMalwarebytes. However, you should also check PayDay ransomware removal guide at the end of the article to learn how to succeed in this task.
Sexy ransomware might be an offspring of the latter malware
Sexy virus attaches .sexy file extension to the encoded data as well. While the amount of the ransom remains not indicated, the cybercriminals insist on contacting via sexy_chief@aol.com e-mail address to settle the price for a decryption tool.
Besides, victims are allowed to send one file for a free decryption that doesn't contain any valuable information. Even though crooks try to earn people's trust, we recommend you to focus on the Sexy removal instead. It is clear that they are not going to stop their malicious activity. Thus, do not motivate them by paying the ransom to develop new versions similar to the PayDay ransomware or updating this one.

Introduction to the variants of the Pay Day ransomware
Cybersecurity experts from NoVirus.uk[2] have noticed an example of the crypto-malware that appends .[]-id-.payday file extension at the end of the file-name. It is believed that the ransomware is inextricably linked to BTCWare together with PayDay virus.
After finishing data encryption, the virus delivers !! RETURN FILES !!.txt file which briefly informs about ransomware attack:
all your files have been encrypted
want return files?
write on email: keyforyou@tuta.io
Later on, the malware opens payday.hta file with further instructions. The latest version includes new email addresses: checkzip@india.com and payday@cryptmaster.info. The malware has been spotted spreading via spam email entitled as Schedule_order.r03. Though the malware developer pretends to be a representative of KAVITA company, take a look at the message content:
Dear Sir,
Attached, please find attached Memo in the folder for purchase requests
Kindly issue requested Order confirmation at your earliest.
Looking forward to your cooperation in the matter for which thank you beforehand.
The malware felons did not bother themselves to write the message in correct English. Ample of grammar mistakes and lack of punctuation marks already suggest the deceptive origin of the message. Furthermore, this PayDay ransomware version employs a brute-force attack strategy, specifically looks for weak Remote Desktop protocols. There are third-party tools which help you manage them and change them into more complex ones.
In order to reduce the probability of ransomware encounter, these recommendations might be of use:
- set a limit for failed log-in attempts
- activate two-step verification
- update security apps and crucial software such as Java and Adobe Flash Player once the updates are issued
- set up complex passwords comprised of letters, punctuation marks, characters and numbers (avoid using full dictionary form words)
In any case, make a rush to eliminate crypto-virus from the system and try either BTCWare or HiddenTear decryption software.

At the beginning of February 2019,
discovered new PayDay ransomware version that has a few different features that first versions of the malware.This virus still uses AES encryption and focuses on file-locking process as the first step in the attack. According to various analysis, it seems that developers focus on specific locations in different campaigns.
When files get encrypted, random six letter marker gets at the end of every document, photo or database file and ransom note – HOW_TO_DECRYPT_MY_FILES.txt gets placed in every folder containing these encoded files. The note shows that the ransom amount is 200$ and reads the following:
============== !!!PAYDAY RANSOMWARE!!! ==============
Attention! All your files are encrypted with extension ***.
to decrypt your files – you must buy decryptor. Decryptor price – 200 USD.
If the decryptor is not bought within 3 day’s – files will be pernamently destroyed.
You can contact us by e-mail, our e-mail address : admin@dontfuckme.top.
Payment is accepted only in bitcoin ( https://en.bitcoin.it/wiki/Main_Page ). Our support will give you the address of our Bitcoin wallet for payment during a personal dialogue.
Contacting us – specify the extension of the encrypted files, and your unique identifier, which is listed below.
Only we can decrypt your files, do not use third-party software, it will break the files.
If you have any problems / questions – our support will help you.
Good luck. May god help you!
Your unique identifier : {**************}___suffinc
As per usual, ransomware creators demand payments in cryptocurrency, in this case, Bitcoin, but you should avoid any contact with these criminals and remove PayDay ransomware instead. You can do that using anti-malware tools but don't forget to clean the system further using FortectIntego or similar PC repair programs.
Pay more attention before opening spam e-mails
Common distribution method employed is to send phishing e-mails that download the executable files of the malware. Spam e-mails look extremely genuine. Thus, victims are tricked to open the attachments, which are designed to infiltrate the ransomware into the system. Besides, the file-encrypting virus might spread via malware-laden advertisements and through exploit kits[3] as well.
Therefore, we suggest you stay away from advertisements that promise too good to be true offers. It is also a good idea to ignore ads from questionable third-party sites, especially if they urge you to install “required updates.” Such updates are typically bundled with malicious components. Finally, beware of exploit kits, who waylay in compromised or simply infectious websites and try to exploit software vulnerabilities in visitors’ computers.
PayDay virus termination procedure involves professional help
You are advised to remove PayDay ransomware with a reputable security software since it will save you time and eliminate other malicious programs which might be disrupting your computer's performance. We also want to warn you that the malware might prevent you from downloading the antivirus software. You can circumvent it by booting your PC into Safe Mode before.
Additionally, you should know that manual PayDay ransomware removal is also possible, but not recommended. If you are not experienced enough, you can easily delete wrong files or Registry Keys, which can cause a lot of stability-related computer problems.
Therefore, we suggest you clean the system using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes (or antivirus that you have). If PayDay ransomware virus prevents from installing or using security software, you should find the instructions below handy.
Was this guide helpful?
3 comments