Pulpy ransomware is a cyber threat that promises to delete victim's important files within 2 days

Pulpy ransomware is serious cyber threat that uses file-encryption methods to swindle people's money. New variant of this ransomware came researchers' attention in June 2018. Just like its previous versions, this crypto-virus is using AES-256 and RSA-2048 encryption methods. As a result, files that typically have are made useless. Ransomware appends .AES file extension to every encrypted file – this is how you can find data encrypted by this malware. Unfortunately, most popular types of data is typically encrypted by Pulpy virus. Additionally, virus creates instruction.txt document that is used by extortionists to convince the victim that he or she has to pay a ransom within 2 days. However, there is no guarantee that people hiding behind this ransomware won't leave you with nothing.
| Name | Pulpy |
|---|---|
| Type | Ransomware |
| Extension | .aes |
| Ransom note | Instruction.txt |
| EMAIL ADDRESS used by extortionists | pulpy2@cock.li; pulpy@protonmail.ch; thomasRaymond@protonmail.com |
| Danger level | High. Locks files and demands ransom |
| Encryption method | AES-256; RSA-2048; RSA2048Pro |
| Distribution | Malicious spam email attachments |
| Decryption | Is not available |
| Elimination | Best tool for ransomware removal is FortectIntego |
Originally, Pulpy ransomware[1] targets English speaking computer users. Malware might be included in the malicious email or spread via vulnerable RDP configurations. Once the malicious payload 1d Ptin.exe is dropped on the system, ransomware starts data encryption procedure and delivers a ransom note in Instruction.txt file when its over.
Malware researchers discovered two variants of the virus ransom note which uses two different contact emails – pulpy2@cock.li and pulpy@protonmail.ch.
Version 1:
Hi, all your files is have Been encrypted. CAN decipher a the if You you the write to me on the mail: pulpy2@cock.li Otherwise, all your files is deleted will of the BE Within 2 days without any problems!
Version 2:
Hello all of your files are encrypted, the decryption of all your file please contact us at email: pulpy@protonmail.ch
However, contacting cybercriminals is not recommended because it may only lead to money loss. There’s no doubt that crooks demand to pay a couple of hundreds of dollars in Bitcoins for unknown decryption software. Though no one can ensure that this software actually exists and criminals will let you use it.
Thus, it’s highly recommended to remove Pulpy ransomware from the computer instead of accepting hackers’ offer. Ransomware elimination requires scanning the system with reputable malware removal software, such as FortectIntego. However, if you cannot run security software, please follow the guide given below the article and do not try to terminate ransomware-related entries yourself.
Keep in mind that, Pulpy ransomware removal does not recover your files. For that, you will need to use backups or try third-party software. However, the virus is not decryptable yet, so chances to restore encrypted data without backups are low.
In June 2018, security researchers found a new ransomware's version. This new variant is using a file extension “.aes” and an e-mail address called ThomasRaymond@protonmail.com. This version uses sophisticated encryption algorithm RSA2048 Pro. It is known that ransom note still is named “Instruction.txt” and contain not much information about the attack itself. No information about the ransom amount, time or instructions on how to pay. This version still encrypts files like photos, videos or documents, archives.

Rozok ransomware – a Russian version of Pulpy
Pulpy has a version that targets Russian-speaking[2] computer users called Rozok. This variant is written in the enbild.exe file. However, the operation peculiarities and appended file-extension are similar. The main difference is a ransom note which is written in Russian language and uses different contact email address.
The original ransom note of Rozok virus says:
Все ваши файлы и данные зашифрованны.Для дешифровки свяжитесь с нами : rozlok@protonmail.com .Чем дольше мы ждём-тем больше.Вам придёться заплатить.
Translation from the Russian language:
All your files and data are encrypted. For decryption, please contact us: rozlok@protonmail.com. The longer we wait, the more. You have to pay.
This version of the Pulpy does not hide that criminals are willing to profit from the victims. Even though they do not tell the exact size of the ransom, it’s clear that crooks are willing to obtain as much money as possible. For this reason, it’s still not recommended following the orders. We highly recommend Rozok removal using anti-malware tools instead.

Email attachments are used to spread this dangerous virus with its versions
All versions of malware like ransomware spreads using similar methods:
- vulnerable RDP configurations;
- malicious email attachments;
- compromised websites (e.g., sports, automotive, etc.)
Thus, it’s recommended to strengthen RDP configurations[3] and avoid visiting high-risk websites. It’s also important to be careful with received emails. Do not click or open attachments if you do not know the sender or the content of the message seems suspicious. Always double-check the information before clicking on unknown content.
Spam email attachments can contain various macro viruses and spread malware this way. Those often hides behind the safe-looking Word or Exel documents. Immediately after you download the files or purchase products from those advertisements you get infection on your PC. You can avoid this if you pay enough attention while browsing online.
Pulpy ransomware elimination is possible with an updated anti-spyware
To remove Pulpy ransomware from the computer, you have to follow a well known sequence of actions. As we have mentioned in the beginning, elimination requires scanning the infected computer system with a reputable malware removal software. Before that, make sure you update the program to its latest version and then eliminate reported viruses right after the program finishes its scan.
Manual Pulpy ransomware removal is not recommended because ransomware is a complicated cyber threat that is hard to get rid of. This virus can have multiple additional files or programs that you might not find yourself.
For a full Pulpy removal, we recommend using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These tools can safely terminate malicious processes and clean computer from malware. For more information, please follow the guide below. We advise you to firstly focus on virus elimination and only then worry about file recovery. Because any drive that is plugged into insecure PC can be infected.
Did this guide help?
Be the first to comment