Spora continues spreading all over the world

Spora is a ransomware-type virus that was first discovered on January 10, 2017. Malware uses an advanced combination of AES and RSA encryption keys to corrupt users data on the affected computer. Despite astonishing appearance and worldwide prevalence, virus activity has been slowed down for a couple of months. However, on August researchers warned about ransomware’s return.
Spora ransomware appears to be a data-encrypting Trojan[1] which derived from CryLocker. Malware started communicating with its victims only in the Russian language. However, after several weeks of operation, it has started traveling the whole world wide web. Currently, the most affected countries are Mexico, Poland,[2] and Sweden.[3]
It gets executed with the help of close.js file. JavaScript files are popular tools among hackers. Surprisingly, the malicious program uses an entirely different, and very complicated data encryption algorithm which seems to be immune.
Apparently, Spora virus creates contents of .KEY file by creating RSA key, encrypting it with a newly generated AES key. In addition, it encrypts the AES key with a public key inserted into the virus' executable file, and finally, saves them to .KEY. Data encryption routine of this malware is slightly less complicated: they are encrypted using an AES key encrypted with RSA cipher (unfortunately, we cannot say so about Spora ransomware removal).
According to the analysis, the virus currently targets only 23 file extensions:
.backup, .xlsx, .docx, .rtf, .dwg, .cdr, .cd, .mdb, .1cd, .odt, .pdf, .psd, .dbf, .doc, .sqlite, .accdb, .jpg, .jpeg, .tiff, .zip, .rar, .7z, .xls.
Files that have these extensions are secured using a long encryption key (the public key); meanwhile, the private key is sent to criminals remote servers and is kept there until the victim agrees to pay a ransom. Instructions on how to transfer the payment are provided in the ransom note which is usually saved on the desktop.
These instructions point the victim to a place that contains even more instructions – the official Spora ransom payment site which is sophisticated. Besides, currently, 10 different sites are used for collecting illegal ransoms, including spora[.]bz, spora[.]one, spora[.]hk, and others.
However, you should not analyze and use none of these payment sites after the attack. You should remove Spora ransomware from the PC immediately with the help of FortectIntego or another reliable malware removal program.
Spora’s activity increased in August 2017: three updates have emerged
Malware researchers spotted few new variants of Spora spreading in August. The first reports about ransomware updates appeared on August 4th.[4] The recent variant spreads as an obfuscated radF14DE.exe file.
It does not append any extension to the targeted files; however, it still corrupts them and demands to pay 90 dollars for data recovery. However, according to the ransom note, the size of the ransom will increase to 121 dollars if users do not pay in four days time.
The second ransomware update was reported on August 7th.[5] This variant spreads as an obfuscated PE/HTA bundle in ZIP archives that are attached to phishing emails. According to the latest data, ransomware runs from mshta.exe and cmd.exe files.
The third variant was reported on August 14th.[6] It aims at Russian computer users only. It spreads via malicious spam emails that include ZIP file. The archive includes pdf.wsf dropper that runs ransomware on the system. What is interesting, this version of Spora does not rename targeted files and does not append any extensions.
According to the ransom note, files are encrypted with RSA encryption, and in order to get back access to them, victims have to transfer 140 USD. If the payment is not made within 4 days, the size of the ransom increase to 189 USD.

Hackers give detailed instructions and surprise with a sophisticated Spora ransom payment site
Once Spora finishes its malicious activities, it drops a ransom note in each folder that has encrypted. The guidelines are written in Russian or/and English language. The name of the ransom note is created by using this scheme:
SPORA_< Sample ID >.hta
The payment site[7] differs from websites that typical ransomware viruses normally point to because it provides a variety of options for the victim:
- remove Spora virus for $20,
- restore files for $30,
- pay $50 for ostensible immunity to ransomware attacks;
- get a full restore package for $79.
Authors of the virus accept the payment in BitCoin currency[8] only. On January 16th, the payment website was improved, and a “Help” page was added. The site also has a public communication window, a table of transactions already made, and other little details that all make a very user-friendly interface[9].
No matter what, the malware is definitely not user-friendly as it wants to extort money[10] from the victim. In order to get the decryption key, victims are asked to pay the ransom and send the .KEY file to crooks via the payment site. If you have been hit by this virus, make sure you delete it immediately. It is highly advisable to use tools like FortectIntego or SpyHunterCombo Cleaner for successful Spora removal.
Spora 2.0 – the major update of the ransomware
oon after the original version of the virtual threat got unleashed, cyber villains introduced an updated variant of the malware – Spora 2.0 ransomware virus. The authors of this virtual menace launched a more crafty campaign to multiply their global infection rate[11].
EITest malicious code would redirect users to the website infected with an exploit kit. Shortly afterward, the web page would turn into a mosaic of miscellaneous source codes. Consequently, the notification “The HoeflerText font wasn't found” emerges.
In order to solve this inconvenience, the crooks offer to enable a special Chrome Font Pack. However, what users would download is not some fishy browser extension but a real virtual menace – Spora 2.0.
Interestingly, that the folder carrying infection are double-zipped. Now the crooks demand approximately 2000 USD in exchange for the files[12]. Despite the elaborate payment site, there are no reports whether the felons returned all files to their victims.
Crypto-malware spreads via malicious emails
Malspam is currently the main technique used to distribute Spora. In the beginning, when this threat was using Russian language only, misleading emails used such subject:
Скан-копия _ 10 января 2017г. Составлено и подписано главным бухгалтером. Экспорт из 1С.a01e743_рdf.hta.
In English that would be: “The copy of scan _ 10 Jan 2017. Written and signed by the chief accountant”.
However, this ransomware keeps changing, and it will definitely use different subject lines. You should be careful with emails and especially with their attachments because they might include infectious HTA files. These hideous files have double extensions, for example, PDF.HTA and the real extension is hidden so that the victim would think that .DOC is the real extension.
Let us remind you that HTA file is HTML executable file format, and so when the victim opens it, it downloads close.js JavaScript file to the system folder called %Temp%. Here, the infection activates itself by extracting an executable file and opening it. This executable file is the main file which is responsible for the data encryption procedure.
At the same time, HTA file opens a DOCX file, which shows an error message that says file cannot be opened. While the victim stares at this suspicious error, the ransomware encrypts all files on the system.
Spora removal guide
You can remove Spora virus quite easily using reliable anti-malware software. If you do not have one, we suggest installing FortectIntego or SpyHunterCombo Cleaner. If you want to use a different program, you can easily choose the one that you like after reading detailed software reviews in the Software section.
Please keep in mind that you are dealing with the virus of ransomware type, so it can try such things as blocking your anti-malware and antivirus programs when trying to remove it from the system.
If you are dealing with such problem right now, we recommend you to try rebooting your computer to a Safe Mode with Networking before launching anti-spyware software. If this option does not work, continue Spora removal with the help of System restore method.
Did this guide help?
4 comments
hetera
Even if the ransom isnt high, Im not gonna pay it, no matter what!
William
This one seems sophisticated, I can say. Wondering if someone is smart enough to crack it!
Lean0n
Ughhhh why why why why I didnt create the God damn backupppp!!
James
Just got infected with Spora, does anybody know how to recover files for free????