Wisperado@india.com ransomware virus – another variant of Dharma ransomware
Wisperado@india.com ransomware is a freshly discovered file-encrypting virus that belongs to the Dharma ransomware family. This crypto-malware family is known for encoding files since November 2016. The Trojan[1] shifted its focus from home computer users to corporate networks and server infrastructures. Thus, server administrators are advised to backup important data and store it an offline storage devices[2]. Backups are crucial because data encryption is impossible specific decryption key. Unfortunately, wisperado@india.com removal won’t recover the files, and paying the ransom for cyber criminals may not end up as expected. The virus acts like its predecessors and after infiltration it looks for the targeted files and protects them with a strong algorithm. The virus uses TOR Network[3] to communicate with the operators and generates unique encryption. It aims at the most popular files, data containers and databases, such as Mandriva DB and SQLite. Indeed, for business enterprises loosing important documents, sensitive information about partners or customers may cause serious problems and developers of the wisperado@india.com virus are aware of that. During data encryption, the virus appends either .[wisperado@india.com].viper2 or [wisperado@india.com].viper1 file extensions to these file types:
.acrodata, .au3, .bak, .bat, .bin, .bmp, .chm, .dat, .db, .def, .dic, .dll, .doc, .docx, .dot, .dotm, .dotx, .dtd, .e2x, .exe, .flt, .gif, .h, .hpp, .htm, .html, .htt, .hxh, .hxl, .hxn, .hxw, .ico, .idl, .ini, .ion, .jpg, .js, .json, .jsx, .lck, .lib, .lic, .lnk, .log, .mk, .msp, .pl, .pm, .png, .pod, .ppt, .pptx, .py, .pyc, .rar, .rdf, .rtf, .sam, .scf, .sfx, .sig, .sqlite, .sst, .tcc, .tmp, .txt, .wav, .wb2, .wma, .wmdb, .wpd, .wpg, .wpl, .xa, .xbn, .xls, .xlsx, .xml, .xss, .zip.
Once all targeted files are encrypted, wisperado@india.com ransomware virus drops one of two ransom notes called HOW TO DECRYPT FILES.txt and Read Me Please.hta. Both documents include the same information about data encryption and recovery. The authors of the ransomware ask for 3 Bitcoins that is more than 3000 dollars. However, paying the ransom might be not as damaging as losing important documents for many companies. However, some attacked institutions have paid the huge ransoms and hackers left them with nothing[4]. Therefore, there’s a risk that developers of the wisperado@india.com virus might forget their promises to provide decryption key because the main purpose of ransomware viruses is to gain as many illegal incomes as possible. After ransomware attack, we highly suggest focusing on the virus removal. Ransomware elimination requires using professional and powerful malware removal tools such as FortectIntego. However, malware can prevent from installing, updating and accessing security programs. In this case, you have to reboot your PC to the Safe Mode with Networking and try to remove wisperado@india.com ransomware automatically again.

How does the virus proliferate?
The developers of the wisperado@india.com malware use few distribution techniques. The virus can get into the system via compromised Remote Desktop Protocol or phishing emails[5]. Therefore, it’s important to educate and remind corporate workers about security tips and possible threats hiding in the emails. Cyber criminals have lots of tricks how to convince people to open infected links or attached files. Malicious emails often claim to be sent from official and legal institutions, banks, retailers, etc. The provided attached document often is obfuscated Word or PDF file that is renamed as invoice or statement. Hence, many users believe in this trick and rush opening it. Meanwhile, malware gets inside the system and starts encryption procedure.
What to do after Wisperado@india.com ransomware attack?
Having ransomware on the system requires only one action – removing it from the system. The only safe way to remove wisperado@india.com is to rely on professional malware removal tools. We highly recommend installing FortectIntego or MalwarebytesMalwarebytes and performing the automatic removal. Manual elimination is not recommended because you may end up leaving malware-related components or causing more damage to your computer. It’s important to mention that ransomware might block security tools or prevent from installing it. In this case, you have to reboot your PC to the Sage Mode with Networking that disables the virus. Then, you will be able to install your chosen software and perform wisperado@india.com removal.
Did this guide help?
3 comments
lalala
Dharma developers should stop!
Malvin
Another version... I hope its the last one.
Megan
I hope there will be a decrypter soon...