Unpaid electricity bill – Customer Reference 50339396
Am Mittwoch, den 23. März 2016 wurde durch unbekannte Dritte die folgende E-Mail in englischer Sprache versendet:
Dear Client,
You have an outstanding debt of – 894,34 $ for period of 02/01 – 03/01. We kindly ask you to transfer the amount as soon as possible in order to avoid power cut.
Find you bill and payment information in the document attached.
Der E-Mail ist eine .zip – Datei beigefügt (z. B. confirm_50339396.zip), die eine .js – Datei enthält (z. B. letter_NxWJNm.js). Das JavaScript lädt von unterschiedlichen Domains die Datei /70.exe?1 nach. Es handelt sich dabei um den Verschlüsselungs- und Erpressungstrojaner „TeslaCrypt“ in der neuesten Version 4.0. Virustotal zeigt eine Erkennungsrate von 5/56.
Nach der Verschlüsselung der Dateien wird eine entsprechende Meldung angezeigt:
—————————————————-
NOT YOUR LANGUAGE? USE https://translate.google.comWhat’s the matter with your files?
Your data was secured using a strong encryption with RSA4096.
Use the link down below to find additional information on the encryption keys using RSA-4096 https://en.wikipedia.org/wiki/RSA_(cryptosystem)What exactly that means?
It means that on a structural level your files have been transformed . You won’t be able to use , read , see or work with them anymore .
In other words they are useless , however , there is a possibility to restore them with our help .What exactly happened to your files ???
*** Two personal RSA-4096 keys were generated for your PC/Laptop; one key is public, another key is private.
*** All your data and files were encrypted by the means of the public key , which you received over the web .
*** In order to decrypt your data and gain access to your computer you need a private key and a decryption software, which can be found on one of our secret servers.What should you do next ?
There are several options for you to consider :
*** You can wait for a while until the price of a private key will raise, so you will have to pay twice as much to access your files or
*** You can start getting BitCoins right now and get access to your data quite fast .
In case you have valuable files , we advise you to act fast as there is no other option rather
than paying in order to get back your data.In order to obtain specific instructions , please access your personal homepage by choosing one of the few addresses down below :
http:// 9hrds.wolfcrap[.]at/***
http:// 6g4ds.froekuge[.]com/***
http:// vewrb.italisumo[.]at/***If you can’t access your personal homepage or the addresses are not working, complete the following steps:
*** Download TOR Browser – http://www.torproject.org/projects/torbrowser.html.en
*** Install TOR Browser and open TOR Browser
*** Insert the following link in the address bar: k7tlx3ghr3m4n2tu.onion/***
*** Follow instructions on your screen !!!*** *** *** *** *** *** *** IMPORTANT INFORMATION *** *** *** *** *** ***
Your personal homepages
http:// 9hrds.wolfcrap[.]at/***
http:// 6g4ds.froekuge[.]com/***
http:// vewrb.italisumo[.]at/***Your personal homepage Tor-Browser k7tlx3ghr3m4n2tu.onion/***
Your personal ID ***
Zur Entschlüsselung der Dateien werden 1,3 Bitcoin im Wert von 500 USD gefordert: