27 December 19, 16:50
Quote:Continue Reading
We just released a new decryption tool for the ChernoLocker ransomware strain. You can download the FREE decryption tool linked below. A detailed guide is also included.
Download the ChernoLocker Decryptor here
Technical details
ChernoLocker is programmed in Python, and encrypts files using AES-256, adding the extension “(.CHERNOLOCKER)”. When ran before it encrypts the victim’s files, the following popup appears:
Unlike most ransomware strains that include a text file containing its ransom note, ChernoLocker’s ransom note is delivered via a popup window. It reads:
Quote:All Your Files have now been encrypted with the strongest encryption You need to purchase the encryption key otherwise you won’t recover your files Read the Browser tab on ways to recover your files Make Sure you don’t loose this Email as you it will be loosing it will be fatal Write it in a notepad and keep it safe Email: filelocker@protonmail.ch...