Thanks to the experts at Emsisoft the victims of the Ims00rry ransomware can decrypt their files for free.
The Ims00rry ransomware used AES-128 algorithm for the encryption process. Unlike most of the ransomware, Ims00rry and doesn’t append an extension to the filenames of the encrypted files. Instead, the ransomware adds the text “—
Crooks demands a 50$ ransom worth of Bitcoin to decrypt the files.
Below the text of the ransom note:
I am sorry!!! My friend. I want to start my own business, but i have no money. All your files photos, databases, documents and other important are encrypted with strongest encryption and algorithms RSA 4096, AES-256. If you want to restore your files payment and write to Telegram bot Price decrypt software is $50. Attention!!! Do not rename or move the encrypted files. Bitcoin wàllet: 1tnZbveCXmqRS1gfZSxztG5MbdJhptaqu Contact Telegram bot: @Ims00rybot