

That file cannot contain valuable information.

It depends on whether victims will email attackers (send an email to or within or after 72 hours from the attack.Īdditionally, the ransom note mentions that one file can be sent for free decryption before paying a ransom. It informs victims that files cannot be decrypted without the right decryption software and a unique key. The ransom note provides contact and payment information. Screenshot of files encrypted by Nuhb ransomware: Also, it provides a ransom note - it creates a text file named " _readme.txt".Īn example of how Nuhb ransomware renames files: it changes " 1.jpg" to " 1.jpg.nuhb", " 2.exe" to " 2.exe.nuhb", " 3.png" to " 3.png.nuhb". While analyzing Nuhb, we learned that it encrypts files and appends the ". It was found while examining malware samples submitted to VirusTotal. We have discovered a new Djvu ransomware variant called Nuhb.
