Virus Email Demanding Ransom - "Account #650280883139 Temporarily Locked" Home Categories Malware Virus Email Demanding Ransom - "Account #650280883139 Temporarily Locked" 0 0 1.74K 0 11y ago 2015-04-30T11:27:05-05:00 11y ago 2015-04-30T11:32:10-05:00 Online Threat Alerts The fake email messages below, which claim that the recipient's account has been temporarily locked, are fakes and have a malicious zip or compressed file attached. The attached file contains the FileCryptor / CTB-Locker / Citroni ransomware, which will lock the victim’s computer screen and encrypt all the files on the victim's computer, making them inaccessible. It will then demand a ransom for the files to be decrypted or made accessible again by displaying the following message: "Your personal files are encrypted by CTB-Locker". The ransom is required to be paid using Bitcoins, which is a form of digital currency, created and held electronically.The recipients of the malicious emails are asked to delete them, and do not attempt to open the malicious attachment. Cyber-criminals are sending out fake emails with malicious attachments ending with ".zip", ".rar", ".cab", “.exe” and ".scr". These attachments should never be open, unless the recipient is expecting the file.The Malicious Email MessagesSubject: [Issue 701392E97155285] Account #650280883139 Temporarily LockedAttachment: 650280883139.zipDear user,We detect unauthorized Login Attempts to your ID #650280883139 from other IP Address. Please re-confirm your identity. See attached docs for full information.Thad FinksAZAHAR CASTELLONParque Oeste 20, Bajo 12006 CastellónCastellónSPAIN+34 964 01 85 11Subject: [Issue 79672F43F4021310] Account #632996648837 Temporarily LockedAttachment: 632996648837.zipDear user,We detect unauthorized Login Attempts to your ID #632996648837 from other IP Address.Please re-confirm your identity. See attached docs for full information.--------Novella SoulierAvenue Lock & Safe738 Bank Street, Ottawa, ON K1S 3V4CANADA613-289-5161Subject: [Issue 2548A80759041653] Account #514956694710 Temporarily LockedAttachment: 514956694710.zipDear user,We detect unauthorized Login Attempts to your ID #514956694710 from other IP Address. Please re-confirm your identity. See attached docs for full information.Juliet TavanaSARL MEUBLES LUXOVIENS56 Rue Jules Jeanneney 70300 Luxeuil Les BainsBainsFRANCE+33 384 65 95 02Subject: [Issue 600663A34F6E2930] Account #394822403123 Temporarily LockedAttachment: 394822403123.zipDear user,We detect unauthorized Login Attempts to your ID #394822403123 from other IP Address. Please re-confirm your identity. See attached docs for full information.--------Hallie KippleyArdrossan Jr-Sr High SchoolArdrossan, AB T8E 1J3CANADA780-997-4028 Check the comment section below for answers or additional information. Share what you know, or ask a question about this article by leaving a comment below. Online Threat Alerts is not affiliated with or endorsed by any trademark owner mentioned in this article. Some of the information in samples in this article may have been impersonated or spoofed. Save + Was this article helpful? (0) (0) More For You Tax Mediation Support Office Scam Call Is Delawaresoft a Trustworthy Company? 'www.rbxxs.com' - it is a Fake Ray-Ban Sunglasses or Eyewears Selling Website Malicious Websites - 'whatsappat.com' and 'perfect-player.com' Lottery Scam - 'Important Notice - Winners of the Samsung Award of the Year' Fake Nepal Earthquake Appeal / Donation Website - www.savenepal.org Fake Web Traffic Generating Website - AddMoreTraffic.com Fake Nepal Earthquake Disaster Charities Fake and Malicious Australian Federal Police (AFP) Traffic Infringement Notice 'www.weeklyfixpay.com' - A Fake Internet Work-From-Home Job Website Fake Emails with a Malicious Zip File Attached that Contains a Virus Comments / Answers Remove sensitive information from your post. Your IP address will be used to display your estimated location. Enter comment post here