Sextortion
Abuser: [email protected] (spoofed)
Claims to have hacked email account
Claims to have hacked email account
A hacker asking for money stated he had access to the computer and will release sex videos
installs itself deep into a Windows system, starts an executable named 1system.exe which cyphers all files on all drives which are not protected. For each file an e-mail address and an id is appended, and the file extension bekomes "*.calum". The ransomware blocks taskmanager and file explorer, it installs itself into "scheduled tasks" e.g. as defragmentation task and many other, it installs itself as a background service. It shows some message on the screen