A new Ransomware named File Spider has appeared in various Balkan countries.
File Spider spreads through spam emails and was first detected in Croatia, Bosnia & Herzegovina and Serbia. It starts with an email that reaches the user with the name “Potrazivanje dugovanja” which in English translates as “Debt Collection”. It contains a malicious Word file attachment. Theoretically, the content can be displayed through the so-called “Protected View”, but if someone chooses to edit it or download and open it, then some macros it contains will start running on your computer.
These commands contain a Base64 PowerShell script which, once executed, downloads two encrypted XOR files named dec.exe and enc.exe. The first one is for decryption and the graphical interface of the ransomware, and the second one is for the encryption process that will follow. enc.exe targets over 1000 different file types which it encrypts with AES-128 bit encoding giving them the “.spider” extension at the end.
In each folder you also create a file named “How to decrypt files.url” which is essentially a site with a tutorial video on the steps you need to follow in order to unlock your files. The contact email is (spider@protonmail.ch) and as you know, in order to save your files you will have to pay 0.00726 Bitcoins, which is about 100 Euros (at today's exchange rate).
At the moment, there does not seem to be any way to decrypt the files for free as File Spider uses very strong algorithms that are not yet broken by any free program.

