In recent days, many companies in Germany have been facing a new spam campaign. A woman named “Eva Richter” is sending an email, saying she is interested in a job. The email contains a photo and her resume. In reality, the resume is an executable, disguised as a PDF file, which is designed to destroy the files by installing Ordinypt Wiper.
Ordinypt is a malicious software that appears to be ransomware (but it is not). It demands a ransom from victims to decrypt their files, but even if users pay, their files cannot be decrypted.
According to information, the spam campaign began around September 11, 2019.
As we mentioned above, the scammers’ target (for now at least) is German companies. The supposed “Eva Richter” sends an email asking for a job. The email contains a photo of a woman, supposedly Eva Richter, and a zip file named “Eva Richter Bewerbung und Lebenslauf.zip”, which is supposedly her resume.
The text of the spam email in German is:

If the victim opens the file with the supposed resume, Ordinypt will begin encrypting the computer's files.

Destruction of files
The Ordinypt malware begins to corrupt files on the victim's computer. It also backups deletes and recovery environment Windows 10.
When it completes the process, a note appears in each folder, (_how_to_decrypt.txt), which guides the victim and explains how to go to a Tor site and how to pay the ransomin order to get their files back.

Most victims of the spam campaign reported the amount the hackers demanded. In all cases, the amount was the same, 0.1473766 BTC, or approximately $1,518.92.

Because Ordinypt is not ransomware, victims should not pay the ransom, as they will not receive data .
In some cases Ordinypt did not delete the backups, so victims were able to restore their files from Shadow Volume Copies.
