Hello guys , i am pretty sure for now , this " WTF " ransomware is from China ,
it's from a popular forum name " Kafan " in China , this forum are also same like MalwareTips ,
Is the forum to discuss the Virus and Malware .
I believe Kafan is the biggest forum for discuss Virus、Malware in China now
The WTF ransomware creator are aslo a member in Kafan forum ,
he just make this ransomware and public to every member in Kafan can easy to download it ,
and this ransomware just for fun , try to testing different security software can defend or not .
Of course he had already suggest everyone , make sure to play in virtual system ,
But if there really someone so unlucky , the host system files had be encryption ,
I had just contact him few min ago , and he say he will release the decryption tool right now
And also i am right , the QR-Code for asking payment , actually just asking for donations ,
just a other joke , lol
By the way , the real name for this ransomware , actually is write by Chinese ,
so that is why some system can't correctly displayed the file name
Translate the original name to English , it's " Press me to look the photo "
if you don't mind to see Chinese , or using Google translate to take a look ,
(even we know translate by the machine , those post will terrible hard to understand)
and here is the link in Kafan forum :
智能勒索第3.5版来袭,测试主防/建议虚拟机运行,真正勒索,加了解密工具_病毒样本区_安全区 卡饭论坛 - 互助分享 - 大气谦和!
P.S : The attach file is the decryption tool , but i do not test it by myself
After download the attach file , please change name from XXX.log to XXX.zip