Ransomware Wiki
Ransomware Wiki

Sage Ransomware Overview[]

The Sage ransomware is a new family of related viruses that may originate from TeslaCrypt. Upon infection the virus encrypts predefined file types and extorts the victim for a ransom payment. 

Sage Ransomware Note[]

ATTENTION!

Sage encrypted all your files!

—————————–

All your files, images, videos, and databases were encrypted and made inacessible by software known as Sage.

You have no chance to restore the files without our help.

But if you follow our instructions files can be restored easily.

Instructions on how to get your files back are stored on every disk,

in your documents and on your desktop.

Look for files !Recovery_2g0zr9.txt and !Recovery_2g0zr9.html

If you can’t find this files, use the program “Tor Browser”(you can find it in Google)

to access the (onion)web site http://qbxeaekvg7o3lxnn.onion to get your instructions

The criminals who operate the Sage ransomware request the ransom sum of 560 US Dollars in Bitcoins. If this is not paid in a week, then it is doubled to 1120 US Dollars.

Sage Ransomware Distribution[]


The Sage ransomware infects its targets via the usual methods – exploit kits, browser hijackers, spam email campaigns and etc.

Sage Ransomware Removal[]

In-depth removal instructions and detailed technical information about the virus can be found on Best Security Search.