Has anyone been hit with ransomware calling itself ThunderCrypt ? It encrypted my graphics, .ppt, .doc, .xls, .xlsx, .html, .c, .h files and some others I am sure. It claims to use hybrid RSA-2048 encryption. It looks like it was using powershell. I ended that process and the ransom window went away along with the weird internet traffic that netstat was showing. I have attached a couple of files, one is the original and the other is the encrypted one. I have also attached an email correspondence I had with these criminals.
Pure_Blend_Labels2.ppt
Pure_BlendLabels2-Clean.ppt
email_from_thund