Negotiation chat with different groups

Akira

Avaddon

Avos

Babuk

BlackBasta

BlackMatter

Cloak

Conti

Darkside

Dragonforce

  • 058f4b92-ae99-45c7-bf35-5d2d6754b3de – 19 message(s) voir chat
  • 05f724f8-906e-4739-8177-815852cc2c3f – 29 message(s) voir chat
  • 29BBE03074FDBB8D – 10 message(s) voir chat
  • 7A313D13EB6B4E58 – 32 message(s) voir chat
  • 89716D29D2CEE36F – 23 message(s) voir chat
  • AB0404E049514B50 – 28 message(s) voir chat
  • BD004D632D87DBA0 – 25 message(s) voir chat
  • C2A3C7249797F5ED – 66 message(s) voir chat
  • C42CDF65B97D0E92 – 30 message(s) voir chat
  • C7CD31EAAF9DE9AC – 71 message(s) voir chat
  • C8479B30418B331E – 4 message(s) voir chat
  • D6DDD9B26D7D41DB – 14 message(s) voir chat
  • FDA8141B6DD392E3 – 10 message(s) voir chat
  • b8e14e1a-548f-4eec-bd6e-a590126e57c9 – 14 message(s) voir chat

Hive

Hunters International

Mallox

NoEscape

Pear

Qilin

  • 20240429 – 3 message(s) voir chat
  • 20250203 - from @RakeshKrish12 – 36 message(s) voir chat

REvil

RansomHub

Ranzy

RunSomeWares

fog

lockbit3.0

mount-locker

trinity

Ranzy 15 Oct, 16:27
Hello, you heed help?

Victim 16 Oct, 16:04
how much

Victim 16 Oct, 16:05
how much

Ranzy 16 Oct, 16:06
Hi, please wait 5 min.

Victim 16 Oct, 16:06
hello ?

Ranzy 16 Oct, 16:06
Hello.

Ranzy 16 Oct, 16:09
Price for your case is $7,000. If you can pay this amount we send you all instructions

Ranzy 16 Oct, 16:33
Hello?

Victim 17 Oct, 03:29
Your note says all of our sensitive
data was downloaded to your servers. Does that mean you took our data?
We read an article that says you like to take data. We want our data
decrypted. So, if we pay we get a decryptor and all of our files back?
Is that how this works?

Ranzy 17 Oct, 03:33
Yes.

Victim 17 Oct, 21:48
Ok. We are going to have a meeting to discuss this situation. Can you send us a file or two from the data you took?

Victim 19 Oct, 14:35
Ok. We had our meeting and agree that we need the decryption program. Can you fix a file to prove your ability to decrypt?

Ranzy 19 Oct, 16:05
yes, upload file on https://ufile.io < 3mb

Victim 19 Oct, 16:24
Here is the link it gave me. https://ufile.io/[redacted]

Ranzy 19 Oct, 17:40
Hello, can you send me teamviewer access on your infected server?

Victim 19 Oct, 19:29
We can't provide you access, but if
you tell us what you need to look at, we can provide information to you.
Do you need more sample files, or something else?

Ranzy 19 Oct, 19:31
Yes, more sample files (from any
servers and in share folders and local folders). Also tell me this
information: Your OS, how to you shutdown our ransomware, and how much
share folders in your local network. Thanks.

Victim 20 Oct, 02:41
Win Server 2008 R2 The Anti Virus caught the malware We only have 1 server.

Victim 20 Oct, 02:42
https://ufile.io/[redacted]

Victim 20 Oct, 21:25
Any update on our encrypted file?

Victim 21 Oct, 14:00
Hello. Have you decrypted our file?

Ranzy 21 Oct, 14:23
Hello

Ranzy 21 Oct, 14:24
We have another messages from recovery company

Victim 21 Oct, 15:57
What do you mean?

Victim 21 Oct, 22:10
In the beginning we asked another
recovery company to help us. Do you know the name of the recovery
company that is communicating with you still? Their website said they
could decrypt our files, but it was a lie and I think they contacted you
instead. Did they pay you? Please ignore them and communicate here with
us and we will get this sorted out.

Ranzy 21 Oct, 22:13
All recovery company is scam and just write us for buy decrypt.

Victim 22 Oct, 15:58
Have you made any progress on decrypting our test file?

Ranzy 22 Oct, 16:05
Hello yes we have progress but we dont
understand which version our software you are encrypted, can you send
me time when you encrypted?

Victim 22 Oct, 18:26
It looks like it happened on 10/11/2020.

Ranzy 22 Oct, 19:52
So, your files encrypted tested
version our software and we must scan all your system for find keys for
decrypt, and also my boss up price for you so final amount is 30,000$

Victim 22 Oct, 22:08
Can you give us the scan tool?

Ranzy 22 Oct, 22:10
Scan with private global decryption
key and when scanned collect all keys and decrypted it in real time, we
can connect to teamviewer and scan it or send it you after payment

Victim 23 Oct, 01:49
There is no way we are letting you
back into the server. We also can't afford anywhere close to the amount
you are asking at $30,000. We could barely even afford $7,000. We are
just a few person company. If you can't prove you can decrypt, we can't
pay you anything. The price needs to go back to $7,000 because I don't
know if we can even afford that. How can you decrypt the data without
getting into our server?

Ranzy 23 Oct, 01:53
In any case need teamviewer.

Victim 23 Oct, 14:02
Why can’t we just run whatever key
find program you need us to run for you? We will not give you Teamviewer
access, especially not if you want a price that we can’t possibly
afford. Can you send us the program that you need to run to find the
keys, then decrypt a sample file, then we can pay $7000 for decryption?

Ranzy 23 Oct, 14:03
Im already repeat you - your network
encrypted with tested versions our software so for finding keys need
scan your system, our scanner with private key and we do not provide it
just like "download this and run". If you cant provide teamviewer and
pay $30,000 - goodbye

Auteur/autrice

sdgadmin@tux.ovh