Negotiation chat with different groups

Akira

Avaddon

Avos

Babuk

BlackBasta

BlackMatter

Cloak

Conti

Darkside

Dragonforce

  • 058f4b92-ae99-45c7-bf35-5d2d6754b3de – 19 message(s) voir chat
  • 05f724f8-906e-4739-8177-815852cc2c3f – 29 message(s) voir chat
  • 29BBE03074FDBB8D – 10 message(s) voir chat
  • 7A313D13EB6B4E58 – 32 message(s) voir chat
  • 89716D29D2CEE36F – 23 message(s) voir chat
  • AB0404E049514B50 – 28 message(s) voir chat
  • BD004D632D87DBA0 – 25 message(s) voir chat
  • C2A3C7249797F5ED – 66 message(s) voir chat
  • C42CDF65B97D0E92 – 30 message(s) voir chat
  • C7CD31EAAF9DE9AC – 71 message(s) voir chat
  • C8479B30418B331E – 4 message(s) voir chat
  • D6DDD9B26D7D41DB – 14 message(s) voir chat
  • FDA8141B6DD392E3 – 10 message(s) voir chat
  • b8e14e1a-548f-4eec-bd6e-a590126e57c9 – 14 message(s) voir chat

Hive

Hunters International

Mallox

NoEscape

Pear

Qilin

  • 20240429 – 3 message(s) voir chat
  • 20250203 - from @RakeshKrish12 – 36 message(s) voir chat

REvil

RansomHub

Ranzy

RunSomeWares

fog

lockbit3.0

mount-locker

trinity

Victim 5/17/2021, 11:30:31 PM
The note said to contact you here, what do we do next?

Conti 5/18/2021, 9:26:03 AM
Welcome! We are ready to help you.

Victim 5/18/2021, 2:13:45 PM
our network is locked

Victim 5/18/2021, 2:17:49 PM
we need your help

Conti 5/18/2021, 4:10:08 PM
Give us some time, and we will definitely help you. Expect instructions please.

Conti 5/18/2021, 4:36:15 PM
Welcome! [redacted]

Conti 5/18/2021, 4:36:40 PM
You need pay for decrypt your files. Your price is 400.000$

Conti 5/18/2021, 4:49:42 PM
You need to pay this amount and we will give you decryptor for all your network, file tree on what we have downloaded from your network and wiping log of that information.

Conti 5/18/2021, 4:50:31 PM
We will also try to find a buyer for your data and access to your network if you refuse to pay.

Victim 5/18/2021, 8:13:52 PM
we do not have that much money, we are still recovering due to covid.

Conti 5/18/2021, 8:17:00 PM
Make a reasonable offer based on our offer.

Victim 5/18/2021, 8:35:55 PM
we dont have that much money, help us out, we are in a bad place

Victim 5/19/2021, 3:50:51 AM
my boss just told me that we can give you $42,850,

Conti 5/19/2021, 8:01:59 AM
Well, we see constructive dialogue and make a discount. Your new price is $357.150

Victim 5/19/2021, 3:23:52 PM
thats still too much for us, i will take it to my boss

Conti 5/19/2021, 3:24:57 PM
Make a reasonable offer based on our offer.

Conti 5/19/2021, 3:25:46 PM
Reputation is expensive.

Victim 5/19/2021, 5:46:21 PM
my boss wants proof of what you got, but we can come with 73,250 which is a large amount

Conti 5/19/2021, 10:03:39 PM
Well, we see constructive dialogue and make a discount. Your new price is $326.750

Conti 5/19/2021, 10:04:23 PM
We will send you 30% of the file tree, you will select any 3 pcs of non-sensitive information and we will provide them to you as evidence.

Victim 5/19/2021, 10:58:27 PM
send us the file tree and i can show it to my boss, with the new amount

Conti 5/20/2021, 10:45:36 AM
wait.

Conti 5/20/2021, 10:48:30 AM
30%_tree_[redacted].txt.7z [ 126kB ]

Conti 5/20/2021, 10:48:41 AM
Pass: 123123

Victim 5/20/2021, 3:55:30 PM
we want to get this done quickly and can offer $98,350.00

Conti 5/20/2021, 4:08:06 PM
Well, we see constructive dialogue and make a discount. Your new price is $301.650

Victim 5/20/2021, 6:10:11 PM
we don't have that much, but made some more cuts and can offer 137,500

Conti 5/20/2021, 6:15:26 PM
Well, we see constructive dialogue and make a discount. Your new price is $262.500

Conti 5/20/2021, 6:15:36 PM
We move to meet each other - this positively affects the likelihood of an agreement.

Victim 5/20/2021, 10:01:19 PM
laptop proposals.pdf.[redacted] [ 3.8MB ]

Victim 5/20/2021, 10:01:30 PM
Registry Fix.jpg.[redacted] [ 73kB ]

Victim 5/20/2021, 10:01:36 PM
we would like proof you can decrypt

Conti 5/20/2021, 10:14:31 PM
Wait.

Conti 5/20/2021, 10:22:04 PM
laptop proposals.pdf [ 3.8MB ]

Conti 5/20/2021, 10:22:15 PM
Registry Fix.jpg [ 72kB ]

Victim 5/20/2021, 11:41:40 PM
if you will accept $182,450 we can make the payment within 24 hours

Conti 5/21/2021, 12:00:28 PM
$200,000 and we agree. Think well, this is our minimum offer.

Victim 5/21/2021, 3:36:08 PM
We agree to the price for the decryptor, file tree, and proof of deletion. How do we finish this up?

Victim 5/21/2021, 4:49:03 PM
Also we can't get into our systems, will you give instructions on that also?

Conti 5/21/2021, 6:39:13 PM
BTC Wallet: [redacted]

Conti 5/21/2021, 6:40:12 PM
Once you pay, you'll get a file tree, deletion log, and a decryptor for all your computers.

Victim 5/21/2021, 6:43:21 PM
What about the machine we cant get into?

Conti 5/21/2021, 6:52:37 PM
What hostnames are the speech about?

Victim 5/21/2021, 6:58:00 PM
I will get a list from our IT leaders

Conti 5/21/2021, 6:59:15 PM
What's wrong with passwords from accounts? or what? Explain in more detail the problem is not very clear.

Conti 5/21/2021, 6:59:56 PM
Of course, we will help if it depends on us.

Victim 5/21/2021, 7:12:12 PM
We have made the payment, please let me know it went through

Conti 5/21/2021, 7:36:10 PM
[redacted]_decryptor.exe [ 103kB ]

Conti 5/21/2021, 7:37:07 PM
Decryptor:
1) Launch the decryptor under Administrative rights
2) Wait till the decryptor window is closed
3) if any of the files haven't changed the extension back to the original - repeat 1 and 2

Conti 5/22/2021, 1:12:35 AM
The file tree and deletion log are expected to be checked out within 24 hours.

Victim 5/22/2021, 4:46:19 PM
How does that work? Do you give us the data back? Sorry but we have never done this before.

Conti 5/22/2021, 5:39:13 PM
Wait for the file list and delete log. will receive within 48 hours. Instructions for working with the decryptor are written above. Get an IT specialist to help you recover.

Victim 5/25/2021, 5:30:45 PM
can we get our file list and delete log?

Conti 5/25/2021, 9:11:35 PM
[redacted]_tree.zip [ 433kB ]

Conti 5/25/2021, 9:11:54 PM
SHRED_[redacted].zip [ 4.4MB ]

Conti 5/25/2021, 9:12:07 PM
file list and delete log

Auteur/autrice

sdgadmin@tux.ovh