EPS - "nezapamćeni hakerski napad, kripto tipa"
#84
Ovako izgleda ransomware notes Qilina (pruža informacije o plaćanju i pretnji, kako poslati uplatu i koliko treba da se plati, i šta se dešava ako ne platiš otkup)

README-RECOVER-[rand].txt
Quote:-- Qilin



Your network/system was encrypted.

Encrypted files have new extension.



-- Compromising and sensitive data



We have downloaded compromising and sensitive data from you system/network

If you refuse to communicate with us and we do not come to an agreement, your data will be published.

Data includes:

- Employees personal data, CVs, DL , SSN.

- Complete network map including credentials for local and remote services.

- Financial information including clients data, bills, budgets, annual reports, bank statements.

- Complete datagrams/schemas/drawings for manufacturing in solidworks format

- And more...



-- Warning



1) If you modify files - our decrypt software won't able to recover data

2) If you use third party software - you can damage/modify files (see item 1)

3) You need cipher key / our decrypt software to restore you files.

4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions.



-- Recovery



1) Download tor browser: https://www.torproject.org/download/

2) Go to domain

3) Enter credentials-- Credentials

Extension: [snip]
Domain: e3v6tjarcltwc4hdkn6fxnpkzq42ul7swf5cfqw6jzvic4577vxsxhid(.)onion
login: [snip]
password:[snip]

DtMXQFOCos-RECOVER-README.txt
Quote:-- Agenda

Your network/system was encrypted.
Encrypted files have new extension.

-- Compromising and sensitive data

We have downloaded compromising and sensitive data from you system/network
If you refuse to communicate with us and we do not come to an agreementyour data will be published.
Data includes:
- Employees personal dataCVsDLSSN.
- Complete network map including credentials for local and remote services.
- Financial information including clients databillsbudgetsannual reportsbank statements.
- Complete datagrams/schemas/drawings for manufacturing in solidworks format
- And more...

-- Warning

1) If you modify files - our decrypt software won't able to recover data
2) If you use third party software - you can damage/modify files (see item 1)
3) You need cipher key / our decrypt software to restore you files.
4) The police or authorities will not be able to help you get the cipher key. We encourage you to consider your decisions.

-- Recovery

1) Download tor browser: https://www.torproject.org/download/
2) Go to domain
3) Enter credentials


-- Credentials

Extension: DtMXQFOCos
Domain: wlh3dpptx2gt7nsxcor37a3kiyaiy6qwhdv7o6nl6iuniu5ycze5ydid(.)onion
login: [snip]
password: [snip]
There is no patch for stupidity - Kevin Mitnick
Reply


Messages In This Thread
RE: portal.eps.rs ne radi ceo dan - by Jana - 12-19-2023, 11:06 AM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-19-2023, 11:28 AM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-19-2023, 03:21 PM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-19-2023, 04:17 PM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-19-2023, 10:27 PM
RE: portal.eps.rs ne radi ceo dan - by milos_rs - 12-19-2023, 11:04 PM
RE: portal.eps.rs ne radi ceo dan - by milos_rs - 12-20-2023, 11:56 AM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-20-2023, 12:00 PM
RE: portal.eps.rs ne radi ceo dan - by y0d4 - 12-20-2023, 12:01 PM
RE: portal.eps.rs ne radi ceo dan - by milos_rs - 12-20-2023, 12:21 PM
RE: portal.eps.rs ne radi ceo dan - by milos_rs - 12-20-2023, 12:02 PM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-20-2023, 12:12 PM
RE: portal.eps.rs ne radi ceo dan - by y0d4 - 12-20-2023, 12:38 PM
RE: portal.eps.rs ne radi ceo dan - by 1van - 12-20-2023, 12:42 PM
RE: portal.eps.rs ne radi ceo dan - by 1van - 02-12-2024, 10:11 AM
RE: portal.eps.rs ne radi ceo dan - by milos_rs - 12-20-2023, 12:52 PM
RE: portal.eps.rs ne radi ceo dan - by milos_rs - 12-20-2023, 03:01 PM
RE: EPS - "nezapamćeni hakerski napad, kripto tipa" - by VincaSec - 02-18-2024, 06:13 PM

Forum Jump:


Users browsing this thread: 4 Guest(s)