Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Negotiation Chat – trinity

Chat ID: 0007

Victim Avatar
hello
Victim Avatar
hello
hello
Gang Avatar
Victim Avatar
what do we have to do to acces our files ?
Please say your network domain
Gang Avatar
Victim Avatar
i sent you email to
Yes I see
Gang Avatar
Victim Avatar
what info do you need ?
[redacted] ?
Gang Avatar
Victim Avatar
idd
your network?
Gang Avatar
Victim Avatar
[redacted] is correct
Price for decrypt 70000$ in bitcoin amount
Gang Avatar
Victim Avatar
ok, i'm talking with management
Victim Avatar
is there any garantee tht we can decrypt all files ?
Victim Avatar
i see the VHDX files are only 3GB and the were much bigger ..
We have been working for several years and all our clients have received their key. You can send us up to 10 files for the test decrypt, but these files should not contain important information
Gang Avatar
Victim Avatar
ok, and my VHD files will decrypt as wel ? they were +1TB in size and now only 3GB
Yes
Gang Avatar
Inside the hard disk these files have normal size
Gang Avatar
Victim Avatar
In order to proceed, my manager requires a due dilligence step that protects us from liability, and that is to obtain proof that you have our sensitive files before we can consider payment. For that reason, can you provide the cleartext copy of the "[redacted]_V10_13_8_GP.ZIP" file located in the "C:\Users\Administrator\Downloads" folder on one of the encrypted servers.
we don't loan out valuable files for testing for the test send 1-2 files (1-5 mb) not backup and database
Gang Avatar
If you don't pay, we'll put your data on the leak sites. https://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion/ companies/2148689972 ,and similar sites
Gang Avatar
Victim Avatar
In order to negotiate a resolution, we would require proof of data posession, so we have asked you for a file that does not contain sensitive information (you can verify that in the file itself). We have so far not received any evidence of you posessing cleartext copies of our data. Such evidence allows me to talk to my manager, who will eventually decide on the best course of action, as we have multiple alternatives.
We can't provide this file to you.
Gang Avatar
Victim Avatar
Since we cannot show our manager any proof of stolen data, we cannot argue such a high ransom demand. We do have backups which are few weeks old, but I am convinced that our manager would pay a smaller fee for decryption key in order to have the latest data in a much faster way. They are willing to offer you $10.000 for the decryption key.
We have already told you the price. The only way you can reduce the final price is to pay today and then we can think about a discount.
Gang Avatar
but 10000$ just a joke for us, you should understand it. We can make discount 10.000$ if you pay today
Gang Avatar
Victim Avatar
I will have to take that offer to my manager. In the meantime, how can you provide proof of having a working decryption key? Can we provide you with an encrypted file and you decrypt it?
Victim Avatar
I will have to take that offer to my manager. In the meantime, how can you provide proof of having a working decryption key? Can we provide you with an encrypted file and you decrypt it?
Yes, send file here https://dropmefiles.com/
Gang Avatar
Yes, send file here https://dropmefiles.com/
Gang Avatar
Victim Avatar
Hereby https://dropmefiles.com/[redacted]
https://dropmefiles.com/[redacted]
Gang Avatar
pass 123
Gang Avatar
You don't use our discount offer. So the price is 70.000$ again. Tomorrow it will rise again.
Gang Avatar