Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes:

IOC

All of your files have been encrypted! ( By Babuk Locker )

Your computer was infected with a ransomware virus. Your files have been encrypted and you won't be able to decrypt them without our help. What can I do to get my files back? You can buy our special Decryption Software, this Software will allow you to recover all of your data and remove the ransomware from your computer.

To buy Decryption Software write to us Tox or email!

email: babuklockerofficial@onionmail.org
------------------------------------------------
Download Session                                            
https://getsession.org/download                                                      
Session ID: 051a6a26dcc1687da6c216fe69cd46cf49931c66484898e4d613eb08466f6be25d                                                        ------------------------------------------------                                     
Download Tox
https://tox.chat/download.html
Tox ID Support: 
022A7EEB83B648F55DA7A6BEFD130C2156C74F3501A31D853234EC2D18E77A1E5BEC7F602011
------------------------------------------------
Group Telegram Affiliation :
https://t.me/+K4bO49DCiI9lMTBl
------------------------------------------------
Affiliate Channels Telegram :
https://t.me/+kKRPXvOJcdY4NGI1
------------------------------------------------
Babuk Locker 2.0 Official Channel Telegram :
https://t.me/y4wLPNEEagVjNDI1
------------------------------------------------
Operator Babuk (Telegram):
@OfficialBabukLocker
------------------------------------------------
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsBNBGenNbgBCAC0K/EWd8wBkFEckEbDT6Fb5bVYdVFrpMo7xMyBMAkAFpTp
ebqFQlmYRMDDcvLCr+XlIyUCf+gOe/+YBdDhvcrLVFBD81q14TUXjVKa5YTR
WPdCa7glWJBPbJskYya1vMcn1DZMX4oqgZ02sVJVIH54maVDcDvpHIcLbSAz
5Hq5ITo+lL/iJalhh3hC0xzwRByLEi1/aUYcPo0xWJWRRnPHbUjAImqyDYQv
ova1a6rUK9A08y7Rn/IKUKthfzoMYBSjF166wH1TCseeHjCB1x9d60Dmhwpe
z7ysiZpkZkvDE7B+UL1DFALZEpyuWW/U6wXMoItSRDtv6Dxpgm8MlK+xABEB
AAHNL0JhYnVrTG9ja2VyIDxiYWJ1a2xvY2tlcm9mZmljaWFsQG9uaW9ubWFp
bC5vcmc+wsCNBBABCAAgBQJnpzW4BgsJBwgDAgQVCAoCBBYCAQACGQECGwMC
HgEAIQkQYKkhEx1FdnAWIQQD0LHuqlWycDk8hUFgqSETHUV2cPVuCACFiBFV
N/I7Rd0bAb5FNrGHcRupm+K7syfs7umaQuEIx2mtghVWyr6hlev0oCNjRM3t
vaYc/Cwyitg/H/jRhdiVoOCsvbKeIY4LdZPHfDj/EiYFp9SIUihh8SpdD+wL
IRVtw5RNu9jRbw4x7KO3bJRw9VVh75Orsh3uPlFvxfCHii9D/FA1unpSC5zg
W8eBGo0HgvuPoiHHfMe3TE/e8napNcMl9YgCvdSce/XGoF5560+pp1t6UfLy
qYqFp4sU245ZyOfz1MajdRssqI+rlej5pGsEyOK0GHF/ph+LMultJNNa4KO1
avysleMvLV3JtjpfJpYJU2f5ITzq2NeQwPEazsBNBGenNbgBCADNe3MsZ9V+
53XpyrXaYii/G89QffzFzzt6OyJ8CFO2JTB2AHc1r8qZLB6A0Oftm+hW7h9n
AVZu3SN0YRPxvqRoP2Dt8/tVN8Vx+tYrzpGKh8HVwYIXPEjSllHp/WCEkdGk
qgvdoKcVTdanie+sItxncwuJyo+wZof300X5vT/7/En6PFZrn8ig4ZWdzWD4
AhAQffTxGsUf6lUDVD1sQyeY7weD8M/cy7wNYnp6ypWySt4HaPBtITI0idB0
gvl2dacGWYSbkjOhvmfyk8o5q9JkwOIA5NFt7JYVFdEGtpLm80tStosInph5
BaGOyGkpO4ciXyrXDnB4IYfrab/9dpVlABEBAAHCwHYEGAEIAAkFAmenNbgC
GwwAIQkQYKkhEx1FdnAWIQQD0LHuqlWycDk8hUFgqSETHUV2cDUeB/43jxIG
K+yMqxiAuDdrFRqFxTs184T/zr1BAGtdvF8mvMrSNG9/ELtaOypkNe3QRn8q
5XBkxzXMqRMTIx11hU7yuqw6aU0/gr6faWPaeav/r7FXjyM3G3V+n7SGuteU
mrB5UZZe/4X4BiuC1hA9L2YN/nLP9JhO65rDJzc5wDuH8yWXh1A/EzGsi6nJ
Yq3sVF4OAxsZqaRv9Wk9jrzv5bmpI+yua5eByYa2SqN1+sjb/DIJCY8VdNt4
4TWnSZjcqs8YH1ScYE2mziVTYqExCF0DqpPiQF2lvyXj8ZfXW+gGnkvvsY2u
3sjWqvGbqr7bIKsLuvlhsd5VU9kAPmTB30N2
=Mocj
-----END PGP PUBLIC KEY BLOCK-----

Indicators of Compromise
Type IOC
email babuklockerofficial@onionmail.org
tox id 022A7EEB83B648F55DA7A6BEFD130C2156C74F3501A31D853234EC2D18E77A1E5BEC7F602011
session id 051a6a26dcc1687da6c216fe69cd46cf49931c66484898e4d613eb08466f6be25d
telegram url https://t.me/+K4bO49DCiI9lMTBl
telegram url https://t.me/+kKRPXvOJcdY4NGI1
telegram url https://t.me/y4wLPNEEagVjNDI1
telegram handle @OfficialBabukLocker
pgp public key present