Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes:

IOC

-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
                                                            HELLO
				                            [snip]					
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-

                                                    ----> Attention <----
                                                
DO NOT:
  ->Modify, rename, copy or move any files or you can DAMAGE them and decryption will be impossible
  ->Use any third-party or public Decryption software, it also may DAMAGE files
  ->Shutdown or Reset your system, it can DAMAGE files
  ->Hire any third-party negotiators (recovery/police and etc)
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-

                                             Your security perimeter was BREACHED.
				Critically important servers and hosts were completely ENCRYPTED.
        This README-FILE here for you to show you our presence in your's network and avoid any silence about hacking and leakage. 
                   Also, we has DOWNLOADED about 700GB your MOST SENSITIVE Data just in case if you will NOT PAY, 
                           than everything will be PUBLISHED in Media and/or SOLD to any third-party.
						   
						   
1) WHAT SHOULD YOU DO:
    --> You have to contact us as soon as possible (you can find contacts below)
    --> You should purchase our decryption tool, so will be able to restore your files. Without our Decryption keys it's impossible
    --> You should make a Deal with us, to avoid your Data leakage

2) YOUR OPTIONS:
    --> IF NO CONTACT OR DEAL MADE IN 3 DAYS:
        Decryption key will be deleted permanently and recovery will be impossible
        All your Data will be Published and/or Sold to any third-parties
        Information regarding vulnerabilities of your network also can be published and/or shared

    --> IF WE MAKE A DEAL:
        We will provide you with the Decryption Key and Manual how-to-use
        We will remove all your files from our file-storage with proof of Deletion
        We guarantee to avoid sharing any details with third-parties
        We will provide you the penetration report and list of security-recommendations

3) WE HAS COLLECTED SUCH DATA AS: 
    --> Confidential files and documents, Passports, HR directories, Employees personal info
    --> Detailed company information, Projects, Sales files and reports, Accountant files
    --> Financial documents, Commercial info, Internal correspondence
    --> Contracts, Agreements, Clients Data
	--> Outlook dumps, SQL dumps and a lot of other sensitive data
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
                                        !!!Instructions for contacting our Team!!!
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
    --> Download and install TOR browser from this site : https://torproject.org
    --> For contact us via LIVE CHAT open our website : http://ebljej7okwfnx5hdfikqqt2uqehihqv3yns3ziij5clqpklwb3i2cxad.onion/r/[snip]
	Your password:[snip]
	Your username:[snip]
	Recovery contact:for[snip]chat@proton.me
    --> If Tor is restricted in your area, use VPN
    --> All your Data will be published in 5 Days if NO contact made
    --> Your Decryption keys will be permanently destroyed in 3 Days if no contact made
    --> Your Data will be published if you will hire third-party negotiators to contact us


Indicators of Compromise
Type IOC
email chat@proton.me
onion url http://ebljej7okwfnx5hdfikqqt2uqehihqv3yns3ziij5clqpklwb3i2cxad.onion/r/[snip]