Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes:

IOC

All of your files are currently encrypted by CONTI ransomware. 
If you try to use any additional recovery software - the files might be damaged or lost.

To make sure that we REALLY CAN recover data - we offer you to decrypt samples. 

You can contact us for further instructions through our website : 

TOR VERSION : 
(you should download and install TOR browser first https://torproject.org) 

http://m232fdxbfmbrcehbrj5iayknxnggf6niqfj6x4iedrgtab4qupzjlaid.onion 

HTTPS VERSION : 
https://contirecovery.info 

YOU SHOULD BE AWARE! 
Just in case, if you try to ignore us. We've downloaded your data and are ready to publish it on out news website if you do not respond. So it will be better for both sides if you contact us ASAP.

---BEGIN ID---
[snip]
---END ID---

Indicators of Compromise
Type IOC
onion url http://m232fdxbfmbrcehbrj5iayknxnggf6niqfj6x4iedrgtab4qupzjlaid.onion