Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes: READ_ME_FILE_RECOVERY_mvv.txt


Your Network Attached storage device has been compromised and all your files have been locked.

Any sensitive files have been copied to our server. 

We will leak any sensitive data collected unless contacted by you in a timely manner.

Where are all your files?
1) Your files are either on your NAS in encrypted shares.
   (You can check in Control Panel > Shares)
2) In encrypted Zip archives
3) They are uploaded to a cloud account which you will receive access to upon payment


To recover your files you need to follow these instructions:
--------------------------------------------------------------

1) Download TOR browser from: https://www.torproject.org/download/

2) Goto your link: http://dmkhn64rhzqtys7rns6zhtfgqyfbenrvwyaqi7lkvxhlj5yxbh2l54yd.onion/access/[snip]
   (This link is only accessible through the TOR browser)

3) Follow the instructions to make payment or contact support.
   You can also see a sample of files that were collected from your NAS

If you do not access your secure link within 1 week your decryption information will be lost forever.

--QuickLock Team




Indicators of Compromise
Type IOC
onion url http://dmkhn64rhzqtys7rns6zhtfgqyfbenrvwyaqi7lkvxhlj5yxbh2l54yd.onion/access/[snip]