Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Ransom Note: !!!_READ_ME_!!!.txt

Group: Vect

!!! README !!!

===============================================================
 :::     ::: :::::::::: :::::::: :::::::::::  
 :+:     :+: :+:       :+:    :+:    :+:      
 +:+     +:+ +:+       +:+           +:+      
 +#+     +:+ +#++:++#  +#+           +#+ 
  +#+   +#+  +#+       +#+           +#+ 
   #+#+#+#   #+#       #+#    #+#    #+#  
     ###     ########## ########     ###       
===============================================================

Dear Management, all of your files have been encrypted with ChaCha20 which is an unbreakable encryption algorithm.
Sadly, this is not the only bad news for you. We have also exfiltrated your sensitive data, consisting mostly of databases, backups and other personal information
from your company and will be published on our website if you do not cooperate with us.

The only way to recover your files is to get the decryption tool from us.

To obtain the decryption tool, you need to:
1. Open Tor Browser and visit: http://vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd.onion/chat/[snip]
2. Follow the instructions on the chat page
3. Receive a sample decryption of up to 4 small files
4. We will provide payment instructions
5. After payment, you will receive decryption tool

WARNING:
- Do not modify encrypted files
- Do not use third party software to restore files
- Do not reinstall system

If you violate these rules, your files will be permanently damaged.

Files encrypted: 0
Total size: 0 bytes
Unique ID: [snip]

Backup contact (Qtox): 1A51DCBB33FBF603B385D223F599C6D64545E631F7C870FFEA320D84CE5DAF076C1F94100B5B

Indicators of Compromise
Type IOC
onion url http://vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd.onion/chat/[snip]
tox id 1A51DCBB33FBF603B385D223F599C6D64545E631F7C870FFEA320D84CE5DAF076C1F94100B5B