Negotiation negotiation
negotiation Negotiation Darkside 2021 20210215 2021-02-15
Actor
Darkside
Record date
Feb 15, 2021
Messages
24
Participants
Darkside, Victim

Preserved messages

Actor / other Victim

Select a message number for a stable citation link. Text remains selectable; hard-wrapped source lines are joined for reading, intentional blank-line paragraph breaks remain, and written URLs remain inert.

  1. Message 001 Victim Victim

    Hello. My files are encrypted. Can you help?

  2. Message 002 Darkside Actor / other

    Hello

  3. Message 003 Darkside Actor / other

    Yes, we can decrypt your all files

  4. Message 004 Darkside Actor / other

    When will you pay? You don't have much time left to pay with a discount

  5. Message 005 Victim Victim

    Thank you. We are working as fast as we can. Can you please decrypt the following files so we know that decryption is going to work?

    [redacted]_L.jpg.[redacted] 60.85 kB

  6. Message 006 Victim Victim

    File:

    [redacted]_M.jpg.[redacted] 14.8 kB

  7. Message 007 Victim Victim

    File:

    [redacted]_T.jpg.[redacted] 8.81 kB

  8. Message 008 Darkside Actor / other

    Yes. We will send the decrypted files shortly

  9. Message 009 Darkside Actor / other

    First

    [redacted].jpg 60.71 kB

  10. Message 010 Darkside Actor / other

    Second

    [redacted].jpg 14.66 kB

  11. Message 011 Darkside Actor / other

    Third

    [redacted]_T.jpg 8.67 kB

  12. Message 012 Victim Victim

    Thank you for decrypting the files. Our business has suffered during the COVID pandemic. We can pay $184,922 in Bitcoin to restore our computers.

  13. Message 013 Darkside Actor / other

    If you pay within the next 24 hours we can give you $25,000 discount, but not more.

  14. Message 014 Victim Victim

    We searched your group and people say you take data. Did you take any of our data? We can pay $226,000 in Bitcoin to restore our computers.

  15. Message 015 Darkside Actor / other

    $250,000 and we will finish this very quickly

  16. Message 016 Victim Victim

    Thank you. I will bring this to my management now. Are you able to tell me if your group took any data from our computers?

  17. Message 017 Darkside Actor / other

    We didn't take data.

  18. Message 018 Victim Victim

    Thank you. We accept your offer of $250,000. Can you please confirm the Bitcoin wallet. We have [redacted]

  19. Message 019 Darkside Actor / other

    Confirmed.

  20. Message 020 Darkside Actor / other

    Write after sending payment.

  21. Message 021 Victim Victim

    Payment sent, please confirm that it was received.

  22. Message 022 Darkside Actor / other

    Linux decryption instruction: 1. Upload decryptor to esxi. 2. Set run permissions: chmod 777 decryptor 3. Run decryptor:./decryptor

    lin_decryptor.out 2.3 MB

  23. Message 023 Darkside Actor / other

    The decryptor works in 2 modes: 1. GUI 2. Console

    Three functions are available in GUI mode: 1. "DECRYPT ALL" - search and decrypt ALL encrypted files on the local PC and on network resources (Shares), where this PC has access. 2. "DECRYPT FOLDER" - decrypts files in the specified folder, which you can select in the "Browse for folders" window or drag and drop the folder into the decryptor window. 3. "DECRYPT ONE FILE" - decrypts a single file, which you can open in the "Open" window or drag and drop the encrypted file into the decryptor window.

    IMPORTANT! Extension of encrypted files may not coincide with the extension of files, which the decryptor suggests to open! To open encrypted files with other extensions, in the "Open" window select, in the lower right corner of "All Files (*. *)" or just drag and drop the given file into the decryptor window. File extension does not affect the decryption of file!

    Console mode has two parameters: 1. "-all" - search and decrypt ALL encrypted files on the local PC and on network resources (Shares), where this PC has access. You can also use Group Policy to quickly decrypt your entire network. 2. "-path" - decrypts files in the specified folder or a single file. 3. Dragging and dropping an encrypted file or folder with encrypted files onto the decryptor file. In this mode, the console window will open automatically, which will display the decryption process.

    Command line examples: > decryptor.exe -all > decryptor.exe -path C:\Folder > decryptor.exe -path C:\Folder\file.txt.[redacted]

    win_decryptor.exe 76.5 kB

  24. Message 024 Darkside Actor / other

    You have 48 hours for support. After that, this chat will be deleted.