Hive — 20211113
Dated recordFrom extortion.wiki, the ransomware negotiation research archive
A validated static rendering of 136 messages in source-array order. Transcript text is preserved without editorial additions.
- Actor
- Hive
- Record date
- Nov 13, 2021
- Messages
- 136
- Participants
- Hive, Victim
Preserved messages
Actor / other Victim
Select a message number for a stable citation link. Text remains selectable; hard-wrapped source lines are joined for reading, intentional blank-line paragraph breaks remain, and written URLs remain inert.
-
Message 001 From Hive Actor / other Date Hello and welcome to Hive. How may I help you?
-
Message 002 From Victim Victim Date Hi, decryption key price?
-
Message 003 From Victim Victim Date how many files are stolen? and can you share some file names?
-
Message 004 From Victim Victim Date maybe no ones here
-
Message 005 From Hive Actor / other Date Hello
-
Message 006 From Hive Actor / other Date To decrypt your files you have to pay $20,000,000 in Bitcoin.
-
Message 007 From Victim Victim Date thats way too much, can you please discount
And please share the hash of the ransomware file so we can at least black list it. You have already stolen everything anyway
-
Message 008 From Hive Actor / other Date We don't provide any hashes. Every time the software is unique. There is no need of hashes here. It will not help anyway.
-
Message 009 From Hive Actor / other Date If you want a discount I would like to see for how much
-
Message 010 From Victim Victim Date let me talk to the management
-
Message 011 From Victim Victim Date share some file names?
-
Message 012 From Hive Actor / other Date I'll share with you later when my teammate will be online.
-
Message 013 From Victim Victim Date ok when should I log back in?
-
Message 014 From Hive Actor / other Date I don't know. Maybe today
-
Message 015 From Victim Victim Date ok
-
Message 016 From Victim Victim Date please ask him/her to share the file names so I can have them when I login, its not easy to use TOR here
-
Message 017 From Hive Actor / other Date Okay, I'll do my best
-
Message 018 From Victim Victim Date thanks
-
Message 019 From Hive Actor / other Date I have uploaded the list of exfiltrated files.
-
Message 020 From Victim Victim Date where?
I cant see them
-
Message 021 From Victim Victim Date is it like 100G?
-
Message 022 From Hive Actor / other Date It's at the left panel titled Uploaded files
-
Message 023 From Hive Actor / other Date I uploaded a list of files not the files themselves
-
Message 024 From Victim Victim Date yes got it, thanks
-
Message 025 From Victim Victim Date you can delete it now
-
Message 026 From Victim Victim Date Can you please share the hash of the ransomware. SO we can just add it to black list and ask the management for money. They are scared that the payload will come back. If you can't I understand but this will make th eprocess easy
-
Message 027 From Hive Actor / other Date We are well-known organization. We honor our agreements. There is no point in the blacklist right now. You need to concentrate on how to collect money.
-
Message 028 From Hive Actor / other Date I have another option for you. You will give me your email address (protonmail is preferred) and I'll send you new credentials to login. Then I'll upload the encryptor to VirusTotal and provide you a link to it. All necessary hashes will be available there. But to prevent others to login to your customer website you have to get new credentials first.
-
Message 029 From Victim Victim Date Here [redacted]@protonmail.com
-
Message 030 From Victim Victim Date just like you wanted... protonmail
-
Message 031 From Victim Victim Date please keep your word, I will login again in a bit or check my email
-
Message 032 From Victim Victim Date BTW, the site you guys made is beautiful. Better support than normal companies:)
-
Message 033 From Hive Actor / other Date Thank you
-
Message 034 From Victim Victim Date did you upload the file?
-
Message 035 From Victim Victim Date and why did you change my creds... are you planing to hack me too?:(((((
-
Message 036 From Hive Actor / other Date The encryptor didn't uploaded yet, looking for it rn.
-
Message 037 From Hive Actor / other Date What do you mean about creds? From what?
-
Message 038 From Victim Victim Date you change the credential to login to this site
-
Message 039 From Hive Actor / other Date It was necessary because whether I upload the encryptor other researchers will be able to login and read your conversation.
-
Message 040 From Hive Actor / other Date It's a potential data leakage so I have prevented it
-
Message 041 From Victim Victim Date Thanks
-
Message 042 From Victim Victim Date would you share the link here or email?
-
Message 043 From Hive Actor / other Date Here is safe now
-
Message 044 From Victim Victim Date ok
-
Message 045 From Victim Victim Date why do you prefer protonmail?
-
Message 046 From Victim Victim Date is it on tor?
-
Message 047 From Hive Actor / other Date https://www.virustotal.com/gui/file/12baa6c83e6f8b059e7f14cb67bdad4e917b90bc8a139b5379a4b42a0c92a6be?nocache=1
-
Message 048 From Victim Victim Date Thanks. I dont have virus total account but at least I got the hash. Really appreciat eit
-
Message 049 From Victim Victim Date we have mcafee and symantec and nothing prevented this:(
-
Message 050 From Hive Actor / other Date Actually I didn't spend too much time to hide it but I will
-
Message 051 From Hive Actor / other Date What a recovery company are you from?
-
Message 052 From Victim Victim Date not from company, directly the SOC team
-
Message 053 From Hive Actor / other Date I got it
-
Message 054 From Victim Victim Date working with the management to do something
-
Message 055 From Victim Victim Date they may hire someone in hope of recovery.
-
Message 056 From Hive Actor / other Date Unfortunately for them there are only two options: 1) start from a scratch 2) purchase the decryption software from us
-
Message 057 From Victim Victim Date yes I have provided all the data
-
Message 058 From Hive Actor / other Date Recovery companies no matter what they say can't decrypt.
-
Message 059 From Victim Victim Date I understand but in the demo they show us how they can do the magic and impress the management
-
Message 060 From Victim Victim Date THey told us that they will recover the keys from the memory and then decrypt files? is that possible?
-
Message 061 From Hive Actor / other Date For ESXi servers it's not possible
-
Message 062 From Victim Victim Date why not? please educate me to I can understand and tell the management not to waste time. We have way too many vendors here
-
Message 063 From Hive Actor / other Date The encryptor software rewrites the key from memory.
-
Message 064 From Victim Victim Date what?:(... liek in simple words please?
-
Message 065 From Hive Actor / other Date Array of bytes in memory where the key resides in rewrites to prevent such operation
-
Message 066 From Victim Victim Date Thats awesome. Is this for all servers or only esxi?
-
Message 067 From Hive Actor / other Date For all of course
-
Message 068 From Victim Victim Date so if we end-up hiring a company that charges us $400 an hour, its pretty much useless?
-
Message 069 From Victim Victim Date BTW, the array of memory that you mentioned, these are the public keys or the private keys?
-
Message 070 From Hive Actor / other Date Encryptor even don't know anything about private keys. It only has public keys. Public keys need to encrypt random field which uses in encryption process.
-
Message 071 From Hive Actor / other Date In my opinion spending money to external IT companies will only waste your valuable time.
-
Message 072 From Victim Victim Date Thanks, appreciate it. Its clear to me now
-
Message 073 From Victim Victim Date Hey, how much data have you stolen 100Gig?
-
Message 074 From Victim Victim Date And the price you provided $20,000,000 is way too much
-
Message 075 From Victim Victim Date This is 20 million $?????
-
Message 076 From Hive Actor / other Date Yes, your company has $2B revenue. We usually rate 1% of revenue
-
Message 077 From Victim Victim Date :( And the total you have stolen in GB?
-
Message 078 From Victim Victim Date I am guessing you used the VPN to get on the network. Did you steal the credentials after that? SYmantec and McAfee didn't prevent stealing credentials?
-
Message 079 From Hive Actor / other Date We have 32 Gb total. Almost all AntiViruses are useless against real hackers.
-
Message 080 From Victim Victim Date unfortunate but true
-
Message 081 From Victim Victim Date For some reason the IT guy told us that they can see certain portion of files and they could be decrypted.
-
Message 082 From Victim Victim Date I think you are only encrypting certain portion of files right? they can see the file content in bigger files
-
Message 083 From Hive Actor / other Date There is a spotted encryption mechanism. If you are talking about ESXi files then I don't think they can. Some text files - yes
-
Message 084 From Victim Victim Date I mean the big files are not fully encrypted. They are encypted at the header and then footer I think... but in the middle one can see the text.
-
Message 085 From Hive Actor / other Date It's true. First 4Kb, the last, and a few blocks in the middle
-
Message 086 From Victim Victim Date But this is nto true for ESXi files? everything for them is encrypted?
-
Message 087 From Victim Victim Date also how efficient is your encryption process? are you faster than lockbit2.0?
-
Message 088 From Victim Victim Date we also got one file for lockbit but was protected that was few weeks ago
-
Message 089 From Hive Actor / other Date I didn't compare it with lockbit but my software is quite fast, especially ESXi
-
Message 090 From Hive Actor / other Date How is it going with decision making?
-
Message 091 From Victim Victim Date its slow, we provided all the data and making sure they understand the complexity
-
Message 092 From Victim Victim Date But for the esxi part, you don't use partial encryption? and everything is encrypted?
-
Message 093 From Victim Victim Date not just 4kb header etc
-
Message 094 From Victim Victim Date can you please explain 2 things to understand. Explain a bit more on how you re-write the keys in the memory and the efficiency of esxi encryption. That way I can explain to everyone as well, that no hope for recovery
-
Message 095 From Victim Victim Date most probly I will ask for discount shirtly
-
Message 096 From Hive Actor / other Date It's very simple. ESXi files especially virtual drives are very fragile. Even few changes make them unreadable because it has a binary structure. ESXi was encrypted using spot method. 4 Kb of beginning of the files, 4 Kb of ending of the file and along file. Totally 100 Kb over the each file is encrypted. It's a quite enough.
-
Message 097 From Victim Victim Date cool and the memory re-writing? as I understand you are not creating a new key for each file
-
Message 098 From Victim Victim Date The memory overwrite is my last question. So I can make sure the SOC team understands
-
Message 099 From Hive Actor / other Date When encryptor starts it creates a random field which will be used in encryption process. It is static. After encryption process finishes it rewrites to prevent restoration process. RSA keys private and public only use to encrypt/decrypt the random field. Only knowing the field it's possible to decrypt files. Encryptor has only public RSA keys, decryptor - private RSA keys.
-
Message 100 From Victim Victim Date by random fields u mean aes?
-
Message 101 From Hive Actor / other Date No, a truly cryptographic random field.
-
Message 102 From Victim Victim Date like PRNG or truly random numbers?
-
Message 103 From Hive Actor / other Date Of course not PRNG:)
-
Message 104 From Victim Victim Date :(
-
Message 105 From Victim Victim Date can you give me an example
-
Message 106 From Victim Victim Date so you have the origanal private key. The ransomware generates fields that will encrypt files? are these fields used as keys? for aes?
-
Message 107 From Victim Victim Date You are one smart guy
-
Message 108 From Hive Actor / other Date Actually I already disclose you a lot of details which was never disclosed to anyone. I think it's enough to make a decision.
-
Message 109 From Victim Victim Date Thanks
-
Message 110 From Hive Actor / other Date AES is a chiper, I use a different one - some kind of Vernam's chiper. It's impossible to decrypt without knowing the keys.
-
Message 111 From Victim Victim Date that means only one key will be used for all files and then re-written
-
Message 112 From Victim Victim Date so no way to get back
-
Message 113 From Hive Actor / other Date In simplified version the key used to encrypt all files. It exports to the disk using a few RSA public keys applied. Then encryption process follows. After that the key rewrites to prevent recovery from memory.
Decryption software has RSA private keys to initially decrypt the exported key.
-
Message 114 From Victim Victim Date Whats the BTC address or wallet?
-
Message 115 From Hive Actor / other Date I made an offer at the right panel
-
Message 116 From Victim Victim Date you came into the network via global protect. Are you still on the network?
-
Message 117 From Hive Actor / other Date No
-
Message 118 From Victim Victim Date you are very honest for a hacker
-
Message 119 From Hive Actor / other Date We are all honest who works at Hive
-
Message 120 From Victim Victim Date but they say you hacked hospitals like [redacted] etc
-
Message 121 From Hive Actor / other Date Yes, we attack every targets, we have no limits here. It's not related with honesty
-
Message 122 From Victim Victim Date Got it
-
Message 123 From Victim Victim Date I think the time is up:(
-
Message 124 From Hive Actor / other Date Don't worry you have time. Tell me how is it going with upper management please
-
Message 125 From Victim Victim Date working on it, tough situation
-
Message 126 From Hive Actor / other Date Hi, how is it going?
-
Message 127 From Victim Victim Date good thanks
-
Message 128 From Victim Victim Date how r u
-
Message 129 From Hive Actor / other Date I'm good too. I just wanted to know to what direction your company inclined right now.
By the way, what about a recovery process from memory from recovery company you told earlier?
-
Message 130 From Victim Victim Date They think the recovery is possible
-
Message 131 From Victim Victim Date also backup etc
-
Message 132 From Hive Actor / other Date Let's play with the price. I think both your management and our side want to resolve this as quick as possible
-
Message 133 From Victim Victim Date Whats the best price?
-
Message 134 From Victim Victim Date I am not sure if 333 is even remotely possible
-
Message 135 From Victim Victim Date They won't even consider 80 a possibility
-
Message 136 From Hive Actor / other Date I can offer you $3,000,000 in Bitcoin.