Avaddon Ransomware Negotiation — Redacted Organisation

103Messages
UnknownDuration
$300,000Initial Demand
UnknownOutcome

About This Negotiation

This transcript documents a Avaddon ransomware negotiation with a redacted victim organisation. The negotiation consisted of 103 messages exchanged over Unknown.

The initial ransom demand was $300,000. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Avaddon] — 11:55 30.04.2021 — Message 1/103
Hello from Avaddon Team .Price for you is $300,000. We have downloaded a lot of critical data, which will be published on our news website ([REDACTED URL] if you do not make a payment. After the payment we will decrypt all your systems, give you listing of files that we have taken, remove data from our servers and give you proofs of deletion. Also we will provide you with security report, so you can fix all your vulnerabilities and be safe again.
[Avaddon] — 11:56 30.04.2021 — Message 2/103
We are ready to talk to you and discuss on this matter ....
[Victim] — 14:58 30.04.2021 — Message 3/103
hi
[Victim] — 14:58 30.04.2021 — Message 4/103
is anyone here?
[Avaddon] — 15:05 30.04.2021 — Message 5/103
Hello!
[Victim] — 15:06 30.04.2021 — Message 6/103
wnat to talk to you about this situation
[Victim] — 15:07 30.04.2021 — Message 7/103
your price is very expensive for us
[Victim] — 15:07 30.04.2021 — Message 8/103
300.000$ is our 3 year budget
[Victim] — 15:08 30.04.2021 — Message 9/103
tell us the real possible price and we ready to pay
[Avaddon] — 15:09 30.04.2021 — Message 10/103
How much can you pay at most?
[Victim] — 15:13 30.04.2021 — Message 11/103
give me 5 minute
[Victim] — 15:13 30.04.2021 — Message 12/103
i will talk with my chief
[Avaddon] — 15:14 30.04.2021 — Message 13/103
ok
[Victim] — 15:19 30.04.2021 — Message 14/103
redy to pay 3000$
[Avaddon] — 15:30 30.04.2021 — Message 15/103
This is a joke?
[Avaddon] — 15:30 30.04.2021 — Message 16/103
Your price is $ 300,000.
[Victim] — 15:32 30.04.2021 — Message 17/103
300.000$ is a joke
[Victim] — 15:32 30.04.2021 — Message 18/103
becauuse we havn't this amount of money
[Victim] — 15:33 30.04.2021 — Message 19/103
3000$ we can pay or go ahead to reainstall all our systems
[Victim] — 15:35 30.04.2021 — Message 20/103
search on map our country Armenia
[Victim] — 15:35 30.04.2021 — Message 21/103
300.000 is out country budget how we can pay this kind of money?
[Avaddon] — 15:38 30.04.2021 — Message 22/103
Perhaps the price is too high for you and we are ready to make a small discount.
[Avaddon] — 15:40 30.04.2021 — Message 23/103
But on $ 3,000 we will never agree.
[Avaddon] — 15:43 30.04.2021 — Message 24/103
Reinstalling all systems and restoring the workflow will take a very long time and you will incur heavy losses. The best option would be to pay and get back to normal quickly.
[Victim] — 15:44 30.04.2021 — Message 25/103
yes you are right
[Victim] — 15:44 30.04.2021 — Message 26/103
we will lose money while trying to reainstall all systems and getting back informtion from external backups
[Victim] — 15:45 30.04.2021 — Message 27/103
but don't lose so much as you want
[Victim] — 15:45 30.04.2021 — Message 28/103
3000$ ready to pay, agree or not?
[Avaddon] — 15:51 30.04.2021 — Message 29/103
We have a lot of your important files that we will publish on our blog if you do not cooperate with us.
[Victim] — 15:52 30.04.2021 — Message 30/103
I know all this
[Victim] — 15:52 30.04.2021 — Message 31/103
but we havn't money!
[Victim] — 15:52 30.04.2021 — Message 32/103
what can we do?!
[Avaddon] — 15:52 30.04.2021 — Message 33/103
You will never be able to get your files back without our decryptor! Only we have a unique key to decrypt your files. Don't waste time and money trying to decrypt files yourself.
[Victim] — 15:53 30.04.2021 — Message 34/103
I know that very well
[Victim] — 15:54 30.04.2021 — Message 35/103
I comunicate with you before
[Victim] — 15:54 30.04.2021 — Message 36/103
I know all this processes
[Victim] — 15:54 30.04.2021 — Message 37/103
and now that we cant decrypt our files
[Victim] — 15:54 30.04.2021 — Message 38/103
we just can reinstall all systemss and restore backups but it will take too long for us
[Avaddon] — 15:54 30.04.2021 — Message 39/103
We are ready to make a very big discount for you. If you pay within 67 hours, we will offer you a 50% discount. Then the price will again be $ 300,000.
[Victim] — 15:55 30.04.2021 — Message 40/103
so we ready to pay as much as we can
[Avaddon] — 15:56 30.04.2021 — Message 41/103
Now you need to pay $ 150,000.
[Victim] — 15:56 30.04.2021 — Message 42/103
what's your name?
[Avaddon] — 15:57 30.04.2021 — Message 43/103
It does not matter.
[Victim] — 15:58 30.04.2021 — Message 44/103
you know our country?
[Victim] — 15:58 30.04.2021 — Message 45/103
how the small firm in Armenia can pay you 150.000?
[Victim] — 15:59 30.04.2021 — Message 46/103
my house cost 15.000$ in all
[Avaddon] — 15:59 30.04.2021 — Message 47/103
Sir, you are offering us a ridiculous price, it does not suit us at all. Before we set you a price of $150,000, we analyzed your profitability and your capabilities in general, this price was taken not from the sky, but according to specific criteria, and by analysis.
[Victim] — 16:00 30.04.2021 — Message 48/103
what can I say, your analysis is wrong...
[Victim] — 16:01 30.04.2021 — Message 49/103
last time a year ago I paid 1700$ for your decrypting key
[Avaddon] — 16:06 30.04.2021 — Message 50/103
And we will tell you that $ 15,000 is still not enough, and we do not agree to such a small amount. Suggest more or we will use other methods. We can share your financial statements, your employee and customer data, and more in the public domain. Use DDOS. We can completely ruin the reputation of your business. Then you will have a lot of problems and you will suffer a lot of damage. You choose ...
[Victim] — 16:07 30.04.2021 — Message 51/103
I don't event suggest 15.000$, because I havn't
[Avaddon] — 16:10 30.04.2021 — Message 52/103
We want to talk to your boss.
[Victim] — 16:11 30.04.2021 — Message 53/103
I called him, will be here in 15 minutes
[Victim] — 16:22 30.04.2021 — Message 54/103
Hi, I'm CEO
[Victim] — 16:23 30.04.2021 — Message 55/103
my name is [redacted]
[Victim] — 16:25 30.04.2021 — Message 56/103
ready to cooperate with you ...
[Avaddon] — 16:25 30.04.2021 — Message 57/103
Hello, [redacted]!
[Avaddon] — 16:26 30.04.2021 — Message 58/103
Are you already aware of the situation?
[Victim] — 16:26 30.04.2021 — Message 59/103
yes, of course
[Victim] — 16:29 30.04.2021 — Message 60/103
but unfortunately your requirements are in not compatible with the budget of our company ...
[Avaddon] — 16:31 30.04.2021 — Message 61/103
How much can you offer? As we already wrote, the amount of $ 15,000 or $ 20,000 does not interest us.
[Victim] — 16:33 30.04.2021 — Message 62/103
:)
[Victim] — 16:34 30.04.2021 — Message 63/103
and how much you want if you don't agree with 15.000 or 20.000?
[Avaddon] — 16:37 30.04.2021 — Message 64/103
You're not serious! You do not understand the magnitude of the problems for your company. Are you ready to incur losses and ruin your reputation or will you cooperate and offer a higher amount?
[Avaddon] — 16:37 30.04.2021 — Message 65/103
We have already offered you a very large discount, which we do not do for other clients. We have made a 50% discount for you.
[Victim] — 16:38 30.04.2021 — Message 66/103
I asked how much you want?
[Victim] — 16:39 30.04.2021 — Message 67/103
I perfectly understand all the risks
[Avaddon] — 16:44 30.04.2021 — Message 68/103
The price for you is $ 150,000.
[Avaddon] — 16:44 30.04.2021 — Message 69/103
After the expiration of the time, the price will double and then it will be $ 300,000.
[Victim] — 16:49 30.04.2021 — Message 70/103
it's not serious my company is not able to pay you that kind of money let my IT specialists stay awake for several days and restore archives or pay you this money as they want
[Victim] — 16:49 30.04.2021 — Message 71/103
by
[Avaddon] — 16:52 30.04.2021 — Message 72/103
You cannot recover files without our unique key.
[Avaddon] — 16:53 30.04.2021 — Message 73/103
You have 66 hours to start working with us or you will have a lot of problems.
[Avaddon] — 04:02 03.05.2021 — Message 74/103
After 7 o'clock your amount to double. This is the last chance to pay at such a low price.
[Avaddon] — 11:39 03.05.2021 — Message 75/103
Hi guys are you there ?
[Avaddon] — 11:40 03.05.2021 — Message 76/103
Contact us if you see this, it looks like we have a misunderstanding.
[Victim] — 16:04 03.05.2021 — Message 77/103
hi
[Victim] — 16:04 03.05.2021 — Message 78/103
what you mean?
[Avaddon] — 16:20 03.05.2021 — Message 79/103
Sir, we found out that one of the branches of your network is located in Armenia, our policy of work does not allow working in the CIS countries, so we will give you a decryptor general with which you can decrypt your entire network. We strongly apologize for this unpleasant incident and would like to say that we will help you restore your systems even if you have any problems.
[Victim] — 05:32 04.05.2021 — Message 80/103
really? this is a great news
[Victim] — 05:35 04.05.2021 — Message 81/103
despite the fact that we already recover most of our information, we will be thankful if you give us the key
[Avaddon] — 05:40 04.05.2021 — Message 82/103
You can download the decryptor.
[Victim] — 05:43 04.05.2021 — Message 83/103
from where? give link please
[Victim] — 05:43 04.05.2021 — Message 84/103
is it free software?
[Avaddon] — 05:46 04.05.2021 — Message 85/103
[REDACTED URL]
[Victim] — 07:00 04.05.2021 — Message 86/103
look like it's work...
[Victim] — 07:03 04.05.2021 — Message 87/103
can you also help us to understand how you did that?
[Victim] — 07:04 04.05.2021 — Message 88/103
we want to found out loophole in our network
[Avaddon] — 07:33 04.05.2021 — Message 89/103
Weak passwords.
[Victim] — 07:41 04.05.2021 — Message 90/103
but how you could come in to our network?
[Avaddon] — 07:42 04.05.2021 — Message 91/103
I will clarify this point.
[Victim] — 07:47 04.05.2021 — Message 92/103
we will wait for your clarifying ant will be very thankful for your support
[Avaddon] — 07:48 04.05.2021 — Message 93/103
Ok
[Avaddon] — 08:16 04.05.2021 — Message 94/103
You guys should do penetration tests more often. Hire a professional company and they will find all loopholes in your network. It will cost you few ten thousends but you will be safe.
[Avaddon] — 08:18 04.05.2021 — Message 95/103
Update all services with outside internet, especially Ms Exchange server.
[Victim] — 08:21 04.05.2021 — Message 96/103
you used zerologon exploit ?
[Avaddon] — 08:26 04.05.2021 — Message 97/103
We cannot say anything more for security reasons for personal purposes.
[Victim] — 08:30 04.05.2021 — Message 98/103
ok , we understood , thanks for information , we will upgrade our exchange server and do several things for security
[Avaddon] — 08:58 04.05.2021 — Message 99/103
Ok guys, excuse us again, I hope you didn't report this to the police? :)
[Victim] — 09:21 04.05.2021 — Message 100/103
))
[Avaddon] — 09:23 04.05.2021 — Message 101/103
What does it mean ?:)
[Victim] — 09:27 04.05.2021 — Message 102/103
don't worry about that
[Avaddon] — 09:28 04.05.2021 — Message 103/103
Ok sir , good luck

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.