// Context
About This Negotiation
This transcript documents a Darkside ransomware negotiation with a redacted victim organisation.
The negotiation consisted of 243 messages exchanged over Unknown.
The initial ransom demand was $5,500. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at
enquiries@binary-response.com — we will act promptly.
[Victim] — 9 days ago — Message 1/243
How to buy Bitcoin for this amount?
[Darkside] — 9 days ago — Message 2/243
Hello!
[Darkside] — 9 days ago — Message 3/243
Moment please, let me prepare a manual for you.
[Darkside] — 9 days ago — Message 4/243
are you sure that you want to pay in bitcoin? maybe you prefer
monero? cause in case you want to pay in bitcoin, you have to pay in 20%
more because of service fees.
[Victim] — 9 days ago — Message 5/243
how monero works?
[Darkside] — 9 days ago — Message 6/243
process is literally the same
[Darkside] — 9 days ago — Message 7/243
give me a moment i provide a monero tutorial
[Victim] — 9 days ago — Message 8/243
ok good for monero
[Darkside] — 9 days ago — Message 9/243
monero manual
here is the fastest and safest service to buy monero in your country [REDACTED URL]
alternative way is to buy bitcoin via next manual and change it to monero here [REDACTED URL]
bitcoin manual
here are some services where you can safely buy and send bitcoin
[REDACTED URL] manual how to buy and send is placed on the
main page, this is the simplest and fastest way, no any verification
required///////
[REDACTED URL] here is the short manual how to buy and send
[REDACTED URL] profile verification may be
required////////
[REDACTED URL] here is the short manual how to buy and send
[REDACTED URL] profile verification may be
required///
chose which one you like more, and buy bitcoin.
hen text in chat and we provide the wallet for transfer
[Victim] — 9 days ago — Message 10/243
ok. I'm working on it
[Victim] — 9 days ago — Message 11/243
ok. I'm working on it
[Victim] — 9 days ago — Message 12/243
Hi. The price is too high
[Victim] — 9 days ago — Message 13/243
could we find a mediation?
[Victim] — 9 days ago — Message 14/243
we do not have that amount of money. We are a little company
[Victim] — 9 days ago — Message 15/243
5.000€?
[Darkside] — 9 days ago — Message 16/243
We do not make such big discounts.
[Darkside] — 9 days ago — Message 17/243
Read about us on the Internet.
[Darkside] — 9 days ago — Message 18/243
5000 euro is impossible. you are not a small company, we've been
working on your network, we have encryped 200tb of data, you can not be a
small company, you have a whole data center.
[Victim] — 9 days ago — Message 19/243
please give us a sustainable amount we are 80 people that works from [redacted location]
[Victim] — 9 days ago — Message 20/243
[redacted location]
[Victim] — 9 days ago — Message 21/243
we work for non profit organization like [redacted]
[Darkside] — 9 days ago — Message 22/243
before the attack we checked info about your company, so it's
absolutely useless to prove us anything. discount is possible, but not
in the amount you want. you can try to take a loan and find any
cryptobrocker who will resolve all the cryptocurrency exchange.
[Victim] — 9 days ago — Message 23/243
10.000€
[Darkside] — 9 days ago — Message 24/243
You are wasting our time. Write when you have serious offers.
[Darkside] — 9 days ago — Message 25/243
discount x100 from first amount is impossible.
we can reduce the price by 50 000. so you have to pay 950 000 $
[Victim] — 9 days ago — Message 26/243
we do not have that amount. Is out of our business
[Darkside] — 9 days ago — Message 27/243
take a loan
[Victim] — 9 days ago — Message 28/243
I can make you an offer compatible with my availability and
comparable to the time it would take if I had to restore from backups
[Darkside] — 9 days ago — Message 29/243
we know everything about your backups, if you could restore, you
wouldn't text us at all. so please stop wasting our time and yours, you
know, that the only way to restore your business is to make the payment
requested
[Darkside] — 9 days ago — Message 30/243
are we talking with recovery company right now? cause few hours ago this conversation had a bit another vector.
[Victim] — 9 days ago — Message 31/243
no I move from home to office
[Darkside] — 9 days ago — Message 32/243
go back home, you were much more pliable from there.
[Victim] — 9 days ago — Message 33/243
I'm talking to the CEO to unadestand how much can we pay
[Darkside] — 9 days ago — Message 34/243
ok we are waiting
[Victim] — 8 days ago — Message 35/243
I talked with my CEO we want to solve the issue. We can offer
75.000€ to start the decryption process and 75.000 at the end of the
decryption. (in total 150.000€)
[Darkside] — 8 days ago — Message 36/243
This amount is not enough. Raise the price and we will give you an additional discount.
We can refuse payment and not give you a decryptor. Can you afford it? What will you tell your clients?
We understand you and are ready to give you a decryptor right now. Give us a good offer.
[Darkside] — 8 days ago — Message 37/243
Any phased payment options are not possible. You pay first, then we
give you decryptors. If you are not sure, you can give us test files and
we will decrypt them for you.
[Darkside] — 8 days ago — Message 38/243
In Linux, we specially encrypt log files, they are small in size and you can upload them to chat.
[Victim] — 8 days ago — Message 39/243
In you site you declare that you do not attack no.profit
organization. We host the site of a lot of no profit organization that
currently has the service down. Please accept our offer 150.000 all in
one
[Darkside] — 8 days ago — Message 40/243
Look, if you were a non-profit organization, you wouldn't be
attacked by anyone. Everyone can say that they are helping someone.
In the current case, your offer does not meet our expectations. It will
get you nowhere and you are wasting your time. Give us a better price
and we will give you a discount.
[Darkside] — 8 days ago — Message 41/243
I want you to understand one thing, it doesn't matter to me how long
it takes to discuss the price. This is important for you. The faster
you get decryptors, the faster you will continue to make money.
[Victim] — 8 days ago — Message 42/243
I sent you a small files
[redacted].txt.[redacted]
8.95 kB
[Darkside] — 8 days ago — Message 43/243
File
[redacted].txt
8.81 kB
[Victim] — 8 days ago — Message 44/243
Hi, we had a crisis committee meeting. We evaluated your proposal. I
know that you don't want waste time but trust me we are not so big as
you think. We need time to get a reasonable amount of MONERO or
BITCOIN. We try deliver an extra special effort and we can raise to
250.000€. We hope that this offers meet your expectation
[Victim] — 8 days ago — Message 45/243
i'm moving to home becouse of lock down and we had to go home at 10pm
[Darkside] — 8 days ago — Message 46/243
We are ready to accept 700k dollars. We will give you a discount of $ 300k.
[Victim] — 8 days ago — Message 47/243
We want to pay but we do not have 700k. We did the best effort to offer you 250.000
[Victim] — 8 days ago — Message 48/243
here is midnigth, i need to sleep and I hope to found some good news.
[Darkside] — 8 days ago — Message 49/243
Let's get back to this question in the morning! you need to rest, you are right! Goodnight!
[Victim] — 8 days ago — Message 50/243
good moring......I hope
[Darkside] — 8 days ago — Message 51/243
We've made you a 30% discount. Give us a better price and we will try to give you an additional discount.
[Victim] — 8 days ago — Message 52/243
Trust me. We host site for no-profit organization that do not have a
lot of money. You found a lot of data but this are our kind of
customer. We made the best 250.000€ is a very high amount for us. We
had also a problem to find this amount in a few days. The site that you
suggested offer MONERO at block of 5000 or 10.000€
[Victim] — 8 days ago — Message 53/243
We are 60 employee and only 6 on IT....we are working on this problem 24 hours....we need your help
[Darkside] — 8 days ago — Message 54/243
I spoke to my boss and explained your situation to him. He approved a payment of 350k dollars.
There will be no more discounts. Now you are offering 300k dollars, raise your price by 50k and we will close this deal now.
[Victim] — 8 days ago — Message 55/243
do you have a quick way to get that amount of MONERO?
[Victim] — 8 days ago — Message 56/243
we accept your proposal
[Darkside] — 8 days ago — Message 57/243
Price updated. Reload the page.
[Victim] — 8 days ago — Message 58/243
ok. Give us a reference to get that amount of monero
[Darkside] — 8 days ago — Message 59/243
Yes, have you considered buying through the exchange? Or are you having trouble with it?
[Darkside] — 8 days ago — Message 60/243
If you find it difficult to get Monero - buy Bitcoin first. Then change it to Monero.
[Victim] — 8 days ago — Message 61/243
We want to buy through the exchange. But they exchange at block of 10.000€.
[Darkside] — 8 days ago — Message 62/243
I think it is not difficult to buy bitcoin in your country. Use exchangers or crypto exchanges (binance, et al.).
[Victim] — 8 days ago — Message 63/243
ok. I will update you
[Victim] — 8 days ago — Message 64/243
we have to do change € on our wallet or directly charge on your wallet
[Darkside] — 8 days ago — Message 65/243
Change money on your wallet and then send us cryptocurrency
[Victim] — 7 days ago — Message 66/243
Hi, just to tell you that we are working to get cryptocurrency
[Darkside] — 7 days ago — Message 67/243
OK, we wait.
[Victim] — 7 days ago — Message 68/243
Good moring. Very difficult to move on BTC that amount on one wallet. You need transaction from one wallet alone?
[Victim] — 7 days ago — Message 69/243
can we make in more transcation?
[Victim] — 7 days ago — Message 70/243
could you Decrypt some server?
[Darkside] — 7 days ago — Message 71/243
We are waiting for xmr from you, not btc. If you decided to pay with btc, you have to pay additional 20%.
[Darkside] — 7 days ago — Message 72/243
And you can use several transaction
[Darkside] — 7 days ago — Message 73/243
After payment you will receive decryptor for all your network.
[Victim] — 7 days ago — Message 74/243
several transaction from same wallet or we could use different wallet?
[Darkside] — 7 days ago — Message 75/243
You can use different wallet
[Victim] — 6 days ago — Message 76/243
How many BTC we had to pay? Yesterday i saw 25.18, now I see 23.3
[Darkside] — 6 days ago — Message 77/243
Pay the amount that you see now
[Darkside] — 6 days ago — Message 78/243
Btc rate is not stable, so don't wait and pay quickly
[Victim] — 6 days ago — Message 79/243
do not change anymore because we had a lot o difficult to get crypto BTC
[Darkside] — 6 days ago — Message 80/243
i can fixed the rate, but you have to pay for 6 hours
[Darkside] — 6 days ago — Message 81/243
will pay for this time?
[Victim] — 6 days ago — Message 82/243
we'll try in 12 hours , but i'm not sure, maybe 24.
[Darkside] — 6 days ago — Message 83/243
i have fixed your btc amount, for the next 24 hours it doesn't depend from btc rate
[Darkside] — 6 days ago — Message 84/243
but you must pay as soon as possible
[Victim] — 6 days ago — Message 85/243
ok
[Victim] — 6 days ago — Message 86/243
help us as soon as possible. We are very little to pay that amount
but we do....and also we had to work a lot of other days....give an hand
as soon as you can....trust us
[Darkside] — 6 days ago — Message 87/243
After payment I will immediately give you decryptors.
[Victim] — 6 days ago — Message 88/243
Hi. Why the rate changed again?
[Victim] — 6 days ago — Message 89/243
you promise me to block the rate of BTC to 23.3
[Victim] — 6 days ago — Message 90/243
we already had a trade for that amount and we need to fix it
[Victim] — 6 days ago — Message 91/243
Are you there?
[Darkside] — 6 days ago — Message 92/243
Hello
[Darkside] — 6 days ago — Message 93/243
Rate was changed yesterday, before i fixed it
[Darkside] — 6 days ago — Message 94/243
You actual amount for the next 12 hours 23.61 BTC
[Victim] — 6 days ago — Message 95/243
we bought yesterday 23.3 by an exchanger and we are waiting for the transaction. We cannot change the amount now
[Victim] — 6 days ago — Message 96/243
the payment is in process
[Darkside] — 6 days ago — Message 97/243
okay, waiting for 23.3 BTC from you in next several hours
[Victim] — 6 days ago — Message 98/243
ok. May I ask a partial decrypion of one server?
[Darkside] — 6 days ago — Message 99/243
After payment you'll immediately receive decryptor for all network
[Darkside] — 5 days ago — Message 100/243
You have the last 3 hours to pay the fixed btc amount after that time the rate will be float again.
[Victim] — 5 days ago — Message 101/243
be patient
[Victim] — 5 days ago — Message 102/243
the transaction is in progress with our exchanger
[Victim] — 5 days ago — Message 103/243
technical time
[Darkside] — 5 days ago — Message 104/243
Our btc wallet is always actual and the same, so send as quickly as it possible.
[Victim] — 5 days ago — Message 105/243
what do you mean?
[Darkside] — 5 days ago — Message 106/243
The wallet that you see on your page is always relevant
[Victim] — 5 days ago — Message 107/243
i'm here
[Victim] — 5 days ago — Message 108/243
operation is in progress
[Darkside] — 5 days ago — Message 109/243
ok
[Victim] — 5 days ago — Message 110/243
be patient operation with exchanger is taking too long time
[Victim] — 5 days ago — Message 111/243
please
[Darkside] — 5 days ago — Message 112/243
How many time you need?
[Victim] — 5 days ago — Message 113/243
The exchanger told me that operation should be in the morning. Now here are 20:47
[Darkside] — 5 days ago — Message 114/243
Take in mind, that after 35 hours your price will be doubled and this action cannot be undone.
[Victim] — 5 days ago — Message 115/243
we know. My mind now is about 23.3 BTC becouse operation is for that amount
[Darkside] — 5 days ago — Message 116/243
If you don't pay tomorrow, i'll enable float rate again and don't fixed it anymore.
[Darkside] — 5 days ago — Message 117/243
So, hurry up your exchanger.
[Darkside] — 5 days ago — Message 118/243
Good morning! Any updates?
[Victim] — 5 days ago — Message 119/243
I had a meeting scheduled with exchanger at 1PM
[Victim] — 5 days ago — Message 120/243
i don't know why he 's taking time. We yesterday moved € to exchanger
[Darkside] — 5 days ago — Message 121/243
Well, if anything, do not hesitate to write about the results
[Victim] — 5 days ago — Message 122/243
we need cryptocurrency to close the deal with you and my family will be happy becouse I have to work all weekend
[Darkside] — 5 days ago — Message 123/243
I understand you, as far as I know in Europe there are bitcoin ATMs for a long time
[Victim] — 5 days ago — Message 124/243
never seen
[Darkside] — 5 days ago — Message 125/243
[REDACTED URL]
[Darkside] — 4 days ago — Message 126/243
We won't give you extra time, after 16 hours you price will be doubled, make payment faster.
[Victim] — 4 days ago — Message 127/243
Hi, i'm in call with exchanger
[Victim] — 4 days ago — Message 128/243
we had to wait for the transfer of the amount
[Victim] — 4 days ago — Message 129/243
technica time between bank
[Victim] — 4 days ago — Message 130/243
I have the document that prove that we are moving money
[Victim] — 4 days ago — Message 131/243
but we need more time
[Victim] — 4 days ago — Message 132/243
till monday
[Victim] — 4 days ago — Message 133/243
in the week end bank do not operate
[Darkside] — 4 days ago — Message 134/243
Send the documents.
[Victim] — 4 days ago — Message 135/243
upload in progress
IMG_20201120_152201.jpg
5.4 MB
[Victim] — 4 days ago — Message 136/243
3 pages
IMG_20201120_152152.jpg
4.8 MB
[Victim] — 4 days ago — Message 137/243
last page
IMG_20201120_152145__02__01.jpg
5.06 MB
[Darkside] — 4 days ago — Message 138/243
Ok, added time.
[Victim] — 4 days ago — Message 139/243
da you update the countdown on this page
[Victim] — 4 days ago — Message 140/243
?
[Victim] — 4 days ago — Message 141/243
Time ends on 23 Nov 2020, 09:51
[Victim] — 4 days ago — Message 142/243
in the morning is too eearly
[Victim] — 4 days ago — Message 143/243
the bank open in the morning
[Victim] — 4 days ago — Message 144/243
please set the deadline to 24 November 9 AM
[Victim] — 4 days ago — Message 145/243
so we are sure than on monday close the transaction
[Darkside] — 4 days ago — Message 146/243
Refresh the page
[Victim] — 4 days ago — Message 147/243
Ok thanks
[Victim] — 2 days ago — Message 148/243
Hi, we are at work.
[Darkside] — 2 days ago — Message 149/243
Hello! We, too, how is the exchange process going?
[Victim] — 2 days ago — Message 150/243
only the bank does not work on the week end
[Victim] — 2 days ago — Message 151/243
the decryption tool work per single file?
[Darkside] — 2 days ago — Message 152/243
You will receive a master (universal) decryptor for your Linux and Windows network after payment
[Victim] — 2 days ago — Message 153/243
it runs recursively o per file?
[Darkside] — 2 days ago — Message 154/243
the process works as when encrypting only in the opposite direction, we
will also send all instructions, and provide support until you decrypt
the all network
[Victim] — 2 days ago — Message 155/243
see you tomorrow
[Darkside] — 2 days ago — Message 156/243
Ok! Have a nice day!
[Darkside] — 1 day ago — Message 157/243
After 17 hours your price will be doubled and we won't change it.
[Victim] — 1 day ago — Message 158/243
i'm here
[Victim] — 1 day ago — Message 159/243
good morning
[Victim] — 1 day ago — Message 160/243
we are almost ready
[Victim] — 1 day ago — Message 161/243
i'm worried about decryption process
[Victim] — 1 day ago — Message 162/243
there are a lot of file on a lot of volume
[Darkside] — 1 day ago — Message 163/243
Hello! the process of decryption is similar to the encryption process,
you do not need to worry, maximum 4-5 hours and your files will be
decrypted
[Victim] — 1 day ago — Message 164/243
on vmware do i need to execute decryption on one host esx that is
connected to all volume or do I have to execute on every single host?
[Darkside] — 1 day ago — Message 165/243
You should upload decryptor to each esxi, set 777 permissions and
run. That's all you need, after small time your esxis will be ready for
work.
[Victim] — 1 day ago — Message 166/243
can we test the decryption process on one single vmdk file?
[Darkside] — 1 day ago — Message 167/243
We will send decryptor after payment and help with all. Don't worry, it's too easy.
[Victim] — 1 day ago — Message 168/243
we are doing the first transaction
[Victim] — 1 day ago — Message 169/243
what description in the transaction?
[Victim] — 1 day ago — Message 170/243
we sent the first little amount in order to test the correct transaction
[Victim] — 1 day ago — Message 171/243
it is ok?
[Darkside] — 1 day ago — Message 172/243
we can see your transaction
[Darkside] — 1 day ago — Message 173/243
you can send all amount
[Victim] — 1 day ago — Message 174/243
ok
[Victim] — 1 day ago — Message 175/243
we proceed
[Darkside] — 1 day ago — Message 176/243
and after 3 confirmation of bitcoin network we will send you decryptors and instruction
[Victim] — 1 day ago — Message 177/243
with the next trance
[Victim] — 1 day ago — Message 178/243
we sent half amount
[Victim] — 1 day ago — Message 179/243
please give us linux or windows decryptor now
[Darkside] — 1 day ago — Message 180/243
we will send your decryptors only after you send us full amount.
[Darkside] — 1 day ago — Message 181/243
we are waiting for next part
[Victim] — 1 day ago — Message 182/243
one moment
[Victim] — 1 day ago — Message 183/243
sent
[Darkside] — 1 day ago — Message 184/243
ok, we can see your transaction
[Darkside] — 1 day ago — Message 185/243
waiting for 3 confirmation and then send you decryptors
[Victim] — 1 day ago — Message 186/243
we are waiting for decryptor
[Darkside] — 1 day ago — Message 187/243
Windows:
The decryptor works in 2 modes:
1. GUI
2. Console
Three functions are available in GUI mode:
1. "DECRYPT ALL" - search and decrypt ALL encrypted files on the local
PC and on network resources (Shares), where this PC has access.
2. "DECRYPT FOLDER" - decrypts files in the specified folder, which you
can select in the "Browse for folders" window or drag and drop the
folder into the decryptor window.
3. "DECRYPT ONE FILE" - decrypts a single file, which you can open in
the "Open" window or drag and drop the encrypted file into the decryptor
window.
IMPORTANT!
Extension of encrypted files may not coincide with the extension of files, which the decryptor suggests to open!
To open encrypted files with other extensions, in the "Open" window
select, in the lower right corner of "All Files (*. *)" or just drag and
drop the given file into the decryptor window.
File extension does not affect the decryption of file!
Console mode has two parameters:
1. "-all" - search and decrypt ALL encrypted files on the local PC and on network resources (Shares), where this PC has access.
You can also use Group Policy to quickly decrypt your entire network.
2. "-path" - decrypts files in the specified folder or a single file.
3. Dragging and dropping an encrypted file or folder with encrypted files onto the decryptor file.
In this mode, the console window will open automatically, which will display the decryption process.
Command line examples:
> decryptor.exe -all
> decryptor.exe -path C:\Folder
> decryptor.exe -path C:\Folder\file.txt.[redacted]
win_decryptor.exe
76.5 kB
[Victim] — 1 day ago — Message 188/243
linux decryptor works alsa per files?
[Victim] — 1 day ago — Message 189/243
also
[Darkside] — 1 day ago — Message 190/243
linux decryptor decrypts all system, it cant decrypt certain files
[Victim] — 1 day ago — Message 191/243
may I ran on host that see all encrypted volume?
[Darkside] — 1 day ago — Message 192/243
just run the decryptor on each esxi, that's all, you don't need to do anything anymore
[Darkside] — 1 day ago — Message 193/243
after decryption you can use your vms as before that
[Victim] — 1 day ago — Message 194/243
we are at work
[Darkside] — 1 day ago — Message 195/243
Linux decryption instruction:
1. Upload decryptor to esxi.
2. Set run permissions: chmod 777 decryptor
3. Run decryptor: ./decryptor
jump_decryptor.out
2.38 MB
[Darkside] — 1 day ago — Message 196/243
Use this one decryptor for you esxi
[Victim] — 1 day ago — Message 197/243
what is the difference?
[Victim] — 1 day ago — Message 198/243
the decryptor did not decrypt some file
[Victim] — 1 day ago — Message 199/243
on esx
[Darkside] — 1 day ago — Message 200/243
Try the last decryptor.
[Darkside] — 1 day ago — Message 201/243
Which file was not decrypted? Give more information.
[Victim] — 1 day ago — Message 202/243
/vmfs/volumes/[redacted]/[redacted]_RM_03/[redacted]_RM_03_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/WD_[redacted]/WD_[redacted]-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V185E016/V185E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V157E016/V157E016_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V066E016 - [redacted]/V066E016 - [redacted]_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V079E016 - [redacted]/V079E016 - [redacted]-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V195E016/V195E016_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000REPP/V000REPP_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000PAS2/V000PAS2_1-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V060E016/V060E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000TS1P_2012/V000TS1P_2012-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V144E016/V144E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V189E016/V189E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V067E016/V067E016-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000AMQP/V000AMQP-flat.vmdk.darkside
/vmfs/volumes/[redacted]/V000AMMP/V000AMMP_3-flat.vmdk.darkside
/vmfs/volumes/[redacted]/[redacted] - ArcGis DataStore/[redacted] - ArcGis DataStore-flat.vmdk.darkside
[Darkside] — 1 day ago — Message 203/243
have other files been decrypted? Are virtual machines working?
[Darkside] — 1 day ago — Message 204/243
Use the last decryptor. He will decrypt them.
[Victim] — 1 day ago — Message 205/243
i will try the other decryptor becouse when i try to start [redacted] seems that a disk is missing
[Darkside] — 1 day ago — Message 206/243
Try the last one and write to me.
[Victim] — 1 day ago — Message 207/243
[START #11] File
Path.........../vmfs/volumes/[redacted]/[redacted]_RM_03/[redacted]_RM_03_1-flat.vmdk.darkside
[INFO] File Size................0mb (4096 Bytes)
[ERROR] File Too Small, Ignored
[Darkside] — 1 day ago — Message 208/243
What is the size of this file? Problem with one file or multiple?
[Victim] — 1 day ago — Message 209/243
42
[Victim] — 1 day ago — Message 210/243
seems that some filese were modified and disk size of the VM was set to 0
[Victim] — 1 day ago — Message 211/243
so the VM does not start
[Darkside] — 1 day ago — Message 212/243
what 42?
[Victim] — 1 day ago — Message 213/243
42 useful file was not decrypted
[Darkside] — 1 day ago — Message 214/243
and how much was decrypted?
[Victim] — 1 day ago — Message 215/243
a lot
[Darkside] — 1 day ago — Message 216/243
If the reason for the non-decryption is that there is 0 size, then I
cannot help you. The decryptor cannot decrypt what is not.
Check all file sizes and tell me them. When you tried to start virtual
machines, the hypervisor could damage the encrypted files.
I mean before you got the decryptor.
[Darkside] — 1 day ago — Message 217/243
Are you having a problem with virtual machines on the same hypervisor? or at all?
[Victim] — 1 day ago — Message 218/243
we are having some problem
[Darkside] — 1 day ago — Message 219/243
answer the questions so that I could understand what to tell you.
[Victim] — 1 day ago — Message 220/243
the probelm is on esx
[Victim] — 1 day ago — Message 221/243
Task name
Power On virtual machine
Target
WD_[redacted]
Status
File /vmfs/volumes/[redacted]/WD_[redacted]/WD_[redacted].vmdk was not found
[Darkside] — 1 day ago — Message 222/243
Look through ssh. Do you have a file?
[Victim] — 1 day ago — Message 223/243
have a file of 4K with .darkside extension
[Victim] — 1 day ago — Message 224/243
we lost some vm
[Victim] — 1 day ago — Message 225/243
sigh!
[Darkside] — 1 day ago — Message 226/243
The decryptor checks all checksums, it could not damage virtual
machines. This is the first time that a client talks about problems.
Did you check the sized before decryption?
[Darkside] — 1 day ago — Message 227/243
How many virtual machines have you failed to recover? Were they on the same esxi?
[Darkside] — 1 day ago — Message 228/243
You showed me a log in which the decryptor is trying to decrypt empty files. So the problem arose before decryption.
Why so, I can not answer you, there can be a lot of reasons.
[Darkside] — 1 day ago — Message 229/243
If you have any other problems with decryption - I will help you, just give me not empty files.
[Victim] — 1 day ago — Message 230/243
the empty file has data of creation on 15Nov in the night
[Victim] — 1 day ago — Message 231/243
i don't know why
[Victim] — 1 day ago — Message 232/243
there is a format job runnin
[Victim] — 1 day ago — Message 233/243
I need your little but useful help. On veem the volume where we have
the backup , this morning was accessible but now the volume is RAW.
[Darkside] — 23 hours ago — Message 234/243
I don't quite understand what you mean
[Victim] — 22 hours ago — Message 235/243
the tool that you used to encrypt our backup. At the end of encrypion does it do disprutive action?
[Darkside] — 22 hours ago — Message 236/243
No, it doesn't. If backups are on Windows - use the Windows decryptor.
[Darkside] — 22 hours ago — Message 237/243
Never interrupt the decryption process by closing the program
manually. The program may freeze during decryption, this is normal.
[Victim] — 19 hours ago — Message 238/243
Hi.
[Victim] — 19 hours ago — Message 239/243
we trusted in you
[Victim] — 19 hours ago — Message 240/243
but we need some files that miss
[Darkside] — 17 hours ago — Message 241/243
We gave you decryptors and they work, if you have problems with them, I will help you.
[Darkside] — 17 hours ago — Message 242/243
Before buying decryptors, you saw that some files were empty and you could not pay.
[Darkside] — 17 hours ago — Message 243/243
We fulfilled our part of the deal, I don't know why you have empty files. You didn't even tell me how many there are.