Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

TeslaDecoder released to decrypt .EXX, .EZZ, .ECC files encrypted by TeslaCrypt


  • Please log in to reply
2120 replies to this topic

#2116 Albinario

Albinario

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 12 April 2017 - 05:18 AM

Hi kind people,

 

The files I want to decrypt are .ccc. My sharedsecret1*privatekeybc is:

 

3303954367154644239977043935369681591835519065445502397497868212264791068239054186409622164114128701516501756576986380759227685115718182436276013660737674

 

I've had yafu working on it for 24+ hours, but no result yet. Is the number too large, or should I keep going? It's at a stage where it keeps "commencing algebraic side lettuce". 

 

Thanks in advance,

 

/Albin



BC AdBot (Login to Remove)

 


#2117 al1963

al1963

  • Members
  • 745 posts
  • OFFLINE
  •  
  • Local time:11:30 AM

Posted 12 April 2017 - 05:24 AM

@Albinario

 

Add one encrypted file to http://sendspace.com, and give us a link to it in your message.



#2118 Albinario

Albinario

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 12 April 2017 - 05:47 AM

Here is a link:

 

https://www.sendspace.com/file/ary48v



#2119 Demonslay335

Demonslay335

    Ransomware Hunter


  • Security Colleague
  • 2,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:30 AM

Posted 12 April 2017 - 09:10 AM

@Albinario

 

The PrivateKeyBC looks to be a C138, that would take a few days on an average i7. The PrivateKeyFile is just a C105 and would take a few hours at most.

 

I am factoring the PrivateKeyFile now.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#2120 Demonslay335

Demonslay335

    Ransomware Hunter


  • Security Colleague
  • 2,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:30 AM

Posted 12 April 2017 - 02:55 PM

@Albinario

 

Sorry, forgot I had this running. Here's your PrivateKeyFile.

 

A6A480E4EC8A485A2A6934C503B9989F255D87CBF63A2AA9706A1F65BE40A83C

 

If it skips files, we will need one of the files it skips, and we can calculate the next key. The C138 may take much longer than just factoring a handful of smaller PrivateKeyFiles.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#2121 Albinario

Albinario

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:30 AM

Posted 12 April 2017 - 04:19 PM

Just awesome!

 

All my holiday pictures rescued :).

 

Glad I kept the files and gave this another go after almost 2 years. 

 

Thanks a lot, you rock!






4 user(s) are reading this topic

0 members, 4 guests, 0 anonymous users