good news?Ability to decrypt？thanks!
Jump to content
Posted 15 January 2018 - 08:24 PM
Posted 16 January 2018 - 10:34 AM
We have been hit by a ransomware attack, according to https://id-ransomware.malwarehunterteam.com/ it probably is GlobeImposter 2.0.
All encrypted files have a .encen extension, for which I didn't find any information on the web. Only id-ransomware says it's a known GlobeImposter 2.0 extension.
The mail adress used is 'firstname.lastname@example.org'.
I'd be very grateful, if someone could help me verify that it's indeed GlobeImposter 2.0.
I already tried all recovery options (restore points, shadow copy, file recovery) to no avail.
Is there anything I can do?
I didn't yet attempt to remove the virus and I'd like to upload it for further investigation. Any hints on how I find the correct executable to upload? It was not detected by my virus scanner (Sophos), is there another tool I should use to find it?
I also have an encrypted/unencrypted file pair, if that's of any help. From what I understand, there is basically no way to brute force this, even with file pair?
Please let me know if I should provide more information here on the forum or if there is anything I can do to help further the research about this particular ransomware!
PS.: Out of curiosity I already wrote a mail to the extortionists, they say it'll cost .3 BTC to recover the files. Has anyone paid the ransom? Did it work out? Because if there is no solution in the near future we may be forced to pay, even though I'd hate rewarding those people. Has anyone tried to haggle them down in price?
Posted 16 January 2018 - 11:12 AM
Posted 16 January 2018 - 11:40 AM
If you can not log in to the accounts, you need to change the permissions on the directories of these users and inherit the files that are in these accounts.
A big request to Global Moderator - to transference the posts related to the case of abakothanasis in the fit topic.
Have you been attacked by a Ransomware? Report here. Пострадали от шифровальщика? Сообщите мне здесь.
Posted 16 January 2018 - 02:45 PM
...A big request to Global Moderator - to transference the posts related to the case of abakothanasis in the fit topic.
0 members, 0 guests, 0 anonymous users