I've not found anything online regarding the Note or file extension, there is however a similar flaw in their grammar in the note which makes me believe that it is a Xorist variant.
The Xorist decrypter from Emsisoft(https://decrypter.emsisoft.com/xorist) actually allows me to succesfully decrypt the files but it breaks the file names completely for example renames dir/subdir/file.name.ext.REVOLUTION to dirsubdir etc.
I want to be able to decrypt the file back to it's original name if possible.
I've uploaded to indentify but no luck here: https://id-ransomware.malwarehunterteam.com/identify.php
I've attached The note, an encrypted file and an unencrypted file here: https://ufile.io/ok74d
I tried with the key I found online from Emsisoft, think maybe the key has just changed slightly.
The brute force does not successfully force the key.
Is there anyone that might have seen this variant, or at least maybe I can ask someone to have a look at it and identify for the rest of its potential victims.
Ideally I would really like if someome could assist me with the decryptor to fix the file rename issues so that I can save my server.
The note(is saved as InfoFiles.txt):
All your important files were encrypted on this PC.
All files with .revolution extension are encrypted.
Encryption was produced using unique private key RSA-1024 generated for this computer.
To decrypt your files, you need to obtain private key + decrypt software.
The single copy of the private key, with will allow you to decrypt the files, is locate on a secret server on the internet.
To retrieve the private key, you need to contact us by email firstname.lastname@example.org send us an email your InfoFiles.txt file and wait for further instructions.
For you to be sure, that we can decrypt your files - you can send us a 1-2 not very big encrypted files and we will send you back it in a decrypted form free.
To send files you can use http://dropmefiles.com/
Do not waste your time! After 72 hours the main server will double your price!
Your personal id:
E-mail address to contact us:
Reserve email address to contact us:
Edited by quietman7, 08 September 2017 - 05:47 AM.