ACSec/Observatorio
← Notas de rescate

Notas de rescate — medusalocker

Contactos, enlaces de pago y direcciones del atacante redactados ([redactado]).

HOW_TO_RECOVER_DATA.html

<html>
    <style type="text/css">
      body {
      background-color: #f5f5f5;
      }
h1, h3{
  text-align:  center;
  text-transform: uppercase;
  font-weight: normal;
}
/*---*/
.tabs1{
    display: block;
    margin: auto;
}
.tabs1 .head{
    text-align: center;
    float: top;
    padding: 0px;
    text-transform: uppercase;
    font-weight: normal;
    display: block;
    background: #81bef7;
    color: #DF0101;
    font-size: 30px;
}
.tabs1 .identi {
    font-size: 10px;
    text-align:  center;
    float: top;
    padding: 15px;
    display: block;
    background: #81bef7;
    color: #DFDFDF;
}
.tabs .content {
  background: #f5f5f5;
  /*text-align: center;*/
  color: #000000;
  padding: 25px 15px;
  font-size: 15px;
  font-weight: 400;
  line-height: 20px; }
 .tabs .content a {
    color: #df0130;
    font-size: 23px;
    font-style: italic;
    text-decoration: none;
    line-height: 35px; }
.tabs .content .text{
padding: 25px;
line-height: 1.2;
}
    </style>
  <body>
    <div class="tabs1">
     <div class="head" ><b>Your personal ID:</b></div>
      <div class="identi">
      <span style="width:1000px; color: #ffffff; font-size: 10px;">[snip]</span> <br>
<!-- !!! dont changing this !!! -->
      </div>
    </div>
  <!-- -->
    <div class="tabs">
<!--tab-->
    <div class="tab">
        <div id="tab-content1" class="content">
          <div class="text">
          <!--text data -->
          <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br>
          <b>All your important files have been encrypted!</b><br><br>
	  <hr>
             Your files are safe! Only modified. (RSA+AES)<br><br>
ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br>
WILL PERMANENTLY CORRUPT IT.<br>
DO NOT MODIFY ENCRYPTED FILES.<br>
DO NOT RENAME ENCRYPTED FILES.<br><br>
No software available on internet can help you. We are the only ones able to<br>
solve your problem.<br><br>
We gathered highly confidential/personal data. These data are currently stored on<br>
a private server. This server will be immediately destroyed after your payment.<br>
If you decide to not pay, we will release your data to public or re-seller.<br>
So you can expect your data to be publicly available in the near future..<br><br>
We only seek money and our goal is not to damage your reputation or prevent<br>
your business from running.<br><br>
You will can send us 2-3 non-important files and we will decrypt it for free<br>
to prove we are able to give your files back.<br><br>
          <!--text data -->
          <hr>
          <b>Contact us for price and get decryption software.</b><br><br>
<a>[redactado]
* Note that this server is available via Tor browser only<br><br>
Follow the instructions to open the link:<br>
              1. Type the addres "[redactado] in your Internet browser. It opens the Tor site.<br>
              2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br>
              3. Now you have Tor browser. In the Tor Browser open <a>[redactado]
          </a>
                        4. Start a chat and follow the further instructions. <br>
          <hr>
          <b>If you can not use the above link, use the email:</b><br>
          <a href="[redactado]  ">[redactado]   </a> <br>
          <a href="[redactado] ">[redactado]   </a> <br>
          <p>* To contact us, create a new free email account on the site:  <a href="[redactado] <br>
<b>
IF YOU DON'T CONTACT US WITHIN 72 HOURS, PRICE WILL BE HIGHER.</b><br>
          </div>
        </div>
    </div>
 <!--tab-->
          <!--text data -->
          </div>
        </div>
<!--tab-->
    </div>
  </div>
  </body>
</html>
Notas: medusalocker | ACSec Observatorio Ransomware