Ransomware negotiation(s) with  trinity



Avatar

hello

Avatar

hello

hello

Avatar
Avatar

what do we have to do to acces our files ?

Please say your network domain

Avatar
Avatar

i sent you email to

Yes I see

Avatar
Avatar

what info do you need ?

[redacted] ?

Avatar
Avatar

idd

your network?

Avatar
Avatar

[redacted] is correct

Price for decrypt 70000$ in bitcoin amount

Avatar
Avatar

ok, i'm talking with management

Avatar

is there any garantee tht we can decrypt all files ?

Avatar

i see the VHDX files are only 3GB and the were much bigger ..

We have been working for several years and all our clients have received their key. You can send us up to 10 files for the test decrypt, but these files should not contain important information

Avatar
Avatar

ok, and my VHD files will decrypt as wel ? they were +1TB in size and now only 3GB

Yes

Avatar

Inside the hard disk these files have normal size

Avatar
Avatar

In order to proceed, my manager requires a due dilligence step that protects us from liability, and that is to obtain proof that you have our sensitive files before we can consider payment. For that reason, can you provide the cleartext copy of the "[redacted]_V10_13_8_GP.ZIP" file located in the "C:\Users\Administrator\Downloads" folder on one of the encrypted servers.

we don't loan out valuable files for testing for the test send 1-2 files (1-5 mb) not backup and database

Avatar

If you don't pay, we'll put your data on the leak sites. https://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion/ companies/2148689972 ,and similar sites

Avatar
Avatar

In order to negotiate a resolution, we would require proof of data posession, so we have asked you for a file that does not contain sensitive information (you can verify that in the file itself). We have so far not received any evidence of you posessing cleartext copies of our data. Such evidence allows me to talk to my manager, who will eventually decide on the best course of action, as we have multiple alternatives.

We can't provide this file to you.

Avatar
Avatar

Since we cannot show our manager any proof of stolen data, we cannot argue such a high ransom demand. We do have backups which are few weeks old, but I am convinced that our manager would pay a smaller fee for decryption key in order to have the latest data in a much faster way. They are willing to offer you $10.000 for the decryption key.

We have already told you the price. The only way you can reduce the final price is to pay today and then we can think about a discount.

Avatar

but 10000$ just a joke for us, you should understand it. We can make discount 10.000$ if you pay today

Avatar
Avatar

I will have to take that offer to my manager. In the meantime, how can you provide proof of having a working decryption key? Can we provide you with an encrypted file and you decrypt it?

Avatar

I will have to take that offer to my manager. In the meantime, how can you provide proof of having a working decryption key? Can we provide you with an encrypted file and you decrypt it?

Yes, send file here https://dropmefiles.com/

Avatar

Yes, send file here https://dropmefiles.com/

Avatar
Avatar

Hereby https://dropmefiles.com/[redacted]

https://dropmefiles.com/[redacted]

Avatar

pass 123

Avatar

You don't use our discount offer. So the price is 70.000$ again. Tomorrow it will rise again.

Avatar

This information is provided by Valéry Marchive & Julien Mousqueton