tsimis.gr
Speaking with LOCKBIT
Victim #36
You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat. If your archive weighs more than 10 megabytes, please use our file sharing service. http://lockbitfss2w7co3ij6am6wox4xcurtgwukunx3yubcoe5cbxiqakxqd.onion http://lockbitfsvf75glg226he5inkfgtuoakt4vgfhd7nfgghx5kwz5zo3ad.onion http://lockbitfskq2fxclyfrop5yizyxpzu65w7pphsgthawcyb4gd27x62id.onion For security reasons we do not click on other links you send in chat. Please wait for a reply, sometimes it takes several hours due to possible time zone differences.
Mon Dec 23 2024 10:56:21 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
hello sir, can you help me what you need to decrypt my files?
Mon Dec 23 2024 10:57:33 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
7 DAYS MINI ROLLS UNCOVERED CONDENCED MILK 20gr OPP2.pdf.usKv553SJ this is a sample file
Mon Dec 23 2024 10:58:55 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat. If your archive weighs more than 10 megabytes, please use our file sharing service. http://lockbitfss2w7co3ij6am6wox4xcurtgwukunx3yubcoe5cbxiqakxqd.onion http://lockbitfsvf75glg226he5inkfgtuoakt4vgfhd7nfgghx5kwz5zo3ad.onion http://lockbitfskq2fxclyfrop5yizyxpzu65w7pphsgthawcyb4gd27x62id.onion
Mon Dec 23 2024 11:31:23 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Mon Dec 23 2024 12:28:50 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
could you please how much it will cost to recover my files because we need to know the costs involved.
Mon Dec 23 2024 13:10:53 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
wait, tech support will send your test files
Mon Dec 23 2024 14:50:20 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
price decrypt 80k in bitcoin, for all hosts and files
Mon Dec 23 2024 14:51:56 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
sir this amount is very high to be paid. We would like to work with you because it will take much time to recover our infrastructure. So some questions from our side 1. Can you please provide a generous discount so it's easier for us to consider your solution? 2. How fast the recovery process will take if we work with you ?
Mon Dec 23 2024 15:47:11 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
we can't offer you a discount
Mon Dec 23 2024 16:08:06 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
if you pay quickly and restore the infostructure on the same day
Mon Dec 23 2024 16:12:12 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
I saw your financial report, our price is not big for you
Mon Dec 23 2024 16:14:28 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
Mon Dec 23 2024 16:16:24 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Thank you for the file. It's been a very hard year for our company, also as you know we are in Greece and since 2010 it's been very tough times for businesses. And the end of the year is always very hard financially with cashflows. That's why i am asking for your understanding in price, so I can make an easier decision for my manager to decide. Please if you can convince your own management to consider a generous discount it will help us in our decision with positive result. From our side we want our files faster and without loses than the options we have now. It seems that you can provide this service from the proof you sent. It would be nice if we can find an agreement on a price we can pay so we can pay you. Right now the amount you said is far beyond our real financial capability so we cannot consider this an option.
Mon Dec 23 2024 16:38:16 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
ok, we can do a 20% discount
Mon Dec 23 2024 16:46:36 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
First of all thank you for your understanding and the discount you provided. I appreciate your help on this. But still we are very far away from what we can really pay. Still the amount you mentioned after the discount is very hard to find in cash. We need to take some serious IT decisions tomorrow as most consultants advised us to format and start from latest offline files which will take several days. So please if you can give us a more grounded financial proposal do so since the purpose here is to see if we can use your services.
Mon Dec 23 2024 17:14:17 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
I don't care whether you pay me or not, there will be no more talk about discounts
Mon Dec 23 2024 17:19:57 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
If you don't make a decision, the price will be 2x tomorrow.
Mon Dec 23 2024 17:25:20 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Please don't misunderstand the interest to find a way to pay you with insult. This was not my point. I respect you are talking with us right now and understanding our side. I just want to make it work for our company based on our limitations in cashflow in the end of the year. I know that you don't care about us. You attacked us after all. I understand that it's just business for you. Some pay, some don't. We want us to both benefit from this incident. We gain knowledge and you gain money. But we wanted to get an amount that we can be able to pay you realistically. We are not here to play either. Unfortunately if your purpose is to raise the price there is no point of discussing any more. Even if we find the correct amount we can pay, we will need at least 7 working days to pay you. Regulations are hard with this kind of transactions.
Mon Dec 23 2024 17:29:26 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
the price will be 60k your decision to pay or not.
Mon Dec 23 2024 17:35:39 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Is there a way to recover 2-3 computers with 15k and get a partial service from your side? So we can see the quality of your service that is valid and then during next year purchase some more bundle of computers? I am just exploring options here to help our operations based on our cashflows.
Mon Dec 23 2024 17:56:21 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
no, the decryptor will be available for all your files with the extension
Mon Dec 23 2024 17:58:44 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Hello sir, could you please accept the price of 30000$ before the end of the year so we can catch up with the processes to pay you in full for the full service you provide? It will take a lot of effort for us to return to normality so we can see this as a successful penetration test from your team and justify the expenses we need to pay to your work. Mention we need some days to manage to pay this huge amount of money so we need your understanding on this.
Tue Dec 24 2024 16:32:59 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
you can pay 50k, but the offer will be available for a some days if you can't pay on the weekend, I'll refund price.
Tue Dec 24 2024 18:04:24 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Please stay with me on this. Even if we find a way to work together, the amount is too big to find it these days. Last two years it's been very hard for us and it's the end of the year. We are trying to find whatever resources are available in cash and let you know. In the following two days we will have a better picture on our financials. We need at least 6-7 days to find 30k, we will need more to get more money to you. There is very limited cashflow in the end of the year which makes things very hard. Let me see what we can do and get back to you. I will try my best, because we want this to finish soon. There is big spending in the end of the year and limited cash receivable. Need more time to see what we can do for you.
Tue Dec 24 2024 21:03:25 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
hello sir, can you please let us know how we can do the payment?
Fri Dec 27 2024 10:16:45 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
hello, btc wallet: 1PKzZhK35fvszaHBdyAwHTRtEoJwjR1ocD
Fri Dec 27 2024 12:54:26 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
We managed to gather this amount you requested. It's been very hard. Please let us know if you accept the following. When we pay 50.000$ USD to this wallet 1PKzZhK35fvszaHBdyAwHTRtEoJwjR1ocD you will keep your promise to: 1. Give us a tool to decrypt all our files in ESXi and all computers affected and we will decrypt today 2. Provide technical support from your side in case something doesn't work 3. Promise you will never attack us in the future 4. Help us understand how we can prevent such incidents again in the future and explain how you managed to get in our infrastructure along with technical details. When we have your replies and confirmation for the above we proceed in the payment.
Fri Dec 27 2024 13:08:42 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
1. there will be no problems with the decryptor,for esxi and all windows files 2. you will need to disable your av and just run the .exe decryptor 3. it could be someone else 4. you know your pass P@ssw0rd
Fri Dec 27 2024 13:18:22 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
if we pay in the next hour when we will get decryptor?
Fri Dec 27 2024 13:20:28 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
i make a request to tech support, it can take from an hour to five hours
Fri Dec 27 2024 13:24:37 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
shall we sent 10$ just you to confirm and then send the rest 49990 ?
Fri Dec 27 2024 13:26:16 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
ok
Fri Dec 27 2024 13:27:13 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
https://mempool.space/tx/afa41038f76e6616814e5c4d4bc7a4907d15d41dac5bf782af42dc2fbbc5c11f can you confirm you received this ?
Fri Dec 27 2024 13:31:24 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
yes 0.00010389
Fri Dec 27 2024 13:34:48 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
bitcoin seller sais you got the money. Please confirm https://mempool.space/tx/c3137291d4c673e21f282e346338568f26f7b7c3558c82392bca6d31c66166b2
Fri Dec 27 2024 14:12:01 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
is ok, thank you
Fri Dec 27 2024 14:19:47 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
wait pls, tech support will drop decryptor here
Fri Dec 27 2024 14:24:03 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
ok
Fri Dec 27 2024 14:24:15 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
Fri Dec 27 2024 14:27:31 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
this is not decryptor
Fri Dec 27 2024 14:32:37 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
yes, decryptor we wait
Fri Dec 27 2024 14:37:36 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
Fri Dec 27 2024 15:49:34 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
What about esxi ?
Fri Dec 27 2024 15:55:19 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
Give me readme file from esxi
Fri Dec 27 2024 15:55:52 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
ok give me 5 minutes
Fri Dec 27 2024 15:57:26 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
Fri Dec 27 2024 16:18:02 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
the VMDK files cannot be decrypter with the .exe decryptor. could you please send decryptor for VMDK in ESxi based on the txt file i sent you 15 minutes ago ?
Fri Dec 27 2024 16:30:50 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
yes
Fri Dec 27 2024 16:31:33 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
wait 5 minutes
Fri Dec 27 2024 16:31:38 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
Fri Dec 27 2024 16:36:55 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
is there a way to decrypt VMDK files on windows? i have a copy of them and the windows decryptor doesn't work with them
Fri Dec 27 2024 16:40:14 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
only linux
Fri Dec 27 2024 16:40:31 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
please provide command line instructions to run linux
Fri Dec 27 2024 16:42:05 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
Victim #36
1. Could you please tell me which commands to run on ESXi step by step in order to decrypt all files? 2. Is there a chance that something goes wrong when i execute this decrypt_ESXI_X64 command on ESXi? Do i lose all the VMDK files in the server?
Fri Dec 27 2024 16:55:40 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
LOCKBIT
Procedure for decrypting ESXi: - log in to vCenter - enable ssh access to ESXi - upload decryptor to ESXi via WinSCP or FileZilla; navigate to /tmp folder - login to ssh with root privileges - set permissions to run the decryptor with the command - chmod 777 decrypt - launch decryptor ./decrypt - follow the first method of decrypting by viewing the log file: tail -f /tmp/decrypt.llg, wait for the message at the end of the log - Your system is decrypted - the second way is to check the presence on the disk file decrypt.pid command ls, which protects the decryptor from the restart - the third way - ps | grep decrypt, as soon as decrypt.pid will be removed from the disk, or decrypt will disappear from the running processes, decrypt is complete - check the decrypt.llg log file and see the message at the end that the system was successfully decrypted "Your system is decrypted" - turn on virtual machines in ESXi You cannot run multiple copies of a decryptor at the same time. After launching, the decryptor deletes the executable file and is demonetized, so that you cannot run the decryptor again and damage the files, this is normal. If you have more than one ESXi host then you should not run the decryptor on all hosts simultaneously, make the decryption alternately, in the case of simultaneous operation of two decryptors may corrupt files and not be able to decrypt If any files in another folder stay crypted, please use this command with path Example: ./decrypt -i /tmp/files1/
Fri Dec 27 2024 16:56:52 GMT+0000 (Coordinated Universal Time) - dontdocrime.com
End of chat