Darkside Log 2
5/26/2026, 9:36:03 AM
VictimInvalid Date
How to buy Bitcoin for this amount?
DarksideInvalid Date
Hello!
DarksideInvalid Date
Moment please, let me prepare a manual for you.
DarksideInvalid Date
are you sure that you want to pay in bitcoin? maybe you prefer monero? cause in case you want to pay in bitcoin, you have to pay in 20% more because of service fees.
VictimInvalid Date
how monero works?
DarksideInvalid Date
process is literally the same
DarksideInvalid Date
give me a moment i provide a monero tutorial
VictimInvalid Date
ok good for monero
DarksideInvalid Date
monero manual here is the fastest and safest service to buy monero in your country https://localmonero.co/ alternative way is to buy bitcoin via next manual and change it to monero here https://changelly.com/ bitcoin manual here are some services where you can safely buy and send bitcoin https://localcryptos.com/ manual how to buy and send is placed on the main page, this is the simplest and fastest way, no any verification required/////// https://paxful.com/ here is the short manual how to buy and send https://www.youtube.com/watch?v=EjB5qFW0bJ8 profile verification may be required//////// https://www.coinbase.com/ here is the short manual how to buy and send https://www.youtube.com/watch?v=Neph3rjv0Co profile verification may be required/// chose which one you like more, and buy bitcoin. hen text in chat and we provide the wallet for transfer
VictimInvalid Date
ok. I'm working on it
VictimInvalid Date
ok. I'm working on it
VictimInvalid Date
Hi. The price is too high
VictimInvalid Date
could we find a mediation?
VictimInvalid Date
we do not have that amount of money. We are a little company
VictimInvalid Date
5.000€?
DarksideInvalid Date
We do not make such big discounts.
DarksideInvalid Date
Read about us on the Internet.
DarksideInvalid Date
5000 euro is impossible. you are not a small company, we've been working on your network, we have encryped 200tb of data, you can not be a small company, you have a whole data center.
VictimInvalid Date
please give us a sustainable amount we are 80 people that works from [redacted location]
VictimInvalid Date
[redacted location]
VictimInvalid Date
we work for non profit organization like [redacted]
DarksideInvalid Date
before the attack we checked info about your company, so it's absolutely useless to prove us anything. discount is possible, but not in the amount you want. you can try to take a loan and find any cryptobrocker who will resolve all the cryptocurrency exchange.
VictimInvalid Date
10.000€
DarksideInvalid Date
You are wasting our time. Write when you have serious offers.
DarksideInvalid Date
discount x100 from first amount is impossible. we can reduce the price by 50 000. so you have to pay 950 000 $
VictimInvalid Date
we do not have that amount. Is out of our business
DarksideInvalid Date
take a loan
VictimInvalid Date
I can make you an offer compatible with my availability and comparable to the time it would take if I had to restore from backups
DarksideInvalid Date
we know everything about your backups, if you could restore, you wouldn't text us at all. so please stop wasting our time and yours, you know, that the only way to restore your business is to make the payment requested
DarksideInvalid Date
are we talking with recovery company right now? cause few hours ago this conversation had a bit another vector.
VictimInvalid Date
no I move from home to office
DarksideInvalid Date
go back home, you were much more pliable from there.
VictimInvalid Date
I'm talking to the CEO to unadestand how much can we pay
DarksideInvalid Date
ok we are waiting
VictimInvalid Date
I talked with my CEO we want to solve the issue. We can offer 75.000€ to start the decryption process and 75.000 at the end of the decryption. (in total 150.000€)
DarksideInvalid Date
This amount is not enough. Raise the price and we will give you an additional discount. We can refuse payment and not give you a decryptor. Can you afford it? What will you tell your clients? We understand you and are ready to give you a decryptor right now. Give us a good offer.
DarksideInvalid Date
Any phased payment options are not possible. You pay first, then we give you decryptors. If you are not sure, you can give us test files and we will decrypt them for you.
DarksideInvalid Date
In Linux, we specially encrypt log files, they are small in size and you can upload them to chat.
VictimInvalid Date
In you site you declare that you do not attack no.profit organization. We host the site of a lot of no profit organization that currently has the service down. Please accept our offer 150.000 all in one
DarksideInvalid Date
Look, if you were a non-profit organization, you wouldn't be attacked by anyone. Everyone can say that they are helping someone. In the current case, your offer does not meet our expectations. It will get you nowhere and you are wasting your time. Give us a better price and we will give you a discount.
DarksideInvalid Date
I want you to understand one thing, it doesn't matter to me how long it takes to discuss the price. This is important for you. The faster you get decryptors, the faster you will continue to make money.
VictimInvalid Date
I sent you a small files
[redacted].txt.[redacted]
8.95 kBDarksideInvalid Date
File
[redacted].txt
8.81 kBVictimInvalid Date
Hi, we had a crisis committee meeting. We evaluated your proposal. I know that you don't want waste time but trust me we are not so big as you think. We need time to get a reasonable amount of MONERO or BITCOIN. We try deliver an extra special effort and we can raise to 250.000€. We hope that this offers meet your expectation
VictimInvalid Date
i'm moving to home becouse of lock down and we had to go home at 10pm
DarksideInvalid Date
We are ready to accept 700k dollars. We will give you a discount of $ 300k.
VictimInvalid Date
We want to pay but we do not have 700k. We did the best effort to offer you 250.000
VictimInvalid Date
here is midnigth, i need to sleep and I hope to found some good news.
DarksideInvalid Date
Let's get back to this question in the morning! you need to rest, you are right! Goodnight!
VictimInvalid Date
good moring......I hope
DarksideInvalid Date
We've made you a 30% discount. Give us a better price and we will try to give you an additional discount.
VictimInvalid Date
Trust me. We host site for no-profit organization that do not have a lot of money. You found a lot of data but this are our kind of customer. We made the best 250.000€ is a very high amount for us. We had also a problem to find this amount in a few days. The site that you suggested offer MONERO at block of 5000 or 10.000€
VictimInvalid Date
We are 60 employee and only 6 on IT....we are working on this problem 24 hours....we need your help
DarksideInvalid Date
I spoke to my boss and explained your situation to him. He approved a payment of 350k dollars. There will be no more discounts. Now you are offering 300k dollars, raise your price by 50k and we will close this deal now.
VictimInvalid Date
do you have a quick way to get that amount of MONERO?
VictimInvalid Date
we accept your proposal
DarksideInvalid Date
Price updated. Reload the page.
VictimInvalid Date
ok. Give us a reference to get that amount of monero
DarksideInvalid Date
Yes, have you considered buying through the exchange? Or are you having trouble with it?
DarksideInvalid Date
If you find it difficult to get Monero - buy Bitcoin first. Then change it to Monero.
VictimInvalid Date
We want to buy through the exchange. But they exchange at block of 10.000€.
DarksideInvalid Date
I think it is not difficult to buy bitcoin in your country. Use exchangers or crypto exchanges (binance, et al.).
VictimInvalid Date
ok. I will update you
VictimInvalid Date
we have to do change € on our wallet or directly charge on your wallet
DarksideInvalid Date
Change money on your wallet and then send us cryptocurrency
VictimInvalid Date
Hi, just to tell you that we are working to get cryptocurrency
DarksideInvalid Date
OK, we wait.
VictimInvalid Date
Good moring. Very difficult to move on BTC that amount on one wallet. You need transaction from one wallet alone?
VictimInvalid Date
can we make in more transcation?
VictimInvalid Date
could you Decrypt some server?
DarksideInvalid Date
We are waiting for xmr from you, not btc. If you decided to pay with btc, you have to pay additional 20%.
DarksideInvalid Date
And you can use several transaction
DarksideInvalid Date
After payment you will receive decryptor for all your network.
VictimInvalid Date
several transaction from same wallet or we could use different wallet?
DarksideInvalid Date
You can use different wallet
VictimInvalid Date
How many BTC we had to pay? Yesterday i saw 25.18, now I see 23.3
DarksideInvalid Date
Pay the amount that you see now
DarksideInvalid Date
Btc rate is not stable, so don't wait and pay quickly
VictimInvalid Date
do not change anymore because we had a lot o difficult to get crypto BTC
DarksideInvalid Date
i can fixed the rate, but you have to pay for 6 hours
DarksideInvalid Date
will pay for this time?
VictimInvalid Date
we'll try in 12 hours , but i'm not sure, maybe 24.
DarksideInvalid Date
i have fixed your btc amount, for the next 24 hours it doesn't depend from btc rate
DarksideInvalid Date
but you must pay as soon as possible
VictimInvalid Date
ok
VictimInvalid Date
help us as soon as possible. We are very little to pay that amount but we do....and also we had to work a lot of other days....give an hand as soon as you can....trust us
DarksideInvalid Date
After payment I will immediately give you decryptors.
VictimInvalid Date
Hi. Why the rate changed again?
VictimInvalid Date
you promise me to block the rate of BTC to 23.3
VictimInvalid Date
we already had a trade for that amount and we need to fix it
VictimInvalid Date
Are you there?
DarksideInvalid Date
Hello
DarksideInvalid Date
Rate was changed yesterday, before i fixed it
DarksideInvalid Date
You actual amount for the next 12 hours 23.61 BTC
VictimInvalid Date
we bought yesterday 23.3 by an exchanger and we are waiting for the transaction. We cannot change the amount now
VictimInvalid Date
the payment is in process
DarksideInvalid Date
okay, waiting for 23.3 BTC from you in next several hours
VictimInvalid Date
ok. May I ask a partial decrypion of one server?
DarksideInvalid Date
After payment you'll immediately receive decryptor for all network
DarksideInvalid Date
You have the last 3 hours to pay the fixed btc amount after that time the rate will be float again.
VictimInvalid Date
be patient
VictimInvalid Date
the transaction is in progress with our exchanger
VictimInvalid Date
technical time
DarksideInvalid Date
Our btc wallet is always actual and the same, so send as quickly as it possible.
VictimInvalid Date
what do you mean?
DarksideInvalid Date
The wallet that you see on your page is always relevant
VictimInvalid Date
i'm here
VictimInvalid Date
operation is in progress
DarksideInvalid Date
ok
VictimInvalid Date
be patient operation with exchanger is taking too long time
VictimInvalid Date
please
DarksideInvalid Date
How many time you need?
VictimInvalid Date
The exchanger told me that operation should be in the morning. Now here are 20:47
DarksideInvalid Date
Take in mind, that after 35 hours your price will be doubled and this action cannot be undone.
VictimInvalid Date
we know. My mind now is about 23.3 BTC becouse operation is for that amount
DarksideInvalid Date
If you don't pay tomorrow, i'll enable float rate again and don't fixed it anymore.
DarksideInvalid Date
So, hurry up your exchanger.
DarksideInvalid Date
Good morning! Any updates?
VictimInvalid Date
I had a meeting scheduled with exchanger at 1PM
VictimInvalid Date
i don't know why he 's taking time. We yesterday moved € to exchanger
DarksideInvalid Date
Well, if anything, do not hesitate to write about the results
VictimInvalid Date
we need cryptocurrency to close the deal with you and my family will be happy becouse I have to work all weekend
DarksideInvalid Date
I understand you, as far as I know in Europe there are bitcoin ATMs for a long time
VictimInvalid Date
never seen
DarksideInvalid Date
https://coinatmradar.com/country/[redacted]/
DarksideInvalid Date
We won't give you extra time, after 16 hours you price will be doubled, make payment faster.
VictimInvalid Date
Hi, i'm in call with exchanger
VictimInvalid Date
we had to wait for the transfer of the amount
VictimInvalid Date
technica time between bank
VictimInvalid Date
I have the document that prove that we are moving money
VictimInvalid Date
but we need more time
VictimInvalid Date
till monday
VictimInvalid Date
in the week end bank do not operate
DarksideInvalid Date
Send the documents.
VictimInvalid Date
upload in progress
IMG_20201120_152201.jpg
5.4 MBVictimInvalid Date
3 pages
IMG_20201120_152152.jpg
4.8 MBVictimInvalid Date
last page
IMG_20201120_152145__02__01.jpg
5.06 MBDarksideInvalid Date
Ok, added time.
VictimInvalid Date
da you update the countdown on this page
VictimInvalid Date
?
VictimInvalid Date
Time ends on 23 Nov 2020, 09:51
VictimInvalid Date
in the morning is too eearly
VictimInvalid Date
the bank open in the morning
VictimInvalid Date
please set the deadline to 24 November 9 AM
VictimInvalid Date
so we are sure than on monday close the transaction
DarksideInvalid Date
Refresh the page
VictimInvalid Date
Ok thanks
VictimInvalid Date
Hi, we are at work.
DarksideInvalid Date
Hello! We, too, how is the exchange process going?
VictimInvalid Date
only the bank does not work on the week end
VictimInvalid Date
the decryption tool work per single file?
DarksideInvalid Date
You will receive a master (universal) decryptor for your Linux and Windows network after payment
VictimInvalid Date
it runs recursively o per file?
DarksideInvalid Date
the process works as when encrypting only in the opposite direction, we will also send all instructions, and provide support until you decrypt the all network
VictimInvalid Date
see you tomorrow
DarksideInvalid Date
Ok! Have a nice day!
DarksideInvalid Date
After 17 hours your price will be doubled and we won't change it.
VictimInvalid Date
i'm here
VictimInvalid Date
good morning
VictimInvalid Date
we are almost ready
VictimInvalid Date
i'm worried about decryption process
VictimInvalid Date
there are a lot of file on a lot of volume
DarksideInvalid Date
Hello! the process of decryption is similar to the encryption process, you do not need to worry, maximum 4-5 hours and your files will be decrypted
VictimInvalid Date
on vmware do i need to execute decryption on one host esx that is connected to all volume or do I have to execute on every single host?
DarksideInvalid Date
You should upload decryptor to each esxi, set 777 permissions and run. That's all you need, after small time your esxis will be ready for work.
VictimInvalid Date
can we test the decryption process on one single vmdk file?
DarksideInvalid Date
We will send decryptor after payment and help with all. Don't worry, it's too easy.
VictimInvalid Date
we are doing the first transaction
VictimInvalid Date
what description in the transaction?
VictimInvalid Date
we sent the first little amount in order to test the correct transaction
VictimInvalid Date
it is ok?
DarksideInvalid Date
we can see your transaction
DarksideInvalid Date
you can send all amount
VictimInvalid Date
ok
VictimInvalid Date
we proceed
DarksideInvalid Date
and after 3 confirmation of bitcoin network we will send you decryptors and instruction
VictimInvalid Date
with the next trance
VictimInvalid Date
we sent half amount
VictimInvalid Date
please give us linux or windows decryptor now
DarksideInvalid Date
we will send your decryptors only after you send us full amount.
DarksideInvalid Date
we are waiting for next part
VictimInvalid Date
one moment
VictimInvalid Date
sent
DarksideInvalid Date
ok, we can see your transaction
DarksideInvalid Date
waiting for 3 confirmation and then send you decryptors
VictimInvalid Date
we are waiting for decryptor
DarksideInvalid Date
Windows:
The decryptor works in 2 modes:
1. GUI
2. Console
Three functions are available in GUI mode:
1. "DECRYPT ALL" - search and decrypt ALL encrypted files on the local
PC and on network resources (Shares), where this PC has access.
2. "DECRYPT FOLDER" - decrypts files in the specified folder, which you
can select in the "Browse for folders" window or drag and drop the
folder into the decryptor window.
3. "DECRYPT ONE FILE" - decrypts a single file, which you can open in
the "Open" window or drag and drop the encrypted file into the decryptor
window.
IMPORTANT!
Extension of encrypted files may not coincide with the extension of files, which the decryptor suggests to open!
To open encrypted files with other extensions, in the "Open" window
select, in the lower right corner of "All Files (*. *)" or just drag and
drop the given file into the decryptor window.
File extension does not affect the decryption of file!
Console mode has two parameters:
1. "-all" - search and decrypt ALL encrypted files on the local PC and on network resources (Shares), where this PC has access.
You can also use Group Policy to quickly decrypt your entire network.
2. "-path" - decrypts files in the specified folder or a single file.
3. Dragging and dropping an encrypted file or folder with encrypted files onto the decryptor file.
In this mode, the console window will open automatically, which will display the decryption process.
Command line examples:
> decryptor.exe -all
> decryptor.exe -path C:\Folder
> decryptor.exe -path C:\Folder\file.txt.[redacted]
win_decryptor.exe
76.5 kBVictimInvalid Date
linux decryptor works alsa per files?
VictimInvalid Date
also
DarksideInvalid Date
linux decryptor decrypts all system, it cant decrypt certain files
VictimInvalid Date
may I ran on host that see all encrypted volume?
DarksideInvalid Date
just run the decryptor on each esxi, that's all, you don't need to do anything anymore
DarksideInvalid Date
after decryption you can use your vms as before that
VictimInvalid Date
we are at work
DarksideInvalid Date
Linux decryption instruction:
1. Upload decryptor to esxi.
2. Set run permissions: chmod 777 decryptor
3. Run decryptor: ./decryptor
jump_decryptor.out
2.38 MBDarksideInvalid Date
Use this one decryptor for you esxi
VictimInvalid Date
what is the difference?
VictimInvalid Date
the decryptor did not decrypt some file
VictimInvalid Date
on esx
DarksideInvalid Date
Try the last decryptor.
DarksideInvalid Date
Which file was not decrypted? Give more information.
VictimInvalid Date
/vmfs/volumes/[redacted]/[redacted]_RM_03/[redacted]_RM_03_1-flat.vmdk.darkside /vmfs/volumes/[redacted]/WD_[redacted]/WD_[redacted]-flat.vmdk.darkside /vmfs/volumes/[redacted]/V185E016/V185E016-flat.vmdk.darkside /vmfs/volumes/[redacted]/V157E016/V157E016_1-flat.vmdk.darkside /vmfs/volumes/[redacted]/V066E016 - [redacted]/V066E016 - [redacted]_1-flat.vmdk.darkside /vmfs/volumes/[redacted]/V079E016 - [redacted]/V079E016 - [redacted]-flat.vmdk.darkside /vmfs/volumes/[redacted]/V195E016/V195E016_1-flat.vmdk.darkside /vmfs/volumes/[redacted]/V000REPP/V000REPP_1-flat.vmdk.darkside /vmfs/volumes/[redacted]/V000PAS2/V000PAS2_1-flat.vmdk.darkside /vmfs/volumes/[redacted]/V060E016/V060E016-flat.vmdk.darkside /vmfs/volumes/[redacted]/V000TS1P_2012/V000TS1P_2012-flat.vmdk.darkside /vmfs/volumes/[redacted]/V144E016/V144E016-flat.vmdk.darkside /vmfs/volumes/[redacted]/V189E016/V189E016-flat.vmdk.darkside /vmfs/volumes/[redacted]/V067E016/V067E016-flat.vmdk.darkside /vmfs/volumes/[redacted]/V000AMQP/V000AMQP-flat.vmdk.darkside /vmfs/volumes/[redacted]/V000AMMP/V000AMMP_3-flat.vmdk.darkside /vmfs/volumes/[redacted]/[redacted] - ArcGis DataStore/[redacted] - ArcGis DataStore-flat.vmdk.darkside
DarksideInvalid Date
have other files been decrypted? Are virtual machines working?
DarksideInvalid Date
Use the last decryptor. He will decrypt them.
VictimInvalid Date
i will try the other decryptor becouse when i try to start [redacted] seems that a disk is missing
DarksideInvalid Date
Try the last one and write to me.
VictimInvalid Date
[START #11] File Path.........../vmfs/volumes/[redacted]/[redacted]_RM_03/[redacted]_RM_03_1-flat.vmdk.darkside [INFO] File Size................0mb (4096 Bytes) [ERROR] File Too Small, Ignored
DarksideInvalid Date
What is the size of this file? Problem with one file or multiple?
VictimInvalid Date
42
VictimInvalid Date
seems that some filese were modified and disk size of the VM was set to 0
VictimInvalid Date
so the VM does not start
DarksideInvalid Date
what 42?
VictimInvalid Date
42 useful file was not decrypted
DarksideInvalid Date
and how much was decrypted?
VictimInvalid Date
a lot
DarksideInvalid Date
If the reason for the non-decryption is that there is 0 size, then I cannot help you. The decryptor cannot decrypt what is not. Check all file sizes and tell me them. When you tried to start virtual machines, the hypervisor could damage the encrypted files. I mean before you got the decryptor.
DarksideInvalid Date
Are you having a problem with virtual machines on the same hypervisor? or at all?
VictimInvalid Date
we are having some problem
DarksideInvalid Date
answer the questions so that I could understand what to tell you.
VictimInvalid Date
the probelm is on esx
VictimInvalid Date
Task name Power On virtual machine Target WD_[redacted] Status File /vmfs/volumes/[redacted]/WD_[redacted]/WD_[redacted].vmdk was not found
DarksideInvalid Date
Look through ssh. Do you have a file?
VictimInvalid Date
have a file of 4K with .darkside extension
VictimInvalid Date
we lost some vm
VictimInvalid Date
sigh!
DarksideInvalid Date
The decryptor checks all checksums, it could not damage virtual machines. This is the first time that a client talks about problems. Did you check the sized before decryption?
DarksideInvalid Date
How many virtual machines have you failed to recover? Were they on the same esxi?
DarksideInvalid Date
You showed me a log in which the decryptor is trying to decrypt empty files. So the problem arose before decryption. Why so, I can not answer you, there can be a lot of reasons.
DarksideInvalid Date
If you have any other problems with decryption - I will help you, just give me not empty files.
VictimInvalid Date
the empty file has data of creation on 15Nov in the night
VictimInvalid Date
i don't know why
VictimInvalid Date
there is a format job runnin
VictimInvalid Date
I need your little but useful help. On veem the volume where we have the backup , this morning was accessible but now the volume is RAW.
DarksideInvalid Date
I don't quite understand what you mean
VictimInvalid Date
the tool that you used to encrypt our backup. At the end of encrypion does it do disprutive action?
DarksideInvalid Date
No, it doesn't. If backups are on Windows - use the Windows decryptor.
DarksideInvalid Date
Never interrupt the decryption process by closing the program manually. The program may freeze during decryption, this is normal.
VictimInvalid Date
Hi.
VictimInvalid Date
we trusted in you
VictimInvalid Date
but we need some files that miss
DarksideInvalid Date
We gave you decryptors and they work, if you have problems with them, I will help you.
DarksideInvalid Date
Before buying decryptors, you saw that some files were empty and you could not pay.
DarksideInvalid Date
We fulfilled our part of the deal, I don't know why you have empty files. You didn't even tell me how many there are.