Franki Fung 0 Posted August 18, 2017 Report Share Posted August 18, 2017 My server is infected with randomware which add .GOTHAM extension to the files. Turns out to be GlobeImposter 2. Attached is the PersonalID, the original file and affected file. Grateful if you can investigate and find a decrypt solution. Sooner or later. Thank you. PAR_2016-2017_1_K_N_K1.doc PersonalID.txt PAR_2016-2017_1_K_N_K1.doc.GOTHAM Quote Link to post Share on other sites
GT500 872 Posted August 19, 2017 Report Share Posted August 19, 2017 There is no known decryption solution for GlobeImposter 2. You would need to obtain the private key to decrypt the files, and since the ransomware generates new keys for every infected computer the only known way to get the private key is from the criminals who made the ransomware. Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.