Gonzalo.ARG.206 0 Posted October 3, 2019 Report Share Posted October 3, 2019 Hi people. I need your help with this decrytion if you can. This ramsonware have .phoenix extension and chain “.id[CC3A8E5C-0001].[[email protected]] “ . Can recover this files ? Quote Link to post Share on other sites
GT500 873 Posted October 4, 2019 Report Share Posted October 4, 2019 From the extension it does appear to be Phobos. If that's the case, then note that there's currently no known way to decrypt files without getting the private key from the criminals who made the ransomware. Quote Link to post Share on other sites
Amigo-A 136 Posted October 4, 2019 Report Share Posted October 4, 2019 Quote Original_filename.id[CC3A8E5C-0001].[[email protected]].phoenix Yes. This is Phobos Ransomware This is an old variant, known since April of this year. Demonslay's tweet >> Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.