Ranzy — 20201015
Dated recordFrom extortion.wiki, the ransomware negotiation research archive
A validated static rendering of 36 messages in source-array order. Transcript text is preserved without editorial additions.
- Actor
- Ranzy
- Record date
- Oct 15, 2020
- Messages
- 36
- Participants
- Ranzy, Victim
Preserved messages
Actor / other Victim
Select a message number for a stable citation link. Text remains selectable; hard-wrapped source lines are joined for reading, intentional blank-line paragraph breaks remain, and written URLs remain inert.
-
Message 001 From Ranzy Actor / other Date Hello, you heed help?
-
Message 002 From Victim Victim Date how much
-
Message 003 From Victim Victim Date how much
-
Message 004 From Ranzy Actor / other Date Hi, please wait 5 min.
-
Message 005 From Victim Victim Date hello?
-
Message 006 From Ranzy Actor / other Date Hello.
-
Message 007 From Ranzy Actor / other Date Price for your case is $7,000. If you can pay this amount we send you all instructions
-
Message 008 From Ranzy Actor / other Date Hello?
-
Message 009 From Victim Victim Date Your note says all of our sensitive data was downloaded to your servers. Does that mean you took our data? We read an article that says you like to take data. We want our data decrypted. So, if we pay we get a decryptor and all of our files back? Is that how this works?
-
Message 010 From Ranzy Actor / other Date Yes.
-
Message 011 From Victim Victim Date Ok. We are going to have a meeting to discuss this situation. Can you send us a file or two from the data you took?
-
Message 012 From Victim Victim Date Ok. We had our meeting and agree that we need the decryption program. Can you fix a file to prove your ability to decrypt?
-
Message 013 From Ranzy Actor / other Date yes, upload file on https://ufile.io < 3mb
-
Message 014 From Victim Victim Date Here is the link it gave me. https://ufile.io/[redacted]
-
Message 015 From Ranzy Actor / other Date Hello, can you send me teamviewer access on your infected server?
-
Message 016 From Victim Victim Date We can't provide you access, but if you tell us what you need to look at, we can provide information to you. Do you need more sample files, or something else?
-
Message 017 From Ranzy Actor / other Date Yes, more sample files (from any servers and in share folders and local folders). Also tell me this information: Your OS, how to you shutdown our ransomware, and how much share folders in your local network. Thanks.
-
Message 018 From Victim Victim Date Win Server 2008 R2 The Anti Virus caught the malware We only have 1 server.
-
Message 019 From Victim Victim Date https://ufile.io/[redacted]
-
Message 020 From Victim Victim Date Any update on our encrypted file?
-
Message 021 From Victim Victim Date Hello. Have you decrypted our file?
-
Message 022 From Ranzy Actor / other Date Hello
-
Message 023 From Ranzy Actor / other Date We have another messages from recovery company
-
Message 024 From Victim Victim Date What do you mean?
-
Message 025 From Victim Victim Date In the beginning we asked another recovery company to help us. Do you know the name of the recovery company that is communicating with you still? Their website said they could decrypt our files, but it was a lie and I think they contacted you instead. Did they pay you? Please ignore them and communicate here with us and we will get this sorted out.
-
Message 026 From Ranzy Actor / other Date All recovery company is scam and just write us for buy decrypt.
-
Message 027 From Victim Victim Date Have you made any progress on decrypting our test file?
-
Message 028 From Ranzy Actor / other Date Hello yes we have progress but we dont understand which version our software you are encrypted, can you send me time when you encrypted?
-
Message 029 From Victim Victim Date It looks like it happened on 10/11/2020.
-
Message 030 From Ranzy Actor / other Date So, your files encrypted tested version our software and we must scan all your system for find keys for decrypt, and also my boss up price for you so final amount is 30,000$
-
Message 031 From Victim Victim Date Can you give us the scan tool?
-
Message 032 From Ranzy Actor / other Date Scan with private global decryption key and when scanned collect all keys and decrypted it in real time, we can connect to teamviewer and scan it or send it you after payment
-
Message 033 From Victim Victim Date There is no way we are letting you back into the server. We also can't afford anywhere close to the amount you are asking at $30,000. We could barely even afford $7,000. We are just a few person company. If you can't prove you can decrypt, we can't pay you anything. The price needs to go back to $7,000 because I don't know if we can even afford that. How can you decrypt the data without getting into our server?
-
Message 034 From Ranzy Actor / other Date In any case need teamviewer.
-
Message 035 From Victim Victim Date Why can’t we just run whatever key find program you need us to run for you? We will not give you Teamviewer access, especially not if you want a price that we can’t possibly afford. Can you send us the program that you need to run to find the keys, then decrypt a sample file, then we can pay $7000 for decryption?
-
Message 036 From Ranzy Actor / other Date Im already repeat you - your network encrypted with tested versions our software so for finding keys need scan your system, our scanner with private key and we do not provide it just like "download this and run". If you cant provide teamviewer and pay $30,000 - goodbye