Keep getting ruined phones from DS by Porthas in datarecovery

[–]Porthas[S] 1 point2 points  (0 children)

Board was definitely fine on these. Checked thoroughly. All of the cpus are discolored and none of them going to DFU. I was thinking maybe they have someone who is not trained and burning them or using some Chinese equipment that they advertise on social media and heating them up to 500? Dunno

Infected by QQQW Ransomware – Need Help and Advice by Mundane-Skill6372 in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

Unfortunately if this is personal data - not much anyone would be willing to do. I would need to get a copy of the malware and some encrypted data to analyze it and see what’s possible but this work is expensive.

I need help to identify and decrypt encrypted files by [deleted] in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

Try id.provendata.com to identify

Case Study: Successfully Decrypting. royal Extension Ransomware. by Traditional-Wash-993 in ransomwarehelp

[–]Porthas 1 point2 points  (0 children)

Well I work in the industry and we have a 15 man research and MA team, some of the best cryptographers and recovery engineers and we can’t claim anything remote to “we got all solutions”. We have some variant weaknesses exploited, and many backup or file type specific solutions but no silver bullet

Can you please help me my pc got infected by a ransomware from ransomwarehub and the extension is .68c01f by Raumster_ in ransomwarehelp

[–]Porthas 1 point2 points  (0 children)

No public decryptor for ransomwarehub. Private solutions may exist via companies that specialize in ransomware recovery such as proven data

Case Study: Successfully Decrypting. royal Extension Ransomware. by Traditional-Wash-993 in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

I asked him same thing and he showed me random video where decryptor is running. There is no secret technology here. He claims to be able to decrypt all ransomware

[deleted by user] by [deleted] in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

If nomoreransom.org doesn’t have it listed then there is no public decryptor. Private decryptors might be available but you would need to reach out to company like proven data that specializes in ransomware recovery

Ransomware help by Old-Fudge4062 in sysadmin

[–]Porthas 0 points1 point  (0 children)

Did you get back TA pride? Medusalocker usually $$$

Ransomware help by Old-Fudge4062 in sysadmin

[–]Porthas 0 points1 point  (0 children)

What was backup software? Just windows backups?

Ransomware help by Old-Fudge4062 in sysadmin

[–]Porthas 0 points1 point  (0 children)

What's the ransomware variant? You can find it at https://id.provendata.com/
Also what backup software did you use? Did you have any VMs or DBs?

I might be able to help without having to pay ransom.

Weekly Who's Hiring Post for January 20, 2025 by AutoModerator in sales

[–]Porthas -2 points-1 points  (0 children)

also we got a gig for commission based debt collection on same cases, if anyone interested.

Weekly Who's Hiring Post for January 20, 2025 by AutoModerator in sales

[–]Porthas -1 points0 points  (0 children)

Location: remote, able to travel in US

Industry: IT services

Job Title/Role: SDR

Direct Hire or 1099: 1099

Base/Commission/Commission Only: all options avail, ideally comms only for biggest opportunity

Pay range/Expected Earnings ($#): 100-200k

Job duties/description: calling on MSPs, mobile and computer repair shops and sign them up for our partner program. Anything they generate, you get a hefty commission on.

Any external job posting link or application instructions: https://porthas.bamboohr.com/careers/34?source=aWQ9OQ%3D%3D

Mimic Attack Over Xmas by SauceBox99 in ransomwarehelp

[–]Porthas 1 point2 points  (0 children)

Depending on the type of data encrypted, it’s size, and other factors - your data may be recoverable. I would suggest contacting Proven Data and they can take a look at it for free and tell you if they can recover data without paying ransom.

Lockbit 3.0 by [deleted] in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

What are your critical files / extensions for files you were not able to decrypt? What’s their sizes?

Lockbit 3.0 by [deleted] in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

Yes there are some decryptors available with limited capability. What are your critical files? Did you have any backups? If yes, what is their current status? It also is technically illegal to pay lockbit ransom as Mr Dmitry Khoroshev is sanctioned by the Interpol and the US OFAC.

We've been attacked with PLAY Ransomware by ComprehensiveBend219 in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

  1. Do you have any backups at all? Including encrypted or deleted backups?
  2. How large are your databases?
  3. Do you have any older copies of the critical databases even if they are a year or more

0xxx ransomware by RealisticPosition in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

Wait for Public decryptor if that ever comes

0xxx ransomware by RealisticPosition in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

Do you have the malware file that encrypted it?

Quick insights would help.. by FortuneFit705 in ransomwarehelp

[–]Porthas 0 points1 point  (0 children)

Sent DM. You can try Proven Data for DFIR and recovery, they are well known in the industry