Urgent Ransomware File Decryption
Publicada el 2026-07-15
Descripción de la oferta
My Windows Server hosting an Oracle-based system was hit by the “BLACKX” ransomware. Every file is now encrypted and the attackers dropped the note quoted below. I need a specialist who can focus on system recovery, specifically file decryption, so I can avoid rolling back to a two-week-old backup and losing important data created since then. What I can provide: • The full ransom note and any associated extension or sample encrypted file you need for analysis. • Access to the affected server through a secure remote session or an off-line disk image, whichever you prefer. • A clean backup taken two weeks prior (last known good state) for comparison or fallback. What I expect from you: 1. Identify the exact BlackX variant, locate the encryption routine or keys, and decrypt at least one test file to prove viability before proceeding with the full restore. 2. Remove any remaining malicious code or persistence mechanisms so the server can be safely brought back online. 3. Deliver a short incident report describing the steps taken and recommended hardening measures to prevent a repeat attack. I understand some variants may be undecryptable without the threat actor’s key; if that turns out to be the case, please outline alternative recovery strategies using my recent backup. Speed is critical, so let me know your estimated turnaround time and the forensic or decryption tools you intend to use (e.g., IDA, Ghidra, Cobalt Strike scanners, dedicated decryptors, etc.). I will remain available to supply logs, hashes, or any additional artifacts you request.
Skills
Fuente original: freelancer