All times are UTC - 5 hours [ DST ]


Forum rules


Please do not post questions about data recovery cases here (use this forum instead). This forum is for topics on finding new ways to recover data. Accessing firmware, writing programs, reading bits off the platter, recovering data from dust...



Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: MKP ransomware decryption - anyone has success?
PostPosted: November 18th, 2023, 5:52 
Offline

Joined: May 30th, 2014, 0:54
Posts: 125
Location: Universe
One my client's network is hacked by this ransomware and all files are encrypted .This is Makop ransomware variant.
Is there anyway to decrypt and what will be cost of decrypter and key.


Attachments:
Screenshot 2023-11-18 015201.png
Screenshot 2023-11-18 015201.png [ 33.85 KiB | Viewed 18604 times ]
Top
 Profile  
 
 Post subject: Re: MKP ransomware decryption - anyone has success?
PostPosted: November 18th, 2023, 6:20 
Offline
User avatar

Joined: May 13th, 2019, 7:50
Posts: 913
Location: Nederland
If I remember correctly it, or some variants at least, do not encrypt entire files if file is above xMB file size but few 256 KB areas only. So then depending on file type partial file repair may be a last option.

_________________
Joep - http://www.disktuna.com - video & photo repair & recovery service


Top
 Profile  
 
 Post subject: Re: MKP ransomware decryption - anyone has success?
PostPosted: November 18th, 2023, 8:28 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3456
Location: Greece
What he says ^^^ is correct.

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: MKP ransomware decryption - anyone has success?
PostPosted: November 19th, 2023, 11:16 
Offline

Joined: May 30th, 2014, 0:54
Posts: 125
Location: Universe
Arch Stanton wrote:
If I remember correctly it, or some variants at least, do not encrypt entire files if file is above xMB file size but few 256 KB areas only. So then depending on file type partial file repair may be a last option.


Thanks Arch Stanton ,Thanks for replying
You are right I have repaired few SQL files though repaired files do not directly open in clients software , developer was successful to extract useful data and reconstruct database again.
Unfortunately in this case this particular variant is super strong and clients entire network is affected (having nearly 500GB office files) so cannot work on thousands of files .Besides doc & pdf files are having weak structure , I haven't been successful to repair any file of these 2 types.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 43 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group