Link to home
Start Free TrialLog in
Avatar of Jason Johanknecht
Jason JohanknechtFlag for United States of America

asked on

Help with Phobos Ransomware

Anyone have experience with Phobos ransomware?  According to the time stamps Phobos took control of a client PC last night around 8:15PM and finished encrypting the entire system and backups by 8:46PM.  The backups are 58GB each x7 copies (The drives alternate daily)  Restored from the other drive without issue, but wondering if I could decrypt the files that are lost from yesterday?  I have tried the Dharma decryption tool so far.
Avatar of John
John
Flag of Canada image

Not likely.  Backups are your only solution here. The majority of ransomware cannot be decrypted.
Avatar of Jason Johanknecht

ASKER

Have you ever seen one that encrypts that large of image files?
Most ransomware will encrypt any number of large / small files
Avatar of Kimputer
Kimputer

Decryption depends on the writer actually being caught by the authorities, with his/her work pc/laptop intact and accessible.
That chance, is pretty low.
If there are decryption tools available, it's usually listed here: https://www.nomoreransom.org/en/decryption-tools.html
In your case, as with 99.999% of the cases, it's not listed.
ASKER CERTIFIED SOLUTION
Avatar of Robert Retzer
Robert Retzer
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Good to know on the submitting samples.  I have worked with Emsisoft in the past, and had forgotten all about them.  Depending on the clients decision, but that will be recommendation.  It is only a days worth of data, and easily recreated they said.