Any files that are encrypted with Proxima Ransomware will have a .Proxima, .Cylance, .Lattice, .Phalcon extension appended to the end of the encrypted data filename and typically will leave files (ransom notes) named PROXIMA_README.txt, CYLANCE_README.txt, LATTIVE_README.txt, PHALCON_RECOVER.txt.
Any files that are encrypted with
Proxima/BlackShadow will have a
.BlackShadow, .BlackSh, .BlackStore, .ZeroCool, .Black, .X, .Gomez, .Jarjets, .Daniel, .Xray, .Mikel, .Tisak, .SNet, .Jack, .uploaded, .transferred, .Antoni, .sysinfo, .Sezar, .Lambda, .[random 9].Synapse (GbFk7VeUI.Synapse)
, .arthur extension appended to the end of the encrypted data filename as explained
here by
rivitna (
Andrey Zhdanov) and
here by
Amigo-A (Andrew Ivanov).
Proxima/BlackShadow typically will leave files (ransom notes) named #FILE ENCRYPTED.txt, BlackSh_Help.txt, BlackShadow_Help.txt, BlackStore_Help.txt, ZeroCool_Help.txt, Black_Recovery.txt, X-Help.txt, Gomez_Recover.txt, Jarjets_ReadMe.txt, Off_Help.txt, Daniel_Help.txt, Xray_Help.txt, Tisak_Help.txt, Mikel_Help.txt, Jack_Help.txt, DecryptNote.txt, Recovery_Instructions.txt, HOW_TO_RESTORE_FILES.txt, Antoni_Recovery.txt, Sezar_Recovery.txt, LAMBDA_README.txt, [random 9].README.txt (GbFk7VeUI.README.txt), Arthur_help.txt.
In some cases the ransom notes include the same appended extension_Help.txt as part of the note's name.
Hello;
we've been hit by Proxima Ransomware. anyone has help in decrypting the files?