02-11-2021 , 10:05 PM
https://www.avast.com/ransomware-decryption-tools Fonix ( Avast Decryption Tool for Fonix 1.0.243.0)
The Fonix ransomware was active since June 2020. Written in C++, it uses three key encryption scheme (RSA-4096 master key, RSA-2048 session key, 256-bit file key for SALSA/ChaCha encryption). On February 2021, the ransomware authors shut their business down and published the master RSA key that can be used for decrypting files for free.
Filename changes:
Encrypted files will have one of these extensions:
.FONIX,
.XINOF
Ransom message:
After encrypting files on the victim machine, the ransomware shows the following screen:
+
If Fonix has encrypted your files, click here to download our free fix:
DOWNLOAD FONIX FIX : https://s-decryptors.avcdn.net/decryptor..._fonix.exe Digital Signature ( Avast Software s.r.o. )
The Fonix ransomware was active since June 2020. Written in C++, it uses three key encryption scheme (RSA-4096 master key, RSA-2048 session key, 256-bit file key for SALSA/ChaCha encryption). On February 2021, the ransomware authors shut their business down and published the master RSA key that can be used for decrypting files for free.
Filename changes:
Encrypted files will have one of these extensions:
.FONIX,
.XINOF
Ransom message:
After encrypting files on the victim machine, the ransomware shows the following screen:
+
If Fonix has encrypted your files, click here to download our free fix:
DOWNLOAD FONIX FIX : https://s-decryptors.avcdn.net/decryptor..._fonix.exe Digital Signature ( Avast Software s.r.o. )