My server (CentOS) recently got hacked by some Crypto Hackers. They encrypted all of my files and asking for ransom to decrypt the files. They kept a message in all folders, which start like this
Your personal files are encrypted! Encryption was produced using a unique public key RSA-2048 generated for this computer.
To decrypt files you need to obtain the private key.
The single copy of the private key, which will allow to decrypt the files, located on a secret server on the Internet. After that, nobody and never will be able to restore files...
To obtain the private key for this computer, which will automatically decrypt files, you need to pay 1 bitcoins (~240 USD). Without key, you will never be able to get your original files back...
Now they have sent me the decrypt keys and I'm still Could someone please help me how I can recover my files?
What are the possible vulnerabilities that they took advantage of? Any other tips/pointers to avoid future threats? Thanks in advance.
Edit: They send me a PHP script with the private key, which I should upload to the server and run through a URL. Here is the decrypt file they sent me.