decrypt Veeam Password to plain text

Dear community,

My company is faced with a ransomware attack. We are unable to restore our VMs from Veeam Backup because we have lost the restore password. We have another instance of Veeam that is doing a backup to a different cluster and is not affected by this. I would like to see the password from the Helthly instance in clear text so that I can use it in another instance. According to this page https://blog.checkymander.com/red%20team/veeam/decrypt-veeam-passwords/ I sould be able to decode this base64 format to plain text, but I receive an error from mimikatz:

ERROR kuhl_m_dpapi_unprotect_raw_or_blob ; NTE_BAD_KEY_STATE, needed Masterkey is:

And I can’t find Masterkey in %appdata%\Microsoft\Protect\{sid}\*.

I’ll appreciate any help

submitted by /u/norbo80
[link] [comments]

July 5, 2023
Read More >>