Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HowDecrypt or CryptorBit Encrypting Ransomware - $500 USD Ransom Topic


  • Please log in to reply
1745 replies to this topic

#1741 jrtovar

jrtovar

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:52 AM

Posted 11 July 2017 - 02:19 AM

A co-worker of mine made a tool to help generate the keys. It only works on CryptoBit v1 though. The key is made up 2 parts, one to identify if the file is infected and the other half to decrypt the file. He uses some brute force method using the magic numbers from the file signature to generate part of the key. It usually takes between 3-8 hours to run. With just a couple of the infected files like a jpg, doc, and pdf, it will usually work. Having the same unaffected file also helps speed up the process since some file types have several different headers and trying to match them takes time.
Here is the file signature page I use to match the file type: http://www.garykessler.net/library/file_sigs.html
If you want me to give a try, you can send me a couple files....Like I said, only CryptoBit v1

 



BC AdBot (Login to Remove)

 


m

#1742 nunoconceicao

nunoconceicao

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:52 AM

Posted 11 July 2017 - 03:11 AM

A co-worker of mine made a tool to help generate the keys. It only works on CryptoBit v1 though. The key is made up 2 parts, one to identify if the file is infected and the other half to decrypt the file. He uses some brute force method using the magic numbers from the file signature to generate part of the key. It usually takes between 3-8 hours to run. With just a couple of the infected files like a jpg, doc, and pdf, it will usually work. Having the same unaffected file also helps speed up the process since some file types have several different headers and trying to match them takes time.
Here is the file signature page I use to match the file type: http://www.garykessler.net/library/file_sigs.html
If you want me to give a try, you can send me a couple files....Like I said, only CryptoBit v1

 

Interesting, once you get the key from lets say a couple jpgs and/or pdfs, can it work in any kind of encrypted file, like 3dsmax, autocad, etc?

 

Is it possible to make this tool public with some documentation for the more techy people be able to sort out the infection themselves?



#1743 jrtovar

jrtovar

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:52 AM

Posted 11 July 2017 - 03:48 AM

There are 2 pieces. Someone sent me a Windows tool long ago that can decrypt the files, but it won't work without the key. My co-worker created the tool that generates the key. So once the key is generated, I can email you the key and the tool and you can fix all your files. I received the files you sent to me via PM and have started the key generation process. As soon as it's completed, I'll let you know if it worked or not.



#1744 jrtovar

jrtovar

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:52 AM

Posted 12 July 2017 - 02:21 AM

Nuno, I was able to generate the key for you and was able to fix your test files. Check your PM.



#1745 nunoconceicao

nunoconceicao

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:52 AM

Posted 14 July 2017 - 03:06 AM

Thank you Jrtovar!

The key worked and my files are restored. :D

I think there might still be a lot of people out there that were affected by this malware and dont know there is a solution, it would be great if this tool to generate the key could be turned public.

 

Cheers

 

Nuno



#1746 Enanon

Enanon

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:52 AM

Posted 26 September 2017 - 04:44 PM

hi folks. your program helped me to restore all my JPGs after years, i really own you my soul, since it wasnt able to rest since this started.

 

but i still have the .avi corrupted, is there any program up there to help with that? 

 

thanks a ton!






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users