Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

eCh0raix Ransomware - QNAPCrypt/Synology NAS (.encrypt) Support Topic


  • Please log in to reply
1210 replies to this topic

#346 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,904 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:01 PM

Posted 06 March 2020 - 03:35 PM

Unfortunately, newer versions (July 19, 2019 and later) are still not decryptable without paying the ransom and obtaining the private keys from the criminals who created the ransomware unless they are leaked or seized & released by authorities. Without the master private RSA key that can be used to decrypt your files, decryption is impossible. That usually means the key is unique (specific) for each victim and generated in a secure way that cannot be brute-forced.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


BC AdBot (Login to Remove)

 


#347 drhenruth

drhenruth

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:09:01 PM

Posted 07 March 2020 - 02:57 AM

Hello,
 
I wonder how many infected people have complained to the police? 
If the only solution is to have the primary keys of the hackers it would be interesting to know.
I don't know if the police are investigating this hack?


#348 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,904 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:01 PM

Posted 07 March 2020 - 07:23 AM

Despite being an expanding threat, ransomware infections are rarely reported to law enforcement agencies, according to conclusions from the 2016 Internet Crime Report, released yesterday by the FBI’s Internet Crime Complaint Center (IC3)...FBI urges victims to file official complaints.

FBI: Victims Aren't Reporting Ransomware Attacks
 


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#349 vijayrajput

vijayrajput

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 17 March 2020 - 08:35 AM

Hi Team Please help for decrypt file with .!Encrypted  



#350 SlavekP

SlavekP

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:01 PM

Posted 17 March 2020 - 11:59 AM

I have just decided to check the "order" page - just to see, if the pricing remained unchanged once the BTC is half of its original price.

But the page seems to be dead. Has anyone tried it recently?



#351 vijayrajput

vijayrajput

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 17 March 2020 - 11:52 PM

any latest tool for recovering data... please help 

 

file ext     .!Encrypted   



#352 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,125 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:12:01 AM

Posted 18 March 2020 - 03:17 AM

Hello vijayrajput

 

Attach several encrypted files and a ransom note here or give me in PM. 


My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#353 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,125 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:12:01 AM

Posted 18 March 2020 - 06:09 AM

file ext .!Encrypted  

I found an interesting coincidence of file names and your extension in a neighboring topic

 

!Encrypted.exe

https://www.virustotal.com/gui/file/394ba143556e813fcaea7919b670cf4b3c89680f682bf56c02997ad782c824f2/detection

 

It seems that a rather old encoder is used, but this does not make it safe. 

DrWeb knows how as Trojan.Ransom.690 (the middle of 2014).


Edited by Amigo-A, 18 March 2020 - 06:18 AM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#354 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,904 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:01 PM

Posted 18 March 2020 - 08:31 AM

any latest tool for recovering data... please help 

 

file ext     .!Encrypted   

Are you sure this is eCh0raix Ransomware? How did you identify it?


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#355 hodsenplods

hodsenplods

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:01 PM

Posted 30 March 2020 - 07:55 AM

I have just decided to check the "order" page - just to see, if the pricing remained unchanged once the BTC is half of its original price.

But the page seems to be dead. Has anyone tried it recently?

I just tried yesterday and today and I can report the same: page is not reachable. Very bad news actually as I always considerd this as a last resort.

 

Best regards

 

hodsenplods


Edited by hodsenplods, 30 March 2020 - 08:00 AM.


#356 doczilla

doczilla

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:12:01 PM

Posted 19 April 2020 - 10:45 PM

Had a HDD fail so I went to restore all my kids' photos from my synology to discover they were encrypted. Looks like from back in August, so the 2nd version. 172 character hash in the readme =(

 

Any updates? Also I found their site to be dead as well, just as a last resort =(



#357 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,904 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:01 PM

Posted 20 April 2020 - 07:02 AM

There are no updates that I am aware of.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#358 ptraid

ptraid

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:01 PM

Posted 24 May 2020 - 05:26 AM

I have my files encrypted since yesterday, with the .encrypt extension and the README_FOR_DECRYPT.txt in each folders, it encrypts only documents and images files (no video or uncommon file extensions). The ransom note does not contain the key at the end, just this :

----

All your data has been locked(crypted).
How to unlock(decrypt) instruction located in this TOR website: http://veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id.onion/order/1L1WwajFy1MCSzvPzbi5YabcVWsi7JGwhf
Use TOR browser for access .onion websites.
https://duckduckgo.com/html?q=tor+browser+how+to

----

I isolated the binaries responsible for this (crp_linux_386 and crp_linux_arm), and there is a log file (screenlog.0) that lists the operation of the ransom ware :

----

share/MD0_DATA/Web/crp_linux_arm: /share/MD0_DATA/Web/crp_linux_arm: cannot execute binary file
Init...
BTC addr: 1L1WwajFy1MCSzvPzbi5YabcVWsi7JGwhf
open /share/MD0_DATA/.@centerim/README_FOR_DECRYPT.txt: permission denied
open /share/MD0_DATA/.@mysql/mysql: permission denied
open /share/MD0_DATA/.@mysql/test: permission denied
open /share/MD0_DATA/.@qmonitor: permission denied
...

Encrypt file: /share/MD0_DATA/.@twonkymedia.db/twonkymedia/db/0.tms.dat
(0x831e7d0,0xa099960)
open /share/MD0_DATA/.@twonkymedia.db/twonkymedia/db/0.tms.dat.encrypt: permission denied
Encrypt file: /share/MD0_DATA/.@twonkymedia.db/twonkymedia/db/1.tms.dat
(0x831e7d0,0xa099980)
...
Encrypt file: /share/MD0_DATA/corpo.html
Encrypt file: /share/MD0_DATA/enviar.pl
Encrypt file: /share/MD0_DATA/ftp.txt
...
open /share/MD0_DATA/lost+found: permission denied
Encrypt file: /share/MD0_DATA/pass.txt
Encrypt file: /share/MD0_DATA/user.txt
Done!

----

Do you know which variant is it ? Or is it a variant or muhstik ?

Thanks



#359 pituke

pituke

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:01 PM

Posted 24 May 2020 - 05:54 AM

Hello. I am victim of hacker attack on QNAP NAS TS-491, all my files ale encrypted and all my documents and fotos files have extension .encrypt. I try to use ECh0raixDecoder2, but no success. Cant find key. I try pair of files, encrypted and original, also known header files and whole encrypted dir. Is it any other way to decrypt my files without payment to attacker?

 

Thanks for advice.



#360 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,904 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:01 PM

Posted 24 May 2020 - 05:58 AM

Newer versions (July 19, 2019 and later) are not decryptable without paying the ransom and obtaining the private keys from the criminals who created the ransomware unless they are leaked or seized & released by authorities. Without the master private RSA key that can be used to decrypt your files, decryption is impossible. That usually means the key is unique (specific) for each victim and generated in a secure way that cannot be brute-forced...the public RSA key alone that encrypted files is useless for decryption.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





4 user(s) are reading this topic

0 members, 4 guests, 0 anonymous users