Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Stopped CryptoLocker


  • Please log in to reply
19 replies to this topic

#1 EricTaylor

EricTaylor

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 02:47 PM

Hey all,

 

I am hoping someone can help me out here, as most of the other sites out there keep pointing reference to this site. I am not 100% how we got this infection, but there was a file running "decrpytfiles.exe" that I was able to stop/delete before it actually started to create a ton of issues. But now my issue is that all the files are showing as a RSA-4096 file (with a .RSA-4096 extension). I went through the TelsaDecoder docs, but since my files are still in this form, not sure really what to do here. If anyone can please help, that would be awesome and save the day for me here.



BC AdBot (Login to Remove)

 


#2 thyrex

thyrex

  • Members
  • 582 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belarus
  • Local time:03:14 PM

Posted 13 December 2016 - 02:50 PM

Upload sample of encrypted .doc or .docx file on https://www.sendspace.com and give us downloading link 


Microsoft MVP 2012-2016 Consumer Security

Microsoft Reconnect 2016


#3 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,085 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:01:14 PM

Posted 13 December 2016 - 02:55 PM

Try the xorist decrypter from here. You will need an original and encrypted file pair.
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#4 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 02:57 PM

Threx,

 

Thanks for your response. Here is the file you request:

 

https://www.sendspace.com/file/r4wpdf



#5 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 02:59 PM

Try the xorist decrypter from here. You will need an original and encrypted file pair.
 
xXToffeeXx~

 

Thank you. I do have some of the before and after as I was moving some files from different locations and my NAS. I disconnected the NAS, and sure I have some original files. I will report back shortly on the outcome of this task.



#6 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 03:05 PM

 

Try the xorist decrypter from here. You will need an original and encrypted file pair.
 
xXToffeeXx~

 

Thank you. I do have some of the before and after as I was moving some files from different locations and my NAS. I disconnected the NAS, and sure I have some original files. I will report back shortly on the outcome of this task.

 

 

It was unable to find a valid key:

 

https://www.sendspace.com/file/tun539



#7 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,085 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:01:14 PM

Posted 13 December 2016 - 03:06 PM

 

 

Try the xorist decrypter from here. You will need an original and encrypted file pair.
 
xXToffeeXx~

 
Thank you. I do have some of the before and after as I was moving some files from different locations and my NAS. I disconnected the NAS, and sure I have some original files. I will report back shortly on the outcome of this task.

 

 
It was unable to find a valid key:
 
https://www.sendspace.com/file/tun539

 

Can you share the pair of files used?
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#8 thyrex

thyrex

  • Members
  • 582 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belarus
  • Local time:03:14 PM

Posted 13 December 2016 - 03:09 PM

Yes, it's Xorist. I asked encrypted .doc or .docx file


Microsoft MVP 2012-2016 Consumer Security

Microsoft Reconnect 2016


#9 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 03:15 PM

 

 

 

Try the xorist decrypter from here. You will need an original and encrypted file pair.
 
xXToffeeXx~

 
Thank you. I do have some of the before and after as I was moving some files from different locations and my NAS. I disconnected the NAS, and sure I have some original files. I will report back shortly on the outcome of this task.

 

 
It was unable to find a valid key:
 
https://www.sendspace.com/file/tun539

 

Can you share the pair of files used?
 
xXToffeeXx~

 

 

 

The files you requested:

 

https://www.sendspace.com/file/qxg90l


Yes, it's Xorist. I asked encrypted .doc or .docx file

 

I can find a doc file if you think that will help you.



#10 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 03:23 PM

Yes, it's Xorist. I asked encrypted .doc or .docx file

 

 

Here are a word docx file for you:

 

https://www.sendspace.com/file/p1f2fe



#11 thyrex

thyrex

  • Members
  • 582 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belarus
  • Local time:03:14 PM

Posted 13 December 2016 - 03:24 PM

It's not encrypted file :)


Microsoft MVP 2012-2016 Consumer Security

Microsoft Reconnect 2016


#12 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 03:29 PM

It's not encrypted file :)

 

I understand its not yet 'encrypted', but still unusable. Is there a way to recover?



#13 thyrex

thyrex

  • Members
  • 582 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belarus
  • Local time:03:14 PM

Posted 13 December 2016 - 03:31 PM

I need .doc.RSA-4096 or .docx.RSA-4096


Microsoft MVP 2012-2016 Consumer Security

Microsoft Reconnect 2016


#14 EricTaylor

EricTaylor
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  

Posted 13 December 2016 - 03:35 PM

I need .doc.RSA-4096 or .docx.RSA-4096

 

Oh, sorry about that. I thought that the last upload would have sent both of the files. Here you go:

 

https://www.sendspace.com/file/n4ubt1



#15 thyrex

thyrex

  • Members
  • 582 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belarus
  • Local time:03:14 PM

Posted 13 December 2016 - 03:54 PM

Thanks. I will start brute-force key only with .docx.RSA-4096 :)


Microsoft MVP 2012-2016 Consumer Security

Microsoft Reconnect 2016





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users