Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Btcware Ransomware Support Topic (.crypton Gryphon Help.txt)


  • Please log in to reply
503 replies to this topic

#496 DStamm

DStamm

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:17 PM

Posted 02 November 2017 - 09:52 AM

I found the executable, would that be of value?



BC AdBot (Login to Remove)

 


m

#497 Demonslay335

Demonslay335

    Ransomware Hunter


  • Security Colleague
  • 3,247 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:04:17 PM

Posted 02 November 2017 - 10:24 AM

Not really, I already have dozens of samples.

 

The current variant is spread via RDP and malicious emails to my knowledge.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#498 DStamm

DStamm

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:17 PM

Posted 02 November 2017 - 10:34 AM

Had to have been an email then, as we have explicitly denied external rdp, unless one of the client's computers has a RAT. As always, you guys are the best.



#499 ngolanh

ngolanh

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:05:17 AM

Posted 04 November 2017 - 11:59 AM

Dear All !
 

I have a new win2k8 server infected with Ransomware with payday file type.
file encrypted with file name : DMKH0107.xls.[chukabra@tuta.io]-id-1E90.payday
After the encoding is done, leave the content as below:
file name: !! RETURN FILES !!.txt
"all your files have been encrypted 
want return files?  
write on email: chukabra@tuta.io"
 
 
pls help me : sharemail.vb@gmail.com


#500 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 49,940 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:05:17 PM

Posted 04 November 2017 - 07:57 PM

As I noted in your other topic....payday is based on the latest AES-256 version of the BTCWare Ransomware family which uses a different RSA-1024 key and is not decryptable unless you have the private AES key from the criminals. If possible, your best option is to restore from backups or wait for a possible solution at a later time.
.
.
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Microsoft MVP Reconnect 2016
Windows Insider MVP 2017
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#501 sotojavi

sotojavi

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 04 November 2017 - 08:24 PM


Hi @Demonslay, just to remember I´m one of the people hit by  .BTCWARE, no email on extension. It seems that the attacks had been mutating to other versions and complexity encryptions, and I need to know if you´re still working on my version, or you consider it´s not possible to decrypt. 
I´m not an IT expert, and wondered if there are 3rd party tools that can be used to try to decrypt, one you consider with a chance to succeded.
Thank you very much.

I am in the same boat. I did try the decrypter created by bitdefender. Actually they have a 2 step process. The first process was to identify the version. When I ran that it was identified as btcware v1 and said it found the personal ID within the ransom note. When I ran the second part that is supposed to decrypt the file I got an 'initialization failed' message. When I looked at the log file it said it could not find the personal ID. I remember that Demonslay did mention that what we have is not really btcware v1. He called it version .5. I'm still holding on to the machine that got hacked into along with all server files that were encrypted in hopes of some day recovering them...


#502 sotojavi

sotojavi

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 04 November 2017 - 08:35 PM

I did exactly the same, found the Bitdefender tool and have the same result. I’m in touch with people from their support, they’re checking the “initialization failed” error, I think they don’t know why. I’m also still hoping to find the decrypter, it’s very strange that most of similar versions were already decrypted,

#503 burek

burek

  • Members
  • 3 posts
  • OFFLINE
  •  

Posted 07 November 2017 - 07:32 AM

ransomware payday lock :( how unlock?

https://www.sendspace.com/filegroup/Y%2BjwtqkD1qv%2BEWUamAOC2w


Edited by burek, 07 November 2017 - 07:33 AM.


#504 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 49,940 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:05:17 PM

Posted 07 November 2017 - 08:03 AM

According to Demonslay335...the .payday variant is not decryptable.


.
.
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Microsoft MVP Reconnect 2016
Windows Insider MVP 2017
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users