Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

New Encryption 2018


  • This topic is locked This topic is locked
3 replies to this topic

#1 JiPi82

JiPi82

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:01 PM

Posted 07 January 2018 - 04:58 PM

Hi,

 

i have been looking around in the forum, and I don't think this one was covered so far...Sorry if it is.

 

company has been hit by a crypto virus, that look to be a derivated of Dharma and Arena crypto.  

 

the crypted extension is; filemane.xxx.id-B8F053EC.[sabantui@tutanota.com].java

 

the notes in the TXT files are really short; 

 

Name: FILES ENCRYPTED.TXT

contain:

all your data has been locked us
You want to return?
write email sabantui@tutanota.com or udacha@cock.li
 
Reason we think Arena or Dharma are behind is the behavior and pop up alerting the encryption. 
 
 All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail sabantui@tutanota.com
Write this ID in the title of your message B8F053EC
In case of no answer in 24 hours write us to theese e-mails:udacha@cock.li
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.
Free decryption as guarantee
  • Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 10Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
How to obtain Bitcoins
Attention!
  • Do not rename encrypted files.
  • Do not try to decrypt your data using third party software, it may cause permanent data loss.
  • Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.  
 
 
It managed to infect 2 network, running files (*VHDs) mostly.
 
We tried so far to decrypt using 3rd party like Kasperksy, ESET tools without any luck.
 
was wondering if this was a new trend for 2018 or if any of you might have seen this ''new'' type of behavior.
 
Regards
 
 


BC AdBot (Login to Remove)

 


#2 Emmanuel_ADC-Soft

Emmanuel_ADC-Soft

  • Members
  • 274 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Paris
  • Local time:04:01 AM

Posted 08 January 2018 - 03:43 AM

The .java extension is one of the Dharma (CrySiS) Ransomware. As quietman7 said, any files that are encrypted with Dharma (CrySiS) Ransomware will have an id-<8 random hexadecimal characters>.[<email>] followed by the extension (i.e. .id-406B4F5A.[black.mirror@qq.com].java) which is similar to yours.....filemane.xxx.id-B8F053EC.[sabantui@tutanota.com].java.

 

There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance :



#3 JiPi82

JiPi82
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:01 PM

Posted 08 January 2018 - 04:17 AM

 

The .java extension is one of the Dharma (CrySiS) Ransomware. As quietman7 said, any files that are encrypted with Dharma (CrySiS) Ransomware will have an id-<8 random hexadecimal characters>.[<email>] followed by the extension (i.e. .id-406B4F5A.[black.mirror@qq.com].java) which is similar to yours.....filemane.xxx.id-B8F053EC.[sabantui@tutanota.com].java.

 

There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance :

 

Hi Emmauel, thanks for your information, i will follow this thread. basically there is no real way (yet) to decrypt these files if I understand trail properly...



#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:10:01 PM

Posted 08 January 2018 - 12:31 PM

Rather than have everyone with individual topics, it would be best (and more manageable for staff) if you posted any more questions, comments or requests for assistance in one of the above support topic discussions. To avoid unnecessary confusion, this topic is closed.

Thanks
The BC Staff
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users