Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

WaifuClub Ransomware ( [[AYspF0Nd]].[[backup@waifu.club]].svh )


  • Please log in to reply
15 replies to this topic

#1 gambiarra

gambiarra

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:45 AM

Posted 05 April 2024 - 09:19 AM

Good morning,

This week a virus entered my server but I was unsuccessful in finding a solution for it.

I would like if you could help me please

because it encrypted all my files and database :/

I'm sending a sample of what appears to me, it's a virus with extension


file.xlsx.[[AYspF0Nd]].[[backup@waifu.club]].svh



BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 05 April 2024 - 10:01 AM

Good morning,

This week a virus entered my server but I was unsuccessful in finding a solution for it.

I would like if you could help me please

because it encrypted all my files and database :/

I'm sending a sample of what appears to me, it's a virus with extension


file.xlsx.[[AYspF0Nd]].[[backup@waifu.club]].svh

 

[[AYspF0Nd]].[[backup@waifu.club]].svh = [[random 8]].[[<email>]].svh
 

This is not a variant of Press Ransomware
 
Did you find any ransom notes? If so, what is the actual name of the ransom note?
Can you provide (copy & paste) the ransom note contents in your next reply?
 
In addition to coping & pasting the ransom note...please attach the original (unedited) ransom note and several samples of encrypted files (different formats - doc, png, jpg) AND its original (unencrypted) file in a "zip file" for comparison so our crypto malware experts can manually inspect them and possibly identify/confirm the infection if they see this topic. To attach files....Click the More Reply Options button in the bottom right corner of the Board Editor, then click the Choose File button under Attach Files.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#3 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 05 April 2024 - 10:39 AM

Since this is not a variant of Press Ransomware, I have split away your posting into it's own topic.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#4 gambiarra

gambiarra
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:45 AM

Posted 05 April 2024 - 11:34 AM

Thanks,


I'm new to the forum, sorry

I'll see if I can get a photo and post it here



#5 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 05 April 2024 - 11:35 AM

Ok.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#6 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,057 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:45 AM

Posted 05 April 2024 - 12:33 PM

I'm sending a sample of what appears to me, it's a virus with extension

 

Where is the ransom note file and samples of encrypted files?


My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#7 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 05 April 2024 - 03:07 PM

A quick search with Yandex shows victims with these extensions (without victim id before email) on several Chinese sites but I did not see a ransom note.
[[MyFile@waifu.club]].wis
[[backup@waifu.club]].wis

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#8 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,057 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:45 AM

Posted 06 April 2024 - 01:17 PM

There are many messages online and almost all of them are in Chinese.
I think we can leave it to them (China) and let them figure it out them selves.
They have the technical and human means for this WaifuClub Ransomware.

Edited by Amigo-A, 06 April 2024 - 01:27 PM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#9 gambiarra

gambiarra
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:45 AM

Posted 08 April 2024 - 11:15 AM

Good afternoon,


I was only able to add the files today.

I couldn't find the rescue file anywhere

I will give you what I have files because I know that you are the best to solve


I suspect that the virus came from these files in the "Maintenance" folder

 

https://sendgb.com/HPGiMI2L7zN

 

Inside it there is a file written keys.dat

and the .exe file inside the "apps" folder indicated as a virus


Inside "archive.rar" there is an infected and non-infected file for testing

Thanks for all your help



#10 gambiarra

gambiarra
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:45 AM

Posted 08 April 2024 - 11:17 AM

Good afternoon,


I was only able to add the files today.

I couldn't find the rescue file anywhere

I will give you what I have files because I know that you are the best to solve


I suspect that the virus came from these files in the "Maintenance" folder

 

https://sendgb.com/HPGiMI2L7zN

 

Inside it there is a file written keys.dat

and the .exe file inside the "apps" folder indicated as a virus


Inside "archive.rar" there is an infected and non-infected file for testing

Thanks for all your help



#11 gambiarra

gambiarra
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:45 AM

Posted 08 April 2024 - 11:19 AM

sorry, I sent it twice

 

I think the file that is 20mb was not uploaded, I added it to the link

 

 

https://sendgb.com/SQIYZHorJLX


Edited by gambiarra, 08 April 2024 - 11:23 AM.


#12 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,057 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:45 AM

Posted 08 April 2024 - 12:46 PM

Apart from the screenshot of the ransom note, there is nothing to take here. 
It would be more useful to examine the malicious file. It needs to be sent to the virustotal.com site.

Edited by Amigo-A, 08 April 2024 - 12:46 PM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#13 gambiarra

gambiarra
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:45 AM

Posted 08 April 2024 - 01:01 PM

This is the file inside the .exe "app" folder

Attached Files



#14 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 08 April 2024 - 02:36 PM

As Amigo-A said....you should submit (upload) a sample of any malicious executable that you suspect was involved in causing the infection to VirusTotal for analysis and provide a link here to the results...this is the safest way of sharing malware since only vetted researchers can access it. Doing that may be helpful with any of the following: analyzing, investigating, identification of the ransomware and possibly finding a flaw which could be useful for decryption of encrypted data.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#15 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,057 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:45 AM

Posted 09 April 2024 - 10:37 AM

As quietman7 said...

Yes. We need a link to the analysis result.

Of course, can distinguish some letters and numbers SHA-256, but the font in the screenshot is too small.


Edited by Amigo-A, 09 April 2024 - 10:38 AM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users