Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

eCh0raix Ransomware - QNAPCrypt/Synology NAS (.encrypt) Support Topic


  • Please log in to reply
1202 replies to this topic

#1201 Snowman3848

Snowman3848

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:45 AM

Posted 21 March 2024 - 01:32 PM

Please see the first page (Post#1) of this topic.

 

 

 

 

The same( 

 

Got files on Synology station encrypted on April 11th, 2023. 

 

Link an order id from README_FOR_DECRYPT.txtt :
 

Paid the ransom, got decoder. It don't work (neither on linux nor on windows,I use virtual machines), decrypted files all unreadable.

 

ECh0raix Decoder - 1.0.6 with "key from file option" - logs the same messages: WARNING - Marker not found. Keeping original file. Decrypted file is probably corrupted.
 
Wrote to "chat", asked the KEY - no reply.
 
Baby photos also, don't have even printed copies, completely in despair((
 
Сolleagues, @blooddolly any thoughts please
 
PS have pairs of encrypted/original files if it can be somehow usefull

 

Check if all ransom notes have the same BTC address in the link to TOR page. It is quite common that files were encrypted with different keys, because the NAS was restarted. Each time ECh0raix starts it will call home for new key.
Godannys' problem is that his files were encrypted with another ransomware on top of ECh0raix encryption. His files started with marker "Salted__" and ECh0raix is not using any marker at the start of the file. If you want to check if your files were encrypted by ECh0raix, pick any block of 6+ bytes from the first half of the file and the same block must be located in the second half of the file.

 

 

I work in DFIR.

 

Are you still accepting the malware sample if available for the version currently out there? I may be able to have access to a machine that has a persistent mechanism on it. payment page is dead since it was back in 2021. but the user wants to have the personal files decrypted, files do not have salted_ header . I'm just not sure if the privkey they used for encryption is still even there.

 


Edited by Snowman3848, 21 March 2024 - 04:40 PM.


BC AdBot (Login to Remove)

 


#1202 Analoguser

Analoguser

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:45 AM

Posted 22 March 2024 - 06:38 PM

Got hit last week with the same ransomware.  I use mostly Mac computers and had no issues with them, they locked up my QNAP though.  I use it mostly for video and image storage, I have taken it off the network since the hit.  For what it's worth I noticed they couldn't lock up some files like Pages documents and Blackmagic raw files.  They were able to lock out all of the traditional files such as .MOV, . PDF, .MP4.  I don't know if there might be something in there that could help to find a way to differentiate something that might help.



#1203 valduh

valduh

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:45 AM

Posted 30 March 2024 - 12:41 AM

Hi all, it seems that my qnap also has been hit with ech0raix.

Trying to find a solution to recover my photos, also tried with BloodDolly's decryptor with different types of files, but it didn't work. As far as i read, it seems that I have been encrypted with a newer key.

How do you suggest to proceed? I read that some of you paid them, but i don't know how much it costs, how safe it is and how it works :) Do you have other suggestions?

 

Thanks in advance.






2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users