Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

RCRU64 Ransomware ([ID=id random 6-Mail=email].random 4) Support Topic


  • Please log in to reply
52 replies to this topic

#1 aamoudi

aamoudi

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:07 AM

Posted 16 April 2022 - 03:28 PM

Any files that are encrypted with RCRU64 Ransomware V3 will have an [ID=id random 6-Mail=email].random 4 character extension appended to the end of the encrypted data filename and leave files (ransom notes) named Restore_Your_Files.txt, ReadMe.hta, Read_Me!_.txt, ReadMe_Now!.hta as explained here by Amigo-A (Andrew Ivanov). These are some examples.

[ID=rfeHv0-Mail=FilesRecoverEN@Gmail.com].03rK
[ID=qMIo8p-Mail=kamira99@tutanota.com].9C8L
[ID=Nc6GC2-Mail=psychopath7@tutanota.com].q6BH
[ID=snnCCB-Mail=Sc0rpio@mailfence.com].7v3t
[ID=y6Cllb-Mail=FreedomTeam@mail.ee].0wqA
RCRU64 V3 typically will include a random 6 character "ID" in the ransom note.
Your ID: AfdoLo
Your Personal ID : rfehvo
Your unique ID: zlkJu2
 
Any files that are encrypted with RCRU64 Ransomware V4 will have an _[ID-id random 5_Mail-email}.random 3 character extension appended to the end of the encrypted data filename and leave files (ransom notes) named Restore_Your_Files.txt, ReadMe.hta, Restore_Your_Files.txt. These are some examples.
_[ID-GRHYT_Mail-jounypaulo@mail.ee].HHE
_[ID-LQIWB_Mail-pm24@tuta.io].LRO
_[ID-RRF0H_Mail-dr.file2022@gmail.com].M4X
_[ID-L1LXB_Mail-vyptteam@zohomail.eu].Vypt
_[ID-DXNVI_Mail-Sc.computer1992@Gmail.com].L7I
_[ID-BVPKO_Mail-insomnia1441@gmail.com].MMV

RCRU64 V4 typically will include a random 5 uppercase character "ID" in the ransom note.

Your ID : YUNFY
Your ID : WEKNZ
Your ID : L1LXB

 

rivitna (Andrey Zhdanov) may be able to help some victims if they have an RSA private key.
 
 
Please i need your support to decrypt my files, i found all its encrypted with the below extension
 
ID=tC3C3O-Mail=Rcru64@cock.lu].oKby
 
Thank you in advanced.



BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 16 April 2022 - 04:43 PM


Did you find any ransom notes? If so, what is the actual name of the ransom note?
Can you provide (copy & paste) the ransom note contents in your next reply?
 
Please submit (upload) samples of encrypted files, ransom notes and any contact email addresses provided by the cyber-criminals to ID Ransomware (IDR) for assistance with identification and confirmation of the infection. ID Ransomware can identify ransomware which adds a prefix instead of an extension and more accurately identifies ransomware by filemarkers if applicable. Uploading both encrypted files and ransom notes together along with any email addresses provided gives a more positive match with identification and helps to avoid false detections. Please provide a link to the ID Ransomware results
 

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#3 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:07 AM

Posted 17 April 2022 - 05:48 AM

ID=tC3C3O-Mail=Rcru64@cock.lu].oKby

 

Probably, this extension [ID=tC3C3O-Mail=Rcru64@cock.lu].oKby 

 

This is RCRU64 Ransomware


Edited by Amigo-A, 17 April 2022 - 05:49 AM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#4 aamoudi

aamoudi
  • Topic Starter

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:07 AM

Posted 17 April 2022 - 06:14 AM

 

ID=tC3C3O-Mail=Rcru64@cock.lu].oKby

 

Probably, this extension [ID=tC3C3O-Mail=Rcru64@cock.lu].oKby 

 

This is RCRU64 Ransomware

 

 

Hello Amigo,

 

Please i checked the website but unfortunately i didn't found the decrypt for ransomware.



#5 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 17 April 2022 - 07:41 AM

That means there is no free decryptor and no way to decrypt files without paying the ransom and obtaining the private encryption keys from the criminals who created the ransomware unless they are leaked or seized & released by authorities. Without the criminal's master private key that can be used to decrypt your files, decryption is impossible. That usually means the key is unique (specific) for each victim and generated in a secure way (i.e. RSA, AES, Salsa20, ChaCha20, ECDH, ECC) that cannot be brute-forced.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#6 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 17 April 2022 - 07:58 AM

Topic title changed to reflect naming convention and direct other victims to this support topic.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#7 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:07 AM

Posted 17 April 2022 - 01:21 PM

Hello Amigo,

 

Please i checked the website but unfortunately i didn't found the decrypt for ransomware.

 

 

Yes, I did not have time to complete the answer. This is the only description of this ransomware.

There is no way to decrypt files without paying a ransom. But extortionists has been using this variant for more than a year.

It is recommended to save the most important files to an external drive and disconnect from the computer. A ransom-free decryptor may be available in the future. We hope.


Edited by Amigo-A, 17 April 2022 - 01:26 PM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#8 arimarjul

arimarjul

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:07 AM

Posted 04 December 2022 - 01:53 PM

Please i need your support to decrypt my files, i found all its encrypted with the below extension
 
 
[ID=AfdoLo-Mail=dr.filees@gmail.com].Mafer
 
 
I did a research but appereantly nobody has enconunered with this ransomware yet
 
 
Thank you in advanced.


#9 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 04 December 2022 - 02:34 PM

Did you find any ransom notes? If so, what is the actual name of the ransom note?
Can you provide (copy & paste) the ransom note contents in your next reply?
 
Also, please attach the original ransom note and several samples of encrypted files (different formats - doc, png, jpg) AND its original (unencrypted) file for comparison so Amigo-A (Andrew Ivanov) can inspect them and possibly confirm the infection (and/or add to his database).


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#10 arimarjul

arimarjul

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:07 AM

Posted 04 December 2022 - 03:03 PM

Hello quietman7, thank you for your response.

 

Here is the ransom note: 

 

Name: Read_Me!_.txt

 

Note:

 

All Your Files Encrypted And Sensitive Data Downloaded (Financial Documents,Contracts,Invoices etc.. ).

 
 
To Get Decryption Tools You Should Buy Our Decrption Tools And Then We Will Send You Decryption Tools And Delete Your Sensitive Data From Our Servers.
 
If Payment Is Not Made We have to Publish Your Sensitive Data If Necessary Sell Them And Send Them To Your Competitors And After A While Our Servers Will Remove Your Decrypion Keys From Servers.
 
Your Files Encrypted With Strongest Encryption Algorithm So Without Our Decryption Tools Nobody Can't Help You So Do Not Waste Your Time In Vain!
 
Your ID:  AfdoLo
 
Email Address: dr.filees@gmail.com
 
In Case Of Problem With First Email Write Us E-mail At : luka.born@tutanota.com
 
Send Your ID In Email And Check Spam Folder.
 
This Is Just Business To Get Benefits, If Do Not Contact Us After 48 Hours Decryption Price Will x2.
 
 
What Guarantee Do We Give You ?
 
You Should Send Some Encrypted Files To Us For Decryption Test.
 
----------------------------------------------------------------------
 
Attention!
 
Do Not Edit Or Rename Encrypted Files.
 
Do Not Try To Decrypt Files By Third-Party Or Data Recovery Softwares It May Damage Files.
 
In Case Of Trying To Decrypt Files With Third-Party Sofwares,This May Make The Decryption Harder So Prices Will Be Rise.
 
----------------------------------------------------------------------
 
How To Buy Bitcoin :
 
Buy Bitcoin Instructions At LocalBitcoins : 
 
 
 
 
When I try to attach the files it give me the error You aren't permitted to upload this kind of file
 
So i uploaded it here:
 
 
Hope it helps,
 
Thank you

Edited by arimarjul, 04 December 2022 - 03:03 PM.


#11 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 04 December 2022 - 03:16 PM

Could be a newer variant of RCRU64 Ransomware which uses the name Read_Me!_.txt. The contents of the ransom note looks like those we have seen with newer variants of RCRU64 Ransomware.
 
Amigo-A will need to confirm.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#12 arimarjul

arimarjul

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:07 AM

Posted 05 December 2022 - 12:17 PM

Hello, after my first post, one user contact me in prívate and give me a whatsapp contact of a person that can decrypt my files.

I wrote to him and after mail him a crypt file they send me a screen capture with the same file decrypted.

He offer to send me the decrypt tool if I send him 0.065 bitcoin.

Dou you know if this kind of offer is legit? Or is the same hacker that create the ransomware and also could be a member of this forum?


Edited by arimarjul, 05 December 2022 - 12:27 PM.


#13 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 05 December 2022 - 12:41 PM

What was the name of the member who reached out?
 
Bleeping Computer cannot vouch for those who claim they can decrypt data or help in other ways. 
 
Ransomware victims should IGNORE, (not reply back, deal with or negotiate payments with) anyone who may contact them via Private Message (PM) on this forum or by email making claims they can decrypt your data. Please read my comments in this topic for information as to what we know about those who claim they can decrypt data (including scammers, the criminals and data recovery services).


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#14 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,049 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:10:07 AM

Posted 05 December 2022 - 01:40 PM

It looks more like RCRU64 Ransomware, unless others copy it.


My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#15 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 05 December 2022 - 01:45 PM

Then they probably switched from random 4 digit extension to 5 digits or just started to used 5 digits.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users