Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

eCh0raix Ransomware - QNAPCrypt/Synology NAS (.encrypt) Support Topic


  • Please log in to reply
1197 replies to this topic

#1186 thefisch007

thefisch007

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:02 AM

Posted 20 October 2023 - 11:44 AM

Hello,

 

first time for being in an forum ;-)

 

Last week i was attaked by ransomeware eCh0raix on my nas. I tried different decocers without luck.

 

In this forum i read, that some people found help to decode the files.

 

My txt file is: 

 
Use TOR browser for access .onion websites.
Is there anyone  how can  help me?
Thanks in advance 


BC AdBot (Login to Remove)

 


#1187 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:02 PM

Posted 20 October 2023 - 02:54 PM

Per the first page of this topic.

 

BloodDolly released a free ECh0raix Decoder decryption tool (Post #184) which can find the key and decrypt old variants of ECh0raix for victims infected prior to July 17, 2019. Using this decoder, victims can brute force the decryption key for encrypted files and use it to restore them. Everyone infected after July 19, 2019 was hit with new variant. A quick way to tell if your are a victim of the new unbreakable version is if the key at the end of the ransom note is 173 characters long. 
 
BloodDolly updated ECh0raix Decoder (V1.0.6) so victims can use any file as a source of decryption keys, however the decoder still cannot find the decryption key for newer versions of ECh0raix. See Post #707. Alternate download link and instructions provided here.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#1188 thefisch007

thefisch007

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:02 AM

Posted 20 October 2023 - 03:00 PM

hi quietman7

 

thank you for your answer! Helps me a lot :-)

 

I dont understand what you meen with "the key at the end..."

 

Would you be so kind and explane it to me?

 

Thank you



#1189 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:02 PM

Posted 20 October 2023 - 05:03 PM

See the example ransom notes posted here.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#1190 thefisch007

thefisch007

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:02 AM

Posted 21 October 2023 - 10:45 AM

Thank you, but i am sorry - it seem i have no chance :-(

 

Best Regards



#1191 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:02 PM

Posted 21 October 2023 - 02:19 PM

In cases where there is no free decryption tool (or a previous tool no longer works for newer variants), restoring from back up is not a viable option and file recovery software does not work, the only other alternative to paying the ransom (which is not advisable) even if you can reach the criminals to pay is to backup/save your encrypted data as is and wait for a possible solution at a later time...meaning, what seems like an impossibility at the moment (decryption of your data), there is always hope someday there may be a potential solution.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#1192 Sinner1973

Sinner1973

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:02 AM

Posted 21 October 2023 - 05:31 PM

We paid the ransom (about 1000 usd) and today we have all our photos and a better backup.

#1193 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:02 PM

Posted 21 October 2023 - 08:27 PM

You were fortunate. Not everyone who pays the ransom demand is successful with decryption of their data or even getting a decrypter from the criminals and not everyone is successful negotiating a payment with them. 


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#1194 Vogel70

Vogel70

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:02 AM

Posted 28 October 2023 - 10:38 AM

 

deleted!


Edited by Vogel70, 28 October 2023 - 11:15 AM.


#1195 test0r

test0r

  •  Avatar image
  • Members
  • 68 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:04:02 AM

Posted 13 November 2023 - 05:12 AM

it looks like that some old QNAPs are still getting infected, but not possible to use the decoder as people can't get the key anymore :(

 

Best way now to recover (and free) is Photorec!!



#1196 ransomwarealert

ransomwarealert

  •  Avatar image
  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 16 January 2024 - 08:16 AM

Hello everyone, someone knows the new link to the eCh0raix payment site

 

The previous portals are out of line

 
 
Thanks
 
 
 
 
 
 


#1197 test0r

test0r

  •  Avatar image
  • Members
  • 68 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:04:02 AM

Posted 25 January 2024 - 05:23 AM

 

Hello everyone, someone knows the new link to the eCh0raix payment site

 

The previous portals are out of line

 
 
Thanks
 
 
 
 
 
 

 

old website is up but no one answering, so useless at the moment.. use photorec!



#1198 SomeMiller

SomeMiller

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:02 AM

Posted Today, 08:15 PM

Recently, my NAS got encrypted. I started searching on Google and stumbled upon this topic, many people are writing that their decryptor doesn't work. I pondered for a long time what to do, didn't really want to pay, and the amount was significant for me. But my wife kept nagging me about the photos because there were children's photos and our wedding photos stored there. I decided to pay when I saw they had a 30% discount for payment. After reading the forum, I realized I was lucky that my files were decrypted, or they changed something in the decryptor






3 user(s) are reading this topic

0 members, 3 guests, 0 anonymous users