¿Qué es el formato de archivo EIUR?
Un archivo .eiur es un archivo ordinario que ha sido cifrado por el ransomware EIUR, una variante de la extendida familia STOP/Djvu. Esta cepa apareció a mediados de 2022 y se comporta como sus muchos hermanos, diferenciándose principalmente en la extensión de cuatro letras que añade. Cuando EIUR infecta un PC con Windows, codifica documentos, fotos, bases de datos y videos con el cifrado Salsa20, protege esa clave con RSA-2048 y renombra cada archivo para que budget.xlsx se convierta en budget.xlsx.eiur. Luego suelta una nota de rescate llamada _readme.txt en cada carpeta afectada, exigiendo «$980» en Bitcoin (o «$490» si se paga en 72 horas) y listando las direcciones de contacto [email protected] y [email protected].
Para trabajar rápidamente, el malware cifra solo los primeros 150 KB de cada archivo, razón por la cual los archivos grandes a veces están parcialmente intactos. Ver archivos .eiur significa que el ransomware se ejecutó en su máquina y es posible que haya instalado un troyano de robo de contraseñas junto con el cifrador.
Seguridad y protección
RIESGO: HIGHA .eiur file is itself inert ciphertext, but its presence means active ransomware ran on the machine and may still be resident along with a bundled information-stealer such as RedLine or Vidar. Do not pay the ransom; there is no guarantee of a key and payment funds further attacks. Isolate the device, run a reputable anti-malware scan to remove the executable, then attempt recovery only from backups or the Emsisoft decryptor.
Detalles del formato
en pocas palabrasProgramas que abren archivos EIUR
Detalles técnicos
especificación profunda| Encoding | Salsa20 stream cipher applied to file contents |
| Encryption | Salsa20 for data; the Salsa20 key is protected with RSA-2048. Each victim receives either a shared 'offline' key (used when the C2 server is unreachable) or a unique 'online' key fetched from the attacker server. |
| Byte order | N/A (opaque ciphertext) |
| Container | Original file wrapped with encrypted payload plus an appended block containing the encryption marker and victim key/ID data |
| Partial Encryption | Only the first 150 KB of each file is encrypted, which is why large files are sometimes partially recoverable or repairable |
| Typical size | Same as the original file plus a small appended overhead |
| Structure | Original data encrypted in-place at the start of the file, with a trailing signature and embedded key/personal-ID block; the '.eiur' extension is appended to the original filename (for example 'photo.jpg' becomes 'photo.jpg.eiur'). |
| Integrity | None; no integrity field is present |
| Ransom Note | _readme.txt dropped in every folder with encrypted files and on the desktop |
| Ransom Amount | USD 980, reduced to USD 490 if the victim contacts the attackers within 72 hours, payable in Bitcoin |
| Attacker Contacts | [email protected] and [email protected] |
| Malware Family | STOP/Djvu ransomware |
| Platforms | Windows |
| Notes | EIUR spreads through cracked software, key generators, fake installers and malicious downloads, and often bundles a secondary information-stealer (such as RedLine or Vidar). Files encrypted with a known offline key can sometimes be recovered with Emsisoft's free decryptor; files encrypted with a unique online key cannot be decrypted without the attacker's private key. |
| Lanzado | 2022 (STOP/Djvu variant appeared around late June 2022) |
Conversiones de EIUR
Preguntas y respuestas de la comunidad
preguntado por usuariosAún no hay preguntas; sea el primero en preguntar sobre los archivos EIUR.