.EIUR

File EIUR

EIUR Ransomware Encrypted File
Fai una domanda
RISPOSTA RAPIDA

Un file .eiur è un normale documento, foto o video che è stato cifrato da EIUR, una variante della famiglia di ransomware STOP/Djvu. Il malware crittografa ogni file con il cifrario Salsa20, aggiunge l'estensione .eiur al nome e rilascia una nota _readme.txt che richiede un pagamento in Bitcoin. Non è possibile aprire direttamente un file .eiur. Le uniche strade legittime sono il ripristino da un backup pulito o l'esecuzione del decryptor gratuito STOP Djvu di Emsisoft, che funziona solo se i file sono stati bloccati con una chiave offline nota.

Sviluppatore: STOP/Djvu ransomware operators (malware authors) Categoria: File crittografati MIME: application/octet-stream
SI APRE SU Windows
Correlati: .CRYPT · .SDOC · .AXX · .REM

In questa pagina

19k+ estensioni indicizzate
Ultima revisione Jul 17, 2026

Non sei sicuro di cosa sia il tuo file?

Trascina qualsiasi file nel nostro identificatore - leggiamo solo i primi byte per dare un nome al formato.

Identifica un file

Che cos'è il formato di file EIUR?

Un file .eiur è un file ordinario che è stato crittografato dal ransomware EIUR, una variante della diffusa famiglia STOP/Djvu. Questo ceppo è apparso intorno alla metà del 2022 e si comporta come i suoi numerosi simili, differendo principalmente per l'estensione di quattro lettere che aggiunge. Quando EIUR infetta un PC Windows, cifra documenti, foto, database e video con il cifrario Salsa20, protegge tale chiave con RSA-2048 e rinomina ogni file in modo che budget.xlsx diventi budget.xlsx.eiur. Successivamente, rilascia una richiesta di riscatto chiamata _readme.txt in ogni cartella interessata, richiedendo «$980» in Bitcoin (o «$490» entro 72 ore) e indicando gli indirizzi di contatto [email protected] e [email protected].

Per agire rapidamente, il malware crittografa solo i primi 150 KB di ogni file, motivo per cui i file di grandi dimensioni sono talvolta parzialmente intatti. La presenza di file .eiur indica che il ransomware è stato eseguito sulla macchina e potrebbe aver installato un trojan per il furto di password insieme al modulo di crittografia.

Sicurezza e incolumità

RISCHIO: HIGH

A .eiur file is itself inert ciphertext, but its presence means active ransomware ran on the machine and may still be resident along with a bundled information-stealer such as RedLine or Vidar. Do not pay the ransom; there is no guarantee of a key and payment funds further attacks. Isolate the device, run a reputable anti-malware scan to remove the executable, then attempt recovery only from backups or the Emsisoft decryptor.

Dettagli del formato

in sintesi
NOME COMPLETOEIUR Ransomware Encrypted Fileanche noto come Eiur virus file, EIUR STOP/Djvu variant
SVILUPPATORESTOP/Djvu ransomware operators (malware authors)dal 2022 (STOP/Djvu variant appeared around late June 2022)
TIPO MIMEapplication/octet-stream
TIPOEncrypted binary container produced by malware

Programmi che aprono file EIUR

Windows5 apps
Emsisoft Decryptor for STOP Djvu Gratuito Download and run the decryptor, let it scan your drives, and it will restore files that were encrypted with a known offline key; it reports when an online key was used and files cannot be recovered.
Malwarebytes Freemium Run a full scan to detect and quarantine the EIUR ransomware executable and any bundled stealer before attempting any file recovery.
Windows System Restore Integrato Roll the system back to a restore point created before the infection to recover unencrypted copies, if restore points survived the attack.
ShadowExplorer Gratuito Browse Volume Shadow Copies to pull earlier, unencrypted versions of files, though STOP/Djvu usually deletes shadow copies.
PhotoRec Open-source Carve deleted original files from the disk after encryption, since STOP/Djvu often encrypts a copy and deletes the source, leaving recoverable remnants.

Dettagli tecnici

specifiche approfondite
EncodingSalsa20 stream cipher applied to file contents
EncryptionSalsa20 for data; the Salsa20 key is protected with RSA-2048. Each victim receives either a shared 'offline' key (used when the C2 server is unreachable) or a unique 'online' key fetched from the attacker server.
Byte orderN/A (opaque ciphertext)
ContainerOriginal file wrapped with encrypted payload plus an appended block containing the encryption marker and victim key/ID data
Partial EncryptionOnly the first 150 KB of each file is encrypted, which is why large files are sometimes partially recoverable or repairable
Typical sizeSame as the original file plus a small appended overhead
StructureOriginal data encrypted in-place at the start of the file, with a trailing signature and embedded key/personal-ID block; the '.eiur' extension is appended to the original filename (for example 'photo.jpg' becomes 'photo.jpg.eiur').
IntegrityNone; no integrity field is present
Ransom Note_readme.txt dropped in every folder with encrypted files and on the desktop
Ransom AmountUSD 980, reduced to USD 490 if the victim contacts the attackers within 72 hours, payable in Bitcoin
Attacker Contacts[email protected] and [email protected]
Malware FamilySTOP/Djvu ransomware
PlatformsWindows
NotesEIUR spreads through cracked software, key generators, fake installers and malicious downloads, and often bundles a secondary information-stealer (such as RedLine or Vidar). Files encrypted with a known offline key can sometimes be recovered with Emsisoft's free decryptor; files encrypted with a unique online key cannot be decrypted without the attacker's private key.
Rilasciato2022 (STOP/Djvu variant appeared around late June 2022)

Conversioni EIUR

Domande e risposte della community

chiesto dagli utenti
Fai una domanda veloce
Ottieni aiuto da persone che lavorano con i file EIUR. Sii specifico - includi il tuo sistema e la versione del software.
Nessun account necessario · risposte solitamente entro un giorno

Ancora nessuna domanda - sii il primo a chiedere informazioni sui file EIUR.

Domande frequenti

Posso aprire un file .eiur?
Non direttamente. I contenuti sono crittografati con Salsa20. È necessario prima decifrare il file con il decryptor Emsisoft STOP Djvu (solo se è stata utilizzata una chiave offline) o ripristinare una copia non crittografata da un backup.
I file .eiur sono decifrabili gratuitamente?
A volte. Se EIUR non ha potuto raggiungere il suo server durante la crittografia, ha utilizzato una chiave offline condivisa e lo strumento gratuito di Emsisoft può recuperare quei file. I file bloccati con una chiave online univoca non possono essere decifrati senza la chiave privata dell'attaccante.
Dovrei pagare il riscatto per riavere i miei file?
No. I ricercatori di sicurezza e FileInfo sconsigliano di pagare. Non c'è garanzia che i criminali inviino una chiave funzionante e il pagamento finanzia ulteriori attacchi. Prova prima il decryptor gratuito e i backup.
Come ho preso il ransomware EIUR?
EIUR si diffonde solitamente attraverso software crackato, generatori di chiavi, falsi programmi di installazione e download malevoli. Spesso installa contemporaneamente un trojan secondario per il furto di password.
Come faccio a rimuovere il ransomware EIUR stesso?
Esegui una scansione completa con un prodotto anti-malware affidabile come Malwarebytes per rilevare e mettere in quarantena l'eseguibile del ransomware e qualsiasi stealer incluso, quindi riavvia prima di tentare il recupero dei file.
Eliminare l'estensione .eiur ripristinerà il mio file?
No. Rinominare il file non cambia i contenuti crittografati. I dati rimangono cifrati finché non vengono decifrati correttamente con la chiave corrispondente.

Riferimenti

1Emsisoft - STOP Djvu decryption toolwww.emsisoft.com
2MyAntiSpyware - Remove Eiur ransomware, decrypt .eiur fileswww.myantispyware.com

Continua a esplorare

nel database

Migliori estensioni della settimana

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.BINCD/DVD Disc Image (BIN/CUE)
5.EXEWindows Executable (Portable Executable)
6.RPMSGRestricted Permission Message
7.MDMarkdown Document
8.DATProgram Data File (generic)
9.NOMEDIAAndroid No-Media Marker File
10.TXTPlain Text File

Estensioni correlate

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

Strumenti file gratuiti

Un identificatore di file e convertitore di immagini nel browser - tutto viene eseguito sul tuo dispositivo.

Apri la cassetta degli attrezzi

Sfoglia le estensioni dei file A-Z