Che cos'è il formato di file EIUR?
Un file .eiur è un file ordinario che è stato crittografato dal ransomware EIUR, una variante della diffusa famiglia STOP/Djvu. Questo ceppo è apparso intorno alla metà del 2022 e si comporta come i suoi numerosi simili, differendo principalmente per l'estensione di quattro lettere che aggiunge. Quando EIUR infetta un PC Windows, cifra documenti, foto, database e video con il cifrario Salsa20, protegge tale chiave con RSA-2048 e rinomina ogni file in modo che budget.xlsx diventi budget.xlsx.eiur. Successivamente, rilascia una richiesta di riscatto chiamata _readme.txt in ogni cartella interessata, richiedendo «$980» in Bitcoin (o «$490» entro 72 ore) e indicando gli indirizzi di contatto [email protected] e [email protected].
Per agire rapidamente, il malware crittografa solo i primi 150 KB di ogni file, motivo per cui i file di grandi dimensioni sono talvolta parzialmente intatti. La presenza di file .eiur indica che il ransomware è stato eseguito sulla macchina e potrebbe aver installato un trojan per il furto di password insieme al modulo di crittografia.
Sicurezza e incolumità
RISCHIO: HIGHA .eiur file is itself inert ciphertext, but its presence means active ransomware ran on the machine and may still be resident along with a bundled information-stealer such as RedLine or Vidar. Do not pay the ransom; there is no guarantee of a key and payment funds further attacks. Isolate the device, run a reputable anti-malware scan to remove the executable, then attempt recovery only from backups or the Emsisoft decryptor.
Dettagli del formato
in sintesiProgrammi che aprono file EIUR
Dettagli tecnici
specifiche approfondite| Encoding | Salsa20 stream cipher applied to file contents |
| Encryption | Salsa20 for data; the Salsa20 key is protected with RSA-2048. Each victim receives either a shared 'offline' key (used when the C2 server is unreachable) or a unique 'online' key fetched from the attacker server. |
| Byte order | N/A (opaque ciphertext) |
| Container | Original file wrapped with encrypted payload plus an appended block containing the encryption marker and victim key/ID data |
| Partial Encryption | Only the first 150 KB of each file is encrypted, which is why large files are sometimes partially recoverable or repairable |
| Typical size | Same as the original file plus a small appended overhead |
| Structure | Original data encrypted in-place at the start of the file, with a trailing signature and embedded key/personal-ID block; the '.eiur' extension is appended to the original filename (for example 'photo.jpg' becomes 'photo.jpg.eiur'). |
| Integrity | None; no integrity field is present |
| Ransom Note | _readme.txt dropped in every folder with encrypted files and on the desktop |
| Ransom Amount | USD 980, reduced to USD 490 if the victim contacts the attackers within 72 hours, payable in Bitcoin |
| Attacker Contacts | [email protected] and [email protected] |
| Malware Family | STOP/Djvu ransomware |
| Platforms | Windows |
| Notes | EIUR spreads through cracked software, key generators, fake installers and malicious downloads, and often bundles a secondary information-stealer (such as RedLine or Vidar). Files encrypted with a known offline key can sometimes be recovered with Emsisoft's free decryptor; files encrypted with a unique online key cannot be decrypted without the attacker's private key. |
| Rilasciato | 2022 (STOP/Djvu variant appeared around late June 2022) |
Conversioni EIUR
Domande e risposte della community
chiesto dagli utentiAncora nessuna domanda - sii il primo a chiedere informazioni sui file EIUR.