EIUR ファイル形式とは?
.eiurファイルは、広く蔓延しているSTOP/Djvuファミリーの亜種であるEIURランサムウェアによって暗号化された通常のファイルです。この系統は2022年中旬頃に出現し、他の多くの亜種と同様の動作をしますが、主に追加される4文字の拡張子が異なります。EIURがWindows PCに感染すると、ドキュメント、写真、データベース、ビデオをSalsa20暗号でスクランブル化し、そのキーをRSA-2048で保護し、budget.xlsxがbudget.xlsx.eiurになるように各ファイルの名前を変更します。その後、影響を受けたすべてのフォルダに_readme.txtという身代金要求メモを残し、ビットコインで«$980»(72時間以内なら«$490»)を要求し、連絡先アドレスとして[email protected]と[email protected]を記載します。
迅速に処理を行うため、このマルウェアは各ファイルの最初の150 KBのみを暗号化します。そのため、大きなファイルは部分的に無傷である場合があります。.eiurファイルが存在するということは、お使いのコンピュータでランサムウェアが実行されたことを意味し、暗号化プログラムと並行してパスワードを盗むトロイの木馬がインストールされた可能性があります。
セキュリティと安全性
リスク: HIGHA .eiur file is itself inert ciphertext, but its presence means active ransomware ran on the machine and may still be resident along with a bundled information-stealer such as RedLine or Vidar. Do not pay the ransom; there is no guarantee of a key and payment funds further attacks. Isolate the device, run a reputable anti-malware scan to remove the executable, then attempt recovery only from backups or the Emsisoft decryptor.
形式の詳細
概要EIUR ファイルを開くプログラム
技術的詳細
詳細仕様| Encoding | Salsa20 stream cipher applied to file contents |
| Encryption | Salsa20 for data; the Salsa20 key is protected with RSA-2048. Each victim receives either a shared 'offline' key (used when the C2 server is unreachable) or a unique 'online' key fetched from the attacker server. |
| Byte order | N/A (opaque ciphertext) |
| Container | Original file wrapped with encrypted payload plus an appended block containing the encryption marker and victim key/ID data |
| Partial Encryption | Only the first 150 KB of each file is encrypted, which is why large files are sometimes partially recoverable or repairable |
| Typical size | Same as the original file plus a small appended overhead |
| Structure | Original data encrypted in-place at the start of the file, with a trailing signature and embedded key/personal-ID block; the '.eiur' extension is appended to the original filename (for example 'photo.jpg' becomes 'photo.jpg.eiur'). |
| Integrity | None; no integrity field is present |
| Ransom Note | _readme.txt dropped in every folder with encrypted files and on the desktop |
| Ransom Amount | USD 980, reduced to USD 490 if the victim contacts the attackers within 72 hours, payable in Bitcoin |
| Attacker Contacts | [email protected] and [email protected] |
| Malware Family | STOP/Djvu ransomware |
| Platforms | Windows |
| Notes | EIUR spreads through cracked software, key generators, fake installers and malicious downloads, and often bundles a secondary information-stealer (such as RedLine or Vidar). Files encrypted with a known offline key can sometimes be recovered with Emsisoft's free decryptor; files encrypted with a unique online key cannot be decrypted without the attacker's private key. |
| リリース日 | 2022 (STOP/Djvu variant appeared around late June 2022) |
EIUR の変換
コミュニティ Q&A
ユーザーからの質問まだ質問はありません。EIUR ファイルについて最初の質問をしてみましょう。