Co to jest format pliku EIUR?
Plik .eiur to zwykły plik, który został zaszyfrowany przez ransomware EIUR, wariant rozpowszechnionej rodziny STOP/Djvu. Ten szczep pojawił się około połowy 2022 roku i zachowuje się jak jego liczni krewni, różniąc się głównie czteroiterowym rozszerzeniem, które dodaje. Gdy EIUR zainfekuje komputer z systemem Windows, szyfruje dokumenty, zdjęcia, bazy danych i filmy za pomocą szyfru Salsa20, chroni ten klucz za pomocą RSA-2048 i zmienia nazwę każdego pliku, tak że budget.xlsx staje się budget.xlsx.eiur. Następnie w każdym zainfekowanym folderze umieszcza żądanie okupu o nazwie _readme.txt, żądając „980 $” w Bitcoinach (lub „490 $” w ciągu 72 godzin) i podając adresy kontaktowe [email protected] oraz [email protected].
Aby działać szybko, złośliwe oprogramowanie szyfruje tylko pierwsze 150 KB każdego pliku, dlatego duże pliki są czasami częściowo nienaruszone. Pojawienie się plików .eiur oznacza, że na Twoim komputerze zostało uruchomione oprogramowanie ransomware, które mogło zainstalować trojana kradnącego hasła wraz z modułem szyfrującym.
Bezpieczeństwo
RYZYKO: HIGHA .eiur file is itself inert ciphertext, but its presence means active ransomware ran on the machine and may still be resident along with a bundled information-stealer such as RedLine or Vidar. Do not pay the ransom; there is no guarantee of a key and payment funds further attacks. Isolate the device, run a reputable anti-malware scan to remove the executable, then attempt recovery only from backups or the Emsisoft decryptor.
Szczegóły formatu
w pigułceProgramy otwierające pliki EIUR
Szczegóły techniczne
specyfikacja| Encoding | Salsa20 stream cipher applied to file contents |
| Encryption | Salsa20 for data; the Salsa20 key is protected with RSA-2048. Each victim receives either a shared 'offline' key (used when the C2 server is unreachable) or a unique 'online' key fetched from the attacker server. |
| Byte order | N/A (opaque ciphertext) |
| Container | Original file wrapped with encrypted payload plus an appended block containing the encryption marker and victim key/ID data |
| Partial Encryption | Only the first 150 KB of each file is encrypted, which is why large files are sometimes partially recoverable or repairable |
| Typical size | Same as the original file plus a small appended overhead |
| Structure | Original data encrypted in-place at the start of the file, with a trailing signature and embedded key/personal-ID block; the '.eiur' extension is appended to the original filename (for example 'photo.jpg' becomes 'photo.jpg.eiur'). |
| Integrity | None; no integrity field is present |
| Ransom Note | _readme.txt dropped in every folder with encrypted files and on the desktop |
| Ransom Amount | USD 980, reduced to USD 490 if the victim contacts the attackers within 72 hours, payable in Bitcoin |
| Attacker Contacts | [email protected] and [email protected] |
| Malware Family | STOP/Djvu ransomware |
| Platforms | Windows |
| Notes | EIUR spreads through cracked software, key generators, fake installers and malicious downloads, and often bundles a secondary information-stealer (such as RedLine or Vidar). Files encrypted with a known offline key can sometimes be recovered with Emsisoft's free decryptor; files encrypted with a unique online key cannot be decrypted without the attacker's private key. |
| Wydano | 2022 (STOP/Djvu variant appeared around late June 2022) |
Konwersje EIUR
Pytania i odpowiedzi społeczności
pytania użytkownikówBrak pytań - bądź pierwszą osobą, która zapyta o pliki EIUR.