O que é o formato de ficheiro EIUR?
Um arquivo .eiur é um arquivo comum que foi criptografado pelo ransomware EIUR, uma variante da difundida família STOP/Djvu. Esta linhagem apareceu por volta de meados de 2022 e se comporta como seus muitos irmãos, diferindo principalmente na extensão de quatro letras que anexa. Quando o EIUR infecta um PC Windows, ele codifica documentos, fotos, bancos de dados e vídeos com a cifra Salsa20, protege essa chave com RSA-2048 e renomeia cada arquivo para que budget.xlsx se torne budget.xlsx.eiur. Ele então solta uma nota de resgate chamada _readme.txt em cada pasta afetada, exigindo «$980» em Bitcoin (ou «$490» em até 72 horas) e listando os endereços de contato [email protected] e [email protected].
Para trabalhar rapidamente, o malware criptografa apenas os primeiros 150 KB de cada arquivo, e é por isso que arquivos grandes às vezes ficam parcialmente intactos. Ver arquivos .eiur significa que o ransomware foi executado em sua máquina e pode ter instalado um trojan de roubo de senhas junto com o criptografador.
Segurança e proteção
RISCO: HIGHA .eiur file is itself inert ciphertext, but its presence means active ransomware ran on the machine and may still be resident along with a bundled information-stealer such as RedLine or Vidar. Do not pay the ransom; there is no guarantee of a key and payment funds further attacks. Isolate the device, run a reputable anti-malware scan to remove the executable, then attempt recovery only from backups or the Emsisoft decryptor.
Detalhes do formato
em resumoProgramas que abrem arquivos EIUR
Detalhes técnicos
especificação profunda| Encoding | Salsa20 stream cipher applied to file contents |
| Encryption | Salsa20 for data; the Salsa20 key is protected with RSA-2048. Each victim receives either a shared 'offline' key (used when the C2 server is unreachable) or a unique 'online' key fetched from the attacker server. |
| Byte order | N/A (opaque ciphertext) |
| Container | Original file wrapped with encrypted payload plus an appended block containing the encryption marker and victim key/ID data |
| Partial Encryption | Only the first 150 KB of each file is encrypted, which is why large files are sometimes partially recoverable or repairable |
| Typical size | Same as the original file plus a small appended overhead |
| Structure | Original data encrypted in-place at the start of the file, with a trailing signature and embedded key/personal-ID block; the '.eiur' extension is appended to the original filename (for example 'photo.jpg' becomes 'photo.jpg.eiur'). |
| Integrity | None; no integrity field is present |
| Ransom Note | _readme.txt dropped in every folder with encrypted files and on the desktop |
| Ransom Amount | USD 980, reduced to USD 490 if the victim contacts the attackers within 72 hours, payable in Bitcoin |
| Attacker Contacts | [email protected] and [email protected] |
| Malware Family | STOP/Djvu ransomware |
| Platforms | Windows |
| Notes | EIUR spreads through cracked software, key generators, fake installers and malicious downloads, and often bundles a secondary information-stealer (such as RedLine or Vidar). Files encrypted with a known offline key can sometimes be recovered with Emsisoft's free decryptor; files encrypted with a unique online key cannot be decrypted without the attacker's private key. |
| Lançado | 2022 (STOP/Djvu variant appeared around late June 2022) |
Conversões de EIUR
Perguntas e Respostas da Comunidade
perguntado por usuáriosAinda não há perguntas - seja o primeiro a perguntar sobre arquivos EIUR.