Bitcoin Ransomware


Recommended Posts

Luckily, it seems the encryption keys have been found and there is a tool to decrypt .wallet files and retrieve your data.

 

https://www.bleepingcomputer.com/news/security/wallet-ransomware-master-keys-released-on-bleepingcomputer-avast-releases-free-decryptor/

 

That link will give you the fine details/instructions, here are mine in short form

 

Download this tool: http://files.avast.com/files/decryptor/avast_decryptor_crysis.exe

 

Run it, this will take a while, and hopefully your files are back. There is one point when running the program where there are two check mark boxes, leave both checked when you run the scan.

 

 

Kaspersky also has a tool to decrypt wallet files, http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip I would probably give Kaspersky a shot first, as it is newer, however both should do the job just fine.

Just now, Circaflex said:

Luckily, it seems the encryption keys have been found and there is a tool to decrypt .wallet files and retrieve your data.

 

https://www.bleepingcomputer.com/news/security/wallet-ransomware-master-keys-released-on-bleepingcomputer-avast-releases-free-decryptor/

 

That link will give you the fine details/instructions, here are mine in short form

 

Download this tool: http://files.avast.com/files/decryptor/avast_decryptor_crysis.exe

 

Run it, this will take a while, and hopefully your files are back. There is one point when running the program where there are two check mark boxes, leave both checked when you run the scan.

Is it recommended to wipe / reimage the system after or do tools like malware bytes and the decryption software do a good enough job? 

Just now, Edrick Smith said:

Is it recommended to wipe / reimage the system after or do tools like malware bytes and the decryption software do a good enough job? 

If it were my machine, or a friends, I would wipe and start over, however if you like a good project and are tech savvy enough to replace system files, you can probably fix it enough with Malwarebytes and some manual repair. Totally up to you, everyone values their time differently.

3 minutes ago, Edrick Smith said:

The avast tool is coming back with Invalid Password or decryption key. 

 

it says [[email protected]]-id-BAC_wallet 

Give the Kaspersky tool a try, I believe it was a little newer.

 

http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip

According to that link via the email method as I've stepped away from the computer right now it says based on that email address. However the extensions it list for the BTCWARE don't match my .wallet

 

BTCWare PayDay

 This ransomware has no known way of decrypting data at this time.

It is recommended to backup your encrypted files, and hope for a solution in the future.

Identified by

ransomnote_email: [email protected]

Click here for more information about BTCWare PayDay

Just now, Edrick Smith said:

According to that link via the email method as I've stepped away from the computer right now it says based on that email address 

 

BTCWare PayDay

 This ransomware has no known way of decrypting data at this time.

It is recommended to backup your encrypted files, and hope for a solution in the future.

Identified by

ransomnote_email: [email protected]

Click here for more information about BTCWare PayDay

Did you upload a sample encrypted file?  

ok, you may have the same thing as this poor gent (new BTCWare variant with .wallet extension) ...

 

https://www.bleepingcomputer.com/forums/t/668054/new-btcwware-variant-with-wallet-extension/

 

Which, if it is a newer variant ... according to Bleeping Computer:

"Unfortunately, newer variants of BTCWare are AES-256 versions of the malware which uses a different RSA-1024 key and are not decryptable unless you pay the ransom and get the private AES key from the criminals. There is no way to bruteforce the key for any of these versions."

 

If the encrypted file sample comes back with the same ransomware variant ... yea ... you may want to take a look at Bleeping Computer.  Obviously, don't pay the ransom but you may have to blow up the hard drive.

 

Edit:  I really wish Microsoft would release some sort of preventative measures for this crud.  Not sure how they can ... but dang if this wouldn't tick me off to no end.  Some are getting installed via brute force of RDP.  /rant off

3 hours ago, Jim K said:

I really wish Microsoft would release some sort of preventative measures for this crud.  Not sure how they can ... but dang if this wouldn't tick me off to no end.  Some are getting installed via brute force of RDP.  /rant off

 

Who puts RDP Internet facing? VPN + RDP is the only way I roll.

50 minutes ago, Edrick Smith said:

I've uploaded a file and the txt instruction file and it confirmed it is as listed above and no method of unlocking. 

I don't want to say you're SOL ... but I think you're kinda SOL.  If there isn't a decrypter ... then the only thing you can do is hold out and hope one becomes available or blast the drive (when in doubt ... C4 ...though it might be overkill).  

 

Someone might have a better opinion ... or you could pose the question at Bleeping and see what they say.  But no decrypter=no files.

Hello,

 

Contact the anti-malware company whose software is on the client's box, and explain the situation to them.  They should tell you what artefacts (forensic info like logs, samples of encrypted files,  copy of ransomware note, wallpaper, etc.) that they need in order to tell you whether or not the system can currently be decrypted.  Even if the answer is "no" right now, it may be possible some event in the future allows for decryption in the future.  I'd also suggest removing the drive and putting a new one in, as that leaves the old drive with its encrypted files intact if needed in the for insurance and legal purposes.

 

Regards,

 

Aryeh Goretsky

  • Like 2
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • To give context to everybody, I bought about 2 sets of RAM, ddr4, 3200, 64 gb, 2 years ago. It costed me 150 usd for each set. If you buy RAM now you only incentivate companies to sell you expensive stuff, as Nvidia did.
    • KillerPDF 1.4.2 by Razvan Serea KillerPDF is a lightweight, portable PDF editor for Windows built for users who want full control without subscriptions, installers, or telemetry. It runs as a single executable, making it ideal for USB use and field work. You can view PDFs with smooth PDFium rendering, navigate quickly with thumbnails, zoom, and shortcuts, and reorganize pages using drag-and-drop. It supports merging multiple PDFs, splitting documents, and extracting selected pages. KillerPDF also allows inline text editing with font matching to preserve the original layout, plus annotations like text boxes, freehand drawing, highlights, and reusable signatures. You can search full text, copy content easily, and print documents with flattened annotations. Designed as a free and open alternative to bloated PDF tools, it works fully offline on Windows 10/11 x64. No runtimes install. Everything needed is inside the EXE (targets .NET Framework 4.8, which ships with every supported Windows release). KillerPDF key features: High-quality PDF rendering via PDFium Edit PDF text inline (double-click to modify text) Page thumbnails and fast navigation with zoom and shortcuts Merge multiple PDFs into one Split PDFs and extract selected pages Drag-and-drop page reordering Font matching to preserve original document appearance Text boxes for notes Freehand drawing tools Highlight overlays with adjustable color, size, opacity Undo actions and clear per-page annotations Create, draw, and save reusable signatures Click-to-place signatures anywhere Full-text search with highlighted results Drag-select or Ctrl+A to copy text Print with annotations flattened Portable single-file app (~10 MB) No installer, no admin rights required No account, no telemetry KillerPDF 1.4.2 changelog: What's new PDF form filling. Interactive PDF forms now render their fields (text inputs, checkboxes, radio buttons) as live controls. Fill them in directly and save — field values are written back into the PDF. PDF outline (bookmark) navigation. A new OUTLINES tab in the sidebar displays the document's bookmark tree. Click any entry to jump to that page. The sidebar auto-fits its width to the longest entry on open and can be dragged wider; switching back to PAGES snaps to the pages-mode width. Fixed Page rotation no longer reverts after saving. Rotations applied via the sidebar context menu now persist correctly through the save pipeline. Copied text words were out of order on PDFs where glyphs are stored in non-reading order (Issue #66). Text extraction now sorts words by position and uses a dynamic line-grouping threshold so both drag-select and Select All produce correctly ordered output. PDFs with malformed or non-standard XRef tables now open in read-only mode instead of showing "Invalid entry in XRef table" and failing entirely. Download: KillerPDF 1.4.2 | 6.1 MB (Open Source) Link: KillerPDF Home Page | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • "...a low price of just $340..." I don't think it means what you think it means.
    • This Corsair Vengeance DDR5-6000 32GB RAM with RGB is a great deal for limited time by Sayan Sen Memory prices have been through the roof for a while, though it seems like things might finally be getting better. If you are in the market for one, then grab this Corsair Vengeance DDR5 32GB (2x16GB) DDR5 6000 CL36 kit with RGB for a low price of just $340 (purchase link under the specs table down below). The kit is compatible with both AMD and Intel systems as it supports both EXPO and XMP overclocking profiles, respectively. 6000 MT/s is often the sweet spot for many systems as it provides ample data transfer speed while still being on Gear 1 mode. This Vengeance variant has RGB so if you love bright setups with such lighting, this is a win-win for you. The technical specifications of the Corsair Vengeance memory kit are given in the table below: Specification Value Memory Type DDR5 Memory Size (Total) 32GB Kit Configuration 2 × 16GB Form Factor UDIMM (Desktop) Pin Count 288-pin Speed (Data Rate) 6000 MT/s Speed Rating PC5-48000 Tested CAS Latency 38-44-44-96 Voltage (Tested) 1.35V Performance Profile AMD EXPO & Intel XMP Heat Spreader Aluminum heatspreader Cooling Type Passive (Heatsink) Lighting Ten Zone RGB Software Support Corsair iCUE Get it at the link below: CORSAIR Vengeance RGB DDR5 32GB (2 x 16GB) 6000 CL38 – Gray (CMH32GX5M1E6000Z38): $339.99 (Sold and Shipped by Woot US, Fulfilled by Amazon US) This Woot deal is US-specific and not available in other regions unless specified. This is a first-party seller link (at the time of article publishing); ensure that you also purchase from a first-party seller link only. If you don't like it or want to look at more options, check out the previous deals that we have covered, OR you can also visit Amazon US deals page. Get Prime (SNAP), Prime Video, Audible Plus or Kindle / Music Unlimited. Free for 30 days. As an Amazon Associate, we earn from qualifying purchases.
    • The very fact that a TPM (v2.0 specifically which is part of the issue I suspect) is now a baseline for any supported Windows installation will naturally mean other vendors will start to leverage it as they know it'll be there. It's called progress, and it's always been the way. A TPM isn't a windows thing, it's just a module designed to securely store keys. Secure boot isn't a Windows thing (although MS are the TCA as I recall hence the upheaval this year as the 2011 certs expire), it's just a way to verify a bootloader is signed. Windows simply leverages them.
  • Recent Achievements

    • Proficient
      Eric Biran went up a rank
      Proficient
    • Dedicated
      Conjor earned a badge
      Dedicated
    • Week One Done
      Windows Guy earned a badge
      Week One Done
    • Dedicated
      Mark Spruce earned a badge
      Dedicated
    • Collaborator
      conkir earned a badge
      Collaborator
  • Popular Contributors

    1. 1
      +primortal
      479
    2. 2
      PsYcHoKiLLa
      244
    3. 3
      Steven P.
      72
    4. 4
      +Edouard
      66
    5. 5
      Skyfrog
      65
  • Tell a friend

    Love Neowin? Tell a friend!