Qnap Ransomware
#14
(22-04-2021, 07:51 PM)DonPeter Wrote: Buenas, os dejo info del twitter de QNAP: https://twitter.com/QNAPEspana/status/13...8991011840

Además indicar que, si os ha entrado a alguno podéis intentar:

1. Do NOT REBOOt NAS , you can pass all steps if you already did
2. Connect nas over ssh
3. Use the command below to find if ransomware is in progress.
ps | grep 7z
4. If 7z is running, run command bellow
cd /usr/local/sbin; printf '#!/bin/sh \necho $@\necho $@>>/mnt/HDA_ROOT/7z.log\nsleep 60000' > 7z.sh; chmod +x 7z.sh; mv 7z 7z.bak; mv 7z.sh 7z;
5. Wait couple minutes use cat to grep encrypt key
cat /mnt/HDA_ROOT/7z.log
Looks like bellow
a -mx=0 -sdel -pmFyBIvp55M46kSxxxxxYv4EIhx7rlTD [FOLDER PATH]
mFyBIvp55M46kSxxxxxYv4EIhx7rlTD is decrypt password
6. Reboot nas and use mFyBIvp55M46kSxxxxxYv4EIhx7rlTD decrypt your files

Si lo veis complicado abrir un ticket desde service.qnap.com

Saludos!!


Buenas yo he sido infectado tambien por el Ransomware. He intentado seguir los pasos que indicas pero cuando llego al punto 4 (porque tengo el 7z corriendo) me indica lo siguiente: 

-sh: 7z.sh: Permission denied
chmod: 7z.sh: No such file or directory
mv: can`t rename '7z': Permission denied
mv: overwrite '7z'? (Escribo yes)
mv: can't rename '7z.sh': No such file or directory

¿Tenéis idea de porque ocurre?

Gracias y saludos,
  Reply


Messages In This Thread
Qnap Ransomware - by JLMG1989 - 21-04-2021, 10:41 AM
RE: Qnap Ransomware - by Ganekogorta - 21-04-2021, 12:30 PM
RE: Qnap Ransomware - by JLMG1989 - 21-04-2021, 04:12 PM
Qnap Ransomware - by Ganekogorta - 21-04-2021, 04:22 PM
RE: Qnap Ransomware - by Oficina - 21-04-2021, 04:28 PM
RE: Qnap Ransomware - by JLMG1989 - 21-04-2021, 06:10 PM
Qnap Ransomware - by Ganekogorta - 21-04-2021, 08:19 PM
RE: Qnap Ransomware - by DonPeter - 22-04-2021, 07:51 PM
RE: Qnap Ransomware - by Alvarosie - 23-04-2021, 03:28 PM
RE: Qnap Ransomware - by Tachu - 22-04-2021, 08:49 PM
RE: Qnap Ransomware - by DonPeter - 22-04-2021, 09:03 PM
RE: Qnap Ransomware - by Tachu - 23-04-2021, 11:20 AM
RE: Qnap Ransomware - by DonPeter - 23-04-2021, 02:19 PM
RE: Qnap Ransomware - by JLMG1989 - 23-04-2021, 01:34 PM
RE: Qnap Ransomware - by DonPeter - 23-04-2021, 04:51 PM
RE: Qnap Ransomware - by Alvarosie - 24-04-2021, 07:55 PM
RE: Qnap Ransomware - by Oroimenak - 24-04-2021, 10:02 AM
Qnap Ransomware - by Ganekogorta - 24-04-2021, 10:38 AM
RE: Qnap Ransomware - by Oroimenak - 24-04-2021, 12:26 PM
Qnap Ransomware - by Ganekogorta - 24-04-2021, 01:55 PM
RE: Qnap Ransomware - by Oroimenak - 24-04-2021, 02:10 PM
Qnap Ransomware - by Ganekogorta - 24-04-2021, 03:04 PM
RE: Qnap Ransomware - by Sphera - 25-04-2021, 04:47 PM
RE: Qnap Ransomware - by Moreno - 25-04-2021, 06:51 PM
RE: Qnap Ransomware - by Sphera - 25-04-2021, 08:05 PM
RE: Qnap Ransomware - by Moreno - 25-04-2021, 08:27 PM
RE: Qnap Ransomware - by Sphera - 25-04-2021, 08:40 PM
Qnap Ransomware - by Ganekogorta - 25-04-2021, 08:09 PM
RE: Qnap Ransomware - by Moreno - 25-04-2021, 08:44 PM
Qnap Ransomware - by Ganekogorta - 25-04-2021, 10:20 PM
RE: Qnap Ransomware - by monchang - 28-04-2021, 12:55 AM
RE: Qnap Ransomware - by Moreno - 28-04-2021, 09:52 AM
RE: Qnap Ransomware - by monchang - 28-04-2021, 07:18 PM
Qnap Ransomware - by Ganekogorta - 28-04-2021, 06:20 AM
RE: Qnap Ransomware - by Oroimenak - 28-04-2021, 07:22 PM
Qnap Ransomware - by Ganekogorta - 28-04-2021, 07:27 PM
RE: Qnap Ransomware - by Oroimenak - 28-04-2021, 07:28 PM
Qnap Ransomware - by monchang - 28-04-2021, 07:29 PM
RE: Qnap Ransomware - by Tachu - 28-04-2021, 07:54 PM
Qnap Ransomware - by Ganekogorta - 28-04-2021, 08:00 PM
RE: Qnap Ransomware - by Tachu - 28-04-2021, 08:12 PM
RE: Qnap Ransomware - by Miguel Sareo Sanchez - 02-08-2021, 10:31 AM
Qnap Ransomware - by Ganekogorta - 22-09-2021, 07:33 PM



Users browsing this thread: 4 Guest(s)