Aller au contenu principal
Groupe de rançongiciel

Ech0raix

The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences:1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint.2. Every victim is provided with a different, unique Bitcoin wallet—this could help the attackers avoid being traced.3. Once a victim is compromised, the malware requests a wallet address and a public RSA key from the command and control server (C&C) before file encryption.

Victimes connues0

Niveau de menace

FAIBLE

Infrastructure connue

Les services cachés Tor suivants ont été associés à ce groupe :

  • 404 page not found
  • 7zvu7njrx7q734kvk435ntuf37gfll2pu46fmrfoweczwpk2rhp444yd.onion

Attention : ces sites sont malveillants. Ne les visitez pas sans mesures de sécurité adaptées.

0

Vérifier si vous êtes touché

Cherchez dans notre base si votre organisation figure sur la liste des victimes de Ech0raix.

Essayez maintenantGratuit⌘K
Exemple

score de risque · catégories de menace · sources · ancienneté · confiance — en une requête

Autres groupes de rançongiciel actifs