Kiran2020

Mpaj Extension to All Photos, Videos, Document

Recommended Posts

Hello Team,

My whole life photos, videos, documents got affected by Mpaj extension. 

Adding sample files for reference. 

No key for New Variant offline ID: RNDHQwNS07HCo9nNdWwsQzumCtR12dC9OhcDrut1


Notice: this ID appears be an offline ID, decryption MAY be possible in the future

Will be great if someone help.

_readme.txt 3_ASR_VillageList_Pune.pdf.mpaj

Share this post


Link to post
Share on other sites
5 hours ago, Kiran2020 said:

No key for New Variant offline ID: RNDHQwNS07HCo9nNdWwsQzumCtR12dC9OhcDrut1

This is a newer variant of STOP/Djvu. Fortunately your ID is an offline ID, however we don't yet have the private key for it. I recommend running the decrypter once every week or two so that you can see when we've been able to add the private key for your variant.

There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Share this post


Link to post
Share on other sites
4 hours ago, GT500 said:

This is a newer variant of STOP/Djvu. Fortunately your ID is an offline ID, however we don't yet have the private key for it. I recommend running the decrypter once every week or two so that you can see when we've been able to add the private key for your variant.

There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

 

 

Thank u. 

 

Sir do I have need to send any files for testing. Some of files I have original n infected to. 

 

If you guide will be more thank ful. 

Share this post


Link to post
Share on other sites
17 hours ago, Kiran2020 said:

Sir do I have need to send any files for testing. Some of files I have original n infected to. 

No. We have access to any variants of the STOP ransomware that we need for analysis.

Share this post


Link to post
Share on other sites

One more thing wanted to bring to your notice that in my PC I have video files with MPEG extension. That wont affected by this MPAJ. 

 

That video files are playing directly without changing there original extensions. So is there is use of this information?

 

Please find sample infected files here.

 

Please confirm.

3_ASR_VillageList_Pune.pdf.mpaj NameChangeAppFormEng.pdf.mpaj IMG-20160801-WA0013.jpg.mpaj

Share this post


Link to post
Share on other sites
19 hours ago, Kiran2020 said:

So is there is use of this information?

This is already known. The reason this is happening is because the STOP/Djvu ransomware only encrypts a small portion of the beginning of files, and some file formats that are tolerant of damaged data and you will only see a small amount of missing data at the beginning of files. Many types of files are not tolerant of damaged data at the beginning of files, so only certain types of files can be recovered this way.

  • Like 1

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.