raziel Posted November 22, 2020 Report Share Posted November 22, 2020 hi need help please my file are crypted by .xcrypt Link to comment Share on other sites More sharing options...
GT500 Posted November 22, 2020 Report Share Posted November 22, 2020 There might be more than one ransomware going by the name "XCrypt". Would it be possible to attach an encrypted file and a copy of the ransom note to a reply? Link to comment Share on other sites More sharing options...
raziel Posted November 22, 2020 Author Report Share Posted November 22, 2020 All the important files on your computer were encrypted. To decrypt the files you should send 0.26 BTC (~100euro) to Bitcoin address: 1D6FAZKhaURNM6V1eFVQEPx7Bv27PNvgwF and in the description field enter your email address. Then you will receive all necessary instructions. zCamera-2031.zip.xcrypt Link to comment Share on other sites More sharing options...
raziel Posted November 22, 2020 Author Report Share Posted November 22, 2020 i noticed that the conversion btc eur and very old so i think it is not a new virus Link to comment Share on other sites More sharing options...
raziel Posted November 22, 2020 Author Report Share Posted November 22, 2020 7 hours ago, GT500 said: There might be more than one ransomware going by the name "XCrypt". Would it be possible to attach an encrypted file and a copy of the ransom note to a reply? any help? Link to comment Share on other sites More sharing options...
GT500 Posted November 23, 2020 Report Share Posted November 23, 2020 I've asked one of our ransomware analysts for more information, however please note that I'm not finding any information on decryption so it may not be possible. Link to comment Share on other sites More sharing options...
raziel Posted November 23, 2020 Author Report Share Posted November 23, 2020 40 minutes ago, GT500 said: J'ai demandé plus d'informations à l'un de nos analystes de ransomware, mais veuillez noter que je ne trouve aucune information sur le décryptage, donc ce n'est peut-être pas possible. ok thanks i'm waiting to hear from you then. if you can give me the name of that ransomware, Link to comment Share on other sites More sharing options...
GT500 Posted November 24, 2020 Report Share Posted November 24, 2020 This ransomware has been around since late 2016, however I don't think it was very common as even our ransomware analysts don't have much information on it. They'll need a copy of the ransomware itself to figure out if it's decryptable or not. You wouldn't happen to know what malicious application encrypted your files, would you? If you do, then could you upload it to VirusTotal and send me a link to the analysis? Link to comment Share on other sites More sharing options...
raziel Posted November 24, 2020 Author Report Share Posted November 24, 2020 32 minutes ago, GT500 said: Ce ransomware existe depuis fin 2016, mais je ne pense pas que ce soit très courant car même nos analystes de ransomwares n'ont pas beaucoup d'informations à ce sujet. Ils auront besoin d'une copie du ransomware lui-même pour savoir s'il est déchiffrable ou non. Vous ne sauriez pas quelle application malveillante a chiffré vos fichiers, n'est-ce pas? Si c'est le cas, pouvez-vous le télécharger sur VirusTotal et m'envoyer un lien vers l'analyse? I don't think so but I will look Link to comment Share on other sites More sharing options...
raziel Posted November 24, 2020 Author Report Share Posted November 24, 2020 22 hours ago, raziel said: I don't think so but I will look https://mega.nz/file/JBkkkJza#WfJvhBzcS1C-2KCWVoxbrIudetAqC7vEALggcMdDJcU I think it's this file my son downloaded it 24/11/2020 11:19:59 Malware "Gen:Variant.MSILPerseus.196529 (B)" detected and blocked on behalf of chrome.exe Link to comment Share on other sites More sharing options...
GT500 Posted November 25, 2020 Report Share Posted November 25, 2020 Thanks. I've forwarded the link to our ransomware analyst so he can look at it. Link to comment Share on other sites More sharing options...
GT500 Posted November 26, 2020 Report Share Posted November 26, 2020 The file you shared with us isn't ransomware. It appears to swap cryptocurrency addresses in the clipboard (when copying and pasting) to redirect transactions. Link to comment Share on other sites More sharing options...
raziel Posted November 26, 2020 Author Report Share Posted November 26, 2020 8 hours ago, GT500 said: The file you shared with us isn't ransomware. It appears to swap cryptocurrency addresses in the clipboard (when copying and pasting) to redirect transactions. i see then you had no info or solution Link to comment Share on other sites More sharing options...
GT500 Posted November 28, 2020 Report Share Posted November 28, 2020 On 11/26/2020 at 8:32 AM, raziel said: i see then you had no info or solution Without a copy of the actual ransomware, I don't think we will be able to determine whether or not your files will be decryptable. Link to comment Share on other sites More sharing options...
raziel Posted March 16, 2021 Author Report Share Posted March 16, 2021 any news for .xcrypt???? Link to comment Share on other sites More sharing options...
GT500 Posted March 17, 2021 Report Share Posted March 17, 2021 13 hours ago, raziel said: any news for .xcrypt???? I don't think we ever received a sample to analyze. Link to comment Share on other sites More sharing options...
raziel Posted April 13, 2021 Author Report Share Posted April 13, 2021 i send it to you in pm sir Link to comment Share on other sites More sharing options...
GT500 Posted April 14, 2021 Report Share Posted April 14, 2021 12 hours ago, raziel said: i send it to you in pm sir Those are just encrypted files. Without the ransomware itself we can't figure out how the encryption process works. Link to comment Share on other sites More sharing options...
Amigo-A Posted April 14, 2021 Report Share Posted April 14, 2021 @raziel The easiest way to find out when files were encrypted is to look at the file's "Properties". Usually, the encryption is its last change and this will be the correct date. Among the programs published in the Digest "Crypto-Ransomware", there are three ransomware that used the word "xcrypt", but only one of them used the .xcrypt extension in its pure form. If the encryption date is closer than 2016, then it could be one of the other well-known ransomware that borrowed this extension. Link to comment Share on other sites More sharing options...
Recommended Posts