360fans168281990 发表于 2019-8-20 15:44

新型外国勒索病毒,后缀为.nuksus

常规操作,先放文本:
ATTENTION!

Don't worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:

病毒作者发布的解锁一个文件的工具地址we。tl/t-6tYZko8NMj

Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail

gorentos爱特bitmessage.ch
Reserve e-mail address to contact us:
gorentos2爱特firemail.cc

Your personal ID:
149HylDhsHtIPJ8JyUSRLIOSt2XVXWXwOIpW6SpkiCMhoQrSiDQ


不过查看十六位参数后发现解锁序列就包含于程序中
I D :IPJ8JyUSRLIOSt2XVXWXwOIpW6SpkiCMhoQrSiDQ
Key:{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
把这条149HylDhsHtIPJ8JyUSRLIOSt2XVXWXwOIpW6SpkiCMhoQrSiDQ
分解就是
149HylDhsHt

IPJ8JyUSRLIOSt2XVXWXwOIpW6SpkiCMhoQrSiDQ
这样应该就算获得病毒的特征了,然后就下载病毒的解锁软件,把key输入就完事了
值得一提,360居然对这种te没法破解。。。

360fans168281990 发表于 2019-8-20 15:54

额外说明:该病毒可能为.djvuu的变种,而.djvuu又是Stop勒索病毒系列的一员

360fans168281990 发表于 2019-8-20 16:13

所以对该类型病毒首先要进行短网,并采用16进制编辑器获得的离线key进行解密

360fans_fnsG8v 发表于 2019-8-21 15:29

你是怎么解决的,中了和你的同款

360fans_fnsG8v 发表于 2019-8-21 15:35

后缀名是masodas

360工作人员-驱动哥 发表于 2019-8-21 16:36

您好 您反馈的病毒加密格式卫士支持解密, 如果遇到问题可以添加我们的qq群处理 204724586
页: [1]
查看完整版本: 新型外国勒索病毒,后缀为.nuksus