s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.qnapcrypt

📛 Threat Title

Malware family: QNAPCrypt

Category: QNAPCrypt First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.qnapcrypt`. Printable name: QNAPCrypt. Aliases: eCh0raix.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.qnapcrypt VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.qnapcrypt

IOC database

Type
domain
Value
elf.qnapcrypt
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.qnapcrypt

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.qnapcrypt

References (1)

Remediations (10)

  • web:elastio.com

    QNAPCrypt Ransomware QNAPCrypt is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on May 31, 2019, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: QNAPCrypt , QNAP-NAS-Encrypt, Synology-NAS-Encrypt, eCh0raix.

  • web:github.com

    Ech0raix decryptor. Contribute to vricosti/ech0raix_decryptor development by creating an account on GitHub.

  • web:link.springer.com

    In today’s world, cloud services and NAS devices are gaining progressively more attention. Both private users and large organizations use NAS servers to create personal clouds. Because of this trend, cybercriminals are targeting many ransomware attacks on NAS...

  • web:malpedia.caad.fkie.fraunhofer.de

    The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences: 1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint. 2. Every victim is provided with a different, unique Bitcoin wallet—this ...

  • web:nordvpn.com

    Also known as: QNAPCrypt Category: Malware Type: Ransomware Platform: Linux-based QNAP and Synology NAS devices Variants: QNAPCrypt (the original form of eCh0raix) and SynoLocker. It has been linked to the CVE-2021-28799 vulnerability. Damage potential: Data encryption, data theft, operational disruption, financial loss, reputational damage, and network compromise. Overview eCh0raix is a ...

  • web:www.askwoody.com

    The eCh0raix ransomware, also called QNAPCrypt , has a new variant that can now infect both QNAP as well as Synology Network-attached Storage (NAS) devices according to a report by security researchers Palo Alto Networks. Palo Alto first spotted the new eCh0raix back in September last year.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.ransomlook.io

    Description The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences: 1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint. 2. Every victim is provided with a different, unique Bitcoin ...

  • web:www.securityweek.com

    A recently observed ransomware family is targeting Linux-based file storage systems (NAS servers) made by QNAP, Intezer's security researchers reveal. Dubbed QNAPCrypt , the threat targets said NAS servers in an attempt to encrypt files on them and hold them for ransom. Currently featuring a very low detection rate, the malware is likely the work of the authors of Linux.Rex. Intezer has ...

  • web:www.zdnet.com

    QNAPCrypt targets Linux, SunCrypt targets Windows and both have different methodologies of distribution and tactics - but researchers say they started life as the same thing and there's lessons to ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.