• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

ECh0raix Ransomware Strain QNAP NAS devices

5882

A new ransomware strain dubbed ‘eCh0raix’ which targets QNAP Network Attached Storage (NAS) devices used for backups and file storage was recently discovered by security researchers.

Written in Go language, eCh0raix is reported to have infected and encrypted documents on QNAP NAS devices, which is compromised upon the execution of the ransomware. The QNAP NAP devices are compromised by brute-forcing weak credentials and exploiting known vulnerabilities.

The impacted devices include QNAP TS-251, QNAP TS-451, QNAP TS-459 Pro II, and QNAP TS 253B.

Researchers analyzed the eCh0raix samples and noted that it uses the hardcoded public key, with a unique key for each target. The ransomware’s C&C server is located on Tor, however, it does not contain any Tor client to connect to it. Instead, the ransomware uses a SOCKS5 proxy that connects in order to communicate with the C&C server. The ransomware operators also created an API that can be used to query for various information.

The ransomware will then search for and kill the process such as apache2, httpd, nginx, mysqld, mysqd, and php-fpm, using service stop %s or systemctl stop %s commands.

eCh0raix is known to encrypt Microsoft Office and OpenOffice documents, PDFs, text files, archives, databases, photos, music, video, and image files using an AES in Cipher Feedback Mode (CFB) secret key created from an AES-256 key generated locally.

This AES key is then encrypted with the downloaded or embedded public RSA key and stored in base64 format in the ransom note. Upon encryption, the ransomware will append the .encrypt extension to the encrypted file's name.Worth noting

Tags:
james
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Forums in ECh0raix Ransomware Strain QNAP NAS devices

Related Forums in ECh0raix Ransomware Strain QNAP NAS devices

Scam (Ransomware)
jayden class=
Will ransome virus will affect linux server
May 16, 2017

Related News in ECh0raix Ransomware Strain QNAP NAS devices

Related News in ECh0raix Ransomware Strain QNAP NAS devices

CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
ECh0raix Ransomware Strain QNAP NAS devices
ECh0raix Ransomware Strain QNAP NAS devices
Jul 30, 2019
'The Nasty List' Instagram Phishing Scam Targets Instagram Credentials
'The Nasty List' Instagram Phishing Scam Targets Instagram Credentials
Apr 19, 2019
NIST Develops Guidelines For Dealing With Ransomware Recovery
NIST Develops Guidelines For Dealing With Ransomware Recovery
Sep 8, 2017
‘NamPoHyu Virus’ ransomware target vulnerable Samba servers
‘NamPoHyu Virus’ ransomware target vulnerable Samba servers
Apr 20, 2019
A Sneaky Ransomware That Seems Benificial. But Deceptive.
A Sneaky Ransomware That Seems Benificial. But Deceptive.
Apr 5, 2019
CrySIS ransomware targeting businesses is on the rise
CrySIS ransomware targeting businesses is on the rise
May 28, 2019
Wannacry attack is far from over – Experts
Wannacry attack is far from over – Experts
May 16, 2017
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Isaac ?
How to run windows application in linux

I need to run the windows application in my Linux machine, instead of installing from yum repo or any other repos. How to do that..??

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.