Deadbolt ransomware

Backup and data protection discussion at its finest.

Moderator: Lillian.W@AST

Post Reply
bazuev
Posts: 3
youtube meble na wymiar Warszawa
Joined: Sun Oct 18, 2015 4:15 am

Re: Deadbolt ransomware

Post by bazuev »

Hi everybody,

Just to be clear. It looks like I was not affected by this ransomware on my AS-604T. I upgraded ADM and followed Asustor's recommendations to prevent this attack.

But today I found the following line in hosts file on a Windows PC in my network pointing to IP address of my NAS:
192.168.1.3 ASTEncryptIP1

I did not find any useful information in the web about that.

The file's date is August 19, 2019. But it could be just falsified.

Could anyone affected by Deadbolt ransomware check if you have similar lines in C:\Windows\System32\drivers\etc\hosts file on Windows machines please?
Moromoro
Posts: 5
Joined: Sat Mar 12, 2022 5:12 am

Re: Deadbolt ransomware

Post by Moromoro »

bazuev wrote:
Moromoro wrote:Hi, I can't find the ransomware status App from app central , can anyone advice how to get it as I can't see the information message for that attack and all my data is locked .
Thank you.
They provide a direct link for this app on the instruction page: https://www.asustor.com/knowledge/detail/?group_id=630

https://downloadgb.asustor.com/download ... r0_any.apk

Not sure why not just upload it to App Central. :?

Thank you, Asustor removed it from the app central "they told me that this was for security purpose :x
Moromoro
Posts: 5
Joined: Sat Mar 12, 2022 5:12 am

Re: Deadbolt ransomware

Post by Moromoro »

Hi All, did anyone Pay the ransomware and received the decryption key? I appreciate if you can share the steps . thank you.
Lobster
Posts: 27
Joined: Tue Feb 22, 2022 10:18 pm

Re: Deadbolt ransomware

Post by Lobster »

It might be worth having a look through the /asustor sub-reddit, there's been some people that have supposedly paid that have posted there. I am not in any way suggesting they are telling the truth mind you, the internet is now full of secondary scams built off of the back of the Deadbolt hit.
outside79
Posts: 11
Joined: Mon Feb 28, 2022 12:39 am

Re: Deadbolt ransomware

Post by outside79 »

i got everything i need to unlock, except. i cant hit unlock button, people seem to have made this work, but this is just wierd.
both qnap users and asustor users have been able to unlock. so what the fuck is wrong right now?
Attachments
Firefox_Screenshot_2022-04-27T22-32-34.880Z.png
Firefox_Screenshot_2022-04-27T22-32-34.880Z.png (73.74 KiB) Viewed 4251 times
Moromoro
Posts: 5
Joined: Sat Mar 12, 2022 5:12 am

Re: Deadbolt ransomware

Post by Moromoro »

outside79 wrote:i got everything i need to unlock, except. i cant hit unlock button, people seem to have made this work, but this is just wierd.
both qnap users and asustor users have been able to unlock. so what the fuck is wrong right now?
you may try Emsisoft to decrypt the data ,

https://www.emsisoft.com/ransomware-dec ... s/deadbolt
SlyBrutal
Posts: 9
Joined: Wed Mar 02, 2022 3:43 pm

Re: Deadbolt ransomware

Post by SlyBrutal »

Moromoro wrote:Hi All, did anyone Pay the ransomware and received the decryption key? I appreciate if you can share the steps . thank you.
Hi,
Around page 33-34 you will find how to pay, I have already described it there once.
Moromoro
Posts: 5
Joined: Sat Mar 12, 2022 5:12 am

Re: Deadbolt ransomware

Post by Moromoro »

SlyBrutal wrote:
Moromoro wrote:Hi All, did anyone Pay the ransomware and received the decryption key? I appreciate if you can share the steps . thank you.
Hi,
Around page 33-34 you will find how to pay, I have already described it there once.
Thank you
Pilloso
Posts: 19
Joined: Tue Feb 02, 2016 6:32 pm

Re: Deadbolt ransomware

Post by Pilloso »

Hello, i followed the solution from Asustor:
https://www.asustor.com/en-gb/knowledge ... oup_id=630

Everything seems fine, but how can I be sure the Nas is clean of viruses?
Is it enough to update ADM, disable services and change ports?
ov2rey
Posts: 26
Joined: Fri Aug 05, 2016 11:13 am

Re: Deadbolt ransomware

Post by ov2rey »

Hi everyone, today my Nas was attacked and this is my second times.... Using latest firmware
dead.jpg
dead.jpg (248.77 KiB) Viewed 3972 times
Post Reply

Return to “Backup and Data Protection”