[RANSOMWARE] >>READ 1st Post<< Deadbolt

Introduce yourself to us and other members here, or share your own product reviews, suggestions, and tips and tricks of using QNAP products.
Post Reply
alexhjones
New here
Posts: 8
Joined: Fri Oct 28, 2016 5:52 pm

Re: [RANSOMWARE] Deadbolt

Post by alexhjones »

mikaux wrote: Wed Jan 26, 2022 6:59 pm Hi There. Is there any way you can post a 'How To' for the actions you have taken. Many of us have no real experience, or limited with SSH and although I can get in that way, I dont know what to do once in. That is I dont know how to get into the file structure to find the files you found
I'd suggest waiting for official instructions before trying this straight away, although it is promising that the Deadbolt page was displayed yet the files weren't encrypted yet.

I got the Deadbolt page on my QNAP this morning and powered off the NAS. I just checked an external USB drive which appears to have not been affected. I'm going to wait for way to check the internal drives (/ some other method) and keep my fingers crossed the files aren't fully encrypted.
jswain
New here
Posts: 9
Joined: Tue Jul 05, 2016 5:32 pm

Re: [RANSOMWARE] Deadbolt

Post by jswain »

So many of my files are now encrypted with the .deadbolt extension, this is so depressing!

Its all so well saying to disconnect from the internet to avoid this happening but i bought it for that very use, otherwise i may as well of just used a USB HDD.

Lets hope there is a guide available to get rid of it soon :(
lknanml
First post
Posts: 1
Joined: Wed Jan 26, 2022 7:33 pm

Re: [RANSOMWARE] Deadbolt

Post by lknanml »

Yep.. Lost every single digital movie I have.
Videos for work as well. I REALLY hope we get a fix for this.
Videos from 3 overseas deployments...
I could eventually replace my movies but those files are impossible to replace.
I thought I had setup the NAS for local share. Guess I missed something. I was hours and hours away from the NAS. By the time I got home it was over. Everything had the deadbolt ext.
Last edited by lknanml on Wed Jan 26, 2022 8:24 pm, edited 1 time in total.
Vogstar
Starting out
Posts: 13
Joined: Sat Aug 26, 2017 9:33 am

Re: [RANSOMWARE] Deadbolt

Post by Vogstar »

I paid the ransome but I never got the decryption key. Horrible :(
jswain
New here
Posts: 9
Joined: Tue Jul 05, 2016 5:32 pm

Re: [RANSOMWARE] Deadbolt

Post by jswain »

I have access to the system by plugging in a keyboard and monitor directly, my plan is to reset to factory defaults then update everything and rebuild from backups :(
Stevenlr
New here
Posts: 5
Joined: Tue Sep 03, 2013 6:10 am

Re: [RANSOMWARE] Deadbolt

Post by Stevenlr »

I managed to get the GUI back up via SSH and renaming index.html to something else and putting index.html.bak in its place
They only encrypted System files and one out of 3 main folders I have

Hoping there is a way to decrypt found out otherwise I'll have to go pull off the data that is fine and wipe and start again
would rather not!
matthewoliver
Getting the hang of things
Posts: 76
Joined: Tue Nov 17, 2009 5:05 am

Re: [RANSOMWARE] Deadbolt

Post by matthewoliver »

I'm really sorry for all of you that got infected... It would be interesting to know what firmware you guys are running though and if you had upnp activated.
I personally am running QuTS hero 5.0.0.1892 (and deactivated upnp) and have not (yet, fingers crossed) been affected by deadbolt
Current:
TVS-h1288X
Intel Xeon W-1250 w/ 64GB Ram
2x Samsung 980 NVMe 1TB
4x Samsung 860 EVO 1TB
8x Seagate IronWolf 10TB
QXP-T32P
Previous:
TS-469L
TS-219
remainz
Starting out
Posts: 16
Joined: Tue Jan 22, 2019 8:17 pm

Re: [RANSOMWARE] Deadbolt

Post by remainz »

I had UPnP on and got infected. This is all alien to me.

Do I SSH on the NAS or from windows to look for the infected files?
P3R
Guru
Posts: 13192
Joined: Sat Dec 29, 2007 1:39 am
Location: Stockholm, Sweden (UTC+01:00)

Re: [RANSOMWARE] Deadbolt

Post by P3R »

jswain wrote: Wed Jan 26, 2022 7:19 pm So many of my files are now encrypted with the .deadbolt extension, this is so depressing!

Its all so well saying to disconnect from the internet to avoid this happening but i bought it for that very use, otherwise i may as well of just used a USB HDD.
Yes the Qnap marketing claiming that was possible to do safely with the Qnap have unfortunatelly been deceiving. :cry:

Remote access is still possible though through a remote access VPN, preferably installed on the Internet-facing firewall/router or at least on something in your network not made by Qnap.

Maybe it's too soon to remind about this but not having backup copies of your most important data on at least two other medias, with one always stored at another site, would have been a gamble even if ransomware didn't exist...
RAID have never ever been a replacement for backups. Without backups on a different system (preferably placed at another site), you will eventually lose data!

A non-RAID configuration (including RAID 0, which isn't really RAID) with a backup on a separate media protects your data far better than any RAID-volume without backup.

All data storage consists of both the primary storage and the backups. It's your money and your data, spend the storage budget wisely or pay with your data!
pbch1
New here
Posts: 8
Joined: Wed Jan 26, 2022 8:53 pm

Re: [RANSOMWARE] Deadbolt

Post by pbch1 »

I am also a victim!

I victim of myself (backup) and of QNAP.
All my files are encrypted *.deadbolt
Unfortunately my backup is not up-to-date. Yes... I know.

I really need the docuemts on my QNAP NAS. Is aynone here who paid and get at working key? Yes - i also know i should not do. But.... :-(

Does anyone know what is the right way? Should i update firmware on the NAS and restart or ist this a bad idea because - if a get the right key - the one will not work then? Or is the unlock-key already on the NAS or the files?

THANK YOU for any help!
nonojapan
Starting out
Posts: 17
Joined: Wed Jan 26, 2022 12:14 pm

Re: [RANSOMWARE] Deadbolt

Post by nonojapan »

pbch1 wrote: Wed Jan 26, 2022 8:59 pm In the same boat.... You should wait few days. Some people already paid the ransom but did not receive the key. Maybe qnap will have a solution, I hope...
Stevenlr
New here
Posts: 5
Joined: Tue Sep 03, 2013 6:10 am

Re: [RANSOMWARE] Deadbolt

Post by Stevenlr »

Found a post here of someone who paid and decryption is running
https://www.bleepingcomputer.com/forums ... ion/page-2
swisshuttles
New here
Posts: 7
Joined: Sun May 26, 2013 1:09 am

Re: [RANSOMWARE] Deadbolt

Post by swisshuttles »

Same hack here on a TVS-653 running on 5.0.0.1870 firmware. with UPnP disabled but with ports 8080, 21, 80, 443 and 3389 open to the internet. No reaction of Qnap yet. Hope to have one soon..
remainz
Starting out
Posts: 16
Joined: Tue Jan 22, 2019 8:17 pm

Re: [RANSOMWARE] Deadbolt

Post by remainz »

Can someone please help with killing the process as above?

How to write kill PID 11943* properly as this doesnt work and I dont know enough programming?
thanks

using windows and this link h[url]ttps://www.qnap.com/en/how-to/knowledge-base/a ... -using-ssh[/url]

Code: Select all

cd /mnt/HDA_ROOT/
ls -alh


drwxr-xr-x  9 admin administrators 4.0K 2022-01-25 15:59 ./
drwxr-xr-x 10 admin administrators  220 2021-11-23 22:55 ../
-rwxr-xr-x  1 admin administrators 939K 2022-01-25 15:59 11943*
-rw-rw-rw-  1 admin administrators  280 2021-11-26 12:49 .conf
drwxr-xr-x 59 admin administrators  12K 2022-01-26 09:46 .config/
drwxrwxrwx  2 admin administrators 4.0K 2021-11-23 22:22 .inited/
drwxr-xr-x  9 admin administrators 4.0K 2022-01-26 13:10 .logs/
drwx------  2 admin administrators  16K 2018-01-11 17:25 lost+found/
-rw-r--r--  1 admin administrators    0 2021-07-19 12:13 .nfs_fix_check
-rw-r--r--  1 admin administrators    0 2018-01-11 17:28 .QTS.installed
-rw-r--r--  1 admin administrators    0 2018-01-11 17:28 .QTS.installed.notice
drwxr-xr-x  2 admin administrators 4.0K 2021-07-19 12:00 ssl_lib/
lrwxrwxrwx  1 admin administrators   24 2020-12-01 14:02 twonkymedia -> /mnt/ext  
alexhjones
New here
Posts: 8
Joined: Fri Oct 28, 2016 5:52 pm

Re: [RANSOMWARE] Deadbolt

Post by alexhjones »

Official QNAP news release on Deadbolt: https://www.qnap.com/en/security-news/2 ... e-together
Post Reply

Return to “Users' Corner”