[RANSOMWARE] >>READ 1st Post<< Deadbolt

Introduce yourself to us and other members here, or share your own product reviews, suggestions, and tips and tricks of using QNAP products.
Post Reply
dosborne
Experience counts
Posts: 1813
Joined: Tue May 29, 2018 3:02 am
Location: Ottawa, Ontario, Canada

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by dosborne »

Zandone wrote: Thu May 18, 2023 8:22 pm Maybe anyone has other experiences in restoring the ransom page the way I tried so far?
Did you try the steps listed here:
viewtopic.php?f=45&t=164797&start=1380#p825512
QNAP TS-563-16G 5x10TB Seagate Ironwolf HDD Raid-5 NIC: 2x1GB 1x10GbE
QNAP TS-231P-US 2x18TB Seagate Exos HDD Raid-1
[Deadbolt and General Ransomware Detection, Prevention, Recovery & MORE]
josch68
New here
Posts: 2
Joined: Wed May 17, 2023 11:50 pm

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by josch68 »

FSC830 wrote: Mon Apr 24, 2023 5:53 am
Phocean wrote: Fri Apr 21, 2023 8:37 am Anyone has received the decrypt key recently? Paid ransom more than 72 hours ago and still only one transaction.

bc1qtwmxvzzghpv625xftz59q9wl8u2m7wpyt7w9rv
You are lucky: OP_Return is aaf8cad41cf6cf61b0aa6d0ba7d8029d.

Regards
Maybe you can help me as well? I am not able to find the OP_Return after paying to bc1q2049vk64uq0y58cl02qzvudzzt7kpz3unj433k. Help would be so much appreciated!
User avatar
dolbyman
Guru
Posts: 35248
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by dolbyman »

@ josh68
OP_RETURN 9404fcb0795e6ee62366089671e2ba0f
josch68
New here
Posts: 2
Joined: Wed May 17, 2023 11:50 pm

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by josch68 »

dolbyman wrote: Wed May 24, 2023 9:30 pm @ josh68
OP_RETURN 9404fcb0795e6ee62366089671e2ba0f
Thank you so much. It accepted the key and started decryption.
illusion_venz
New here
Posts: 4
Joined: Sun Jul 16, 2017 8:16 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by illusion_venz »

Hello everybody,

After having my qnap in storage for over a year I found out I also have a deadbolted qnap :( , I think it happened around february/march 2022 when I needed all stuff my stored because of some personal stuff happening.
----
❓ What happened?
All your files have been encrypted. This includes (but is not limited to) Photos, Documents and Spreadsheets.
❓ Why Me?
This is not a personal attack. You have been targeted because of the inadequate security provided by your vendor (QNAP).
❓ What now?
You can make a payment of (exactly) 0.030000 bitcoin to the following address:
bc1qksqe8fyflnnacrzgcuemenu2k8c67u0a0m7nvp
----
I need the files, but i am not able to find the return code. I followed the instructions as described on the first page of this thread and made the payment. But I can't find the return code, can someone find it for me?

Thanks!
FSC830
Experience counts
Posts: 2043
Joined: Thu Mar 03, 2016 1:11 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by FSC830 »

Unbelieveable...after more than a year you are aware that you are deadbolted? :geek:
And now you need the data?


The OP-Return will be available usually within 48-72 hours.
If you get one, you will be lucky. A ransom of 0.03BTC is very outdated, it was increased to 0.05BTC somewhen mid of 2022.

Regards
illusion_venz
New here
Posts: 4
Joined: Sun Jul 16, 2017 8:16 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by illusion_venz »

Thanks for the reply! Yes more than a year. Circumstances made I had to store my belongings in a storage for a long time, without knowing about deadbolt :(. So the OP-return will be shown in a different transaction @ bc1qksqe8fyflnnacrzgcuemenu2k8c67u0a0m7nvp if I'm lucky?

I wish I knew earlier :(

Regards
illusion_venz
New here
Posts: 4
Joined: Sun Jul 16, 2017 8:16 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by illusion_venz »

FSC830 wrote: Wed May 31, 2023 6:14 pm Unbelieveable...after more than a year you are aware that you are deadbolted? :geek:
And now you need the data?


The OP-Return will be available usually within 48-72 hours.
If you get one, you will be lucky. A ransom of 0.03BTC is very outdated, it was increased to 0.05BTC somewhen mid of 2022.

Regards
No luck. I've increased it to the updated amount 0.05.

expensive lesson, but still no luck :( . Or do you see an OP return code?

Thanks for the help
FSC830
Experience counts
Posts: 2043
Joined: Thu Mar 03, 2016 1:11 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by FSC830 »

No, did check last time abt. 2 hours ago.
My guess, this is all an automated process, so lets hope that increasing the fee will result in an OP_Return.

Good luck.

Regards
FSC830
Experience counts
Posts: 2043
Joined: Thu Mar 03, 2016 1:11 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by FSC830 »

illusion_venz wrote: Mon Jun 05, 2023 4:33 pm ...
No luck. I've increased it to the updated amount 0.05.

expensive lesson, but still no luck :( . Or do you see an OP return code?

Thanks for the help
Seems you are a lucky one...
OP_RETURN a64e7cb4bf6882415c2cdd44ecab7d1f

Regards
illusion_venz
New here
Posts: 4
Joined: Sun Jul 16, 2017 8:16 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by illusion_venz »

FSC830 wrote: Tue Jun 06, 2023 2:09 pm
illusion_venz wrote: Mon Jun 05, 2023 4:33 pm ...
No luck. I've increased it to the updated amount 0.05.

expensive lesson, but still no luck :( . Or do you see an OP return code?

Thanks for the help
Seems you are a lucky one...
OP_RETURN a64e7cb4bf6882415c2cdd44ecab7d1f

Regards
That made my day! Thanks!

My QNAP will never be reachable via internet again! next to a tripple backup :)
FSC830
Experience counts
Posts: 2043
Joined: Thu Mar 03, 2016 1:11 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by FSC830 »

DeltaBlock wrote: Tue Jun 06, 2023 6:04 pm 0.05BTC is equal to over more than 1200euro/dollar... :!: :!: :!: :!:
Yes, and?
Several dozen times mentioned here, that an USB drive (or even 2 or 3 or...) is much cheaper than paying the ransom.
But there will be always people who will learning this the hard (expensive) way... 8) .

No risk - no fun... :P

Regards
FSC830
Experience counts
Posts: 2043
Joined: Thu Mar 03, 2016 1:11 am

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by FSC830 »

illusion_venz wrote: Tue Jun 06, 2023 5:00 pm ...
My QNAP will never be reachable via internet again! next to a tripple backup :)
As countless times said here and in other threads: with a VPN service at your router and a VPN client at your mobile you should be able to access from everywhere you are staying - in the safest way you can choose.

All other access methods are less safe up to very insecure (port forwardings, myqnapcloud, ...).

Regards
baseballfan44
New here
Posts: 4
Joined: Thu Jun 08, 2023 11:43 pm

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by baseballfan44 »

seems that i'm on the 0.05BTC list and so far the deadbolt address hasn't been tracked by Dutch authorities and the decryption key isn't available from them. trying to find any avenue to restore the files (mainly pictures) I've been searching through the blockchain site but not seeing the OP_Return from the new interface on the blockchain site. Yes I checked the instructions in the previous post.
User avatar
dolbyman
Guru
Posts: 35248
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: [RANSOMWARE] >>READ 1st Post<< Deadbolt

Post by dolbyman »

This is still an English forum, so if you want to converse in dutch, check here

https://forum.qnapclub.be/index.php

And it has been discussed on end that the dutch authorities did nothing other than to pay/cancel the transaction to the criminals but they (the criminals) smartened up and are now delaying payments until each transaction has been confirmed plenty of times

So no need to hope for any authorities to step in .. pay up or live without these files
Post Reply

Return to “Users' Corner”