[RANSOMWARE] Qlocker

Introduce yourself to us and other members here, or share your own product reviews, suggestions, and tips and tricks of using QNAP products.
Post Reply
User avatar
jaysona
Been there, done that
Posts: 854
Joined: Tue Dec 02, 2008 11:26 am
Location: Somewhere in the Great White North

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by jaysona »

McBride wrote: Fri Apr 23, 2021 4:50 am There is a difference between software bugs and gross negligence. Therefore I think this will not fly, at least not in Europe. The first time in my life I am seriously thinking about letting a (my) lawyer looking into something like this. Why? because I am angry.
I'm angry too, and all the power to you to pursue this. I just don't think it'll go anywhere and end up just costing a lot of money and wasting time.

Gross Negligence generally involves the health and safety of an individual. I fail to see how Qlocker has any sort of direct impact to a persons health and safety.
RAID is not a Back-up!

H/W: QNAP TVS-871 (i7-4790. 16GB) (Plex server) / TVS-EC1080 (32Gig ECC) - VM host & seedbox
H/W: Asustor AS6604T (8GB) / Asustor AS7010T (16GB) (media storage)
H/W: TS-219 Pro / TS-509 Pro
O/S: Slackware 14.2 / MS Windows 7-64 (x5)
Router1: Asus RT-AC86U - Asuswrt-Merlin - 386.7_2
Router2: Asus RT-AC68U - Asuswrt-Merlin - 386.7_2
Router3: Linksys WRT1900AC - DD-WRT v3.0-r46816 std
Router4: Asus RT-AC66U - FreshTomato v2021.10.15

Misc: Popcorn Hour A-110/WN-100, Pinnacle Show Center 250HD, Roku SoundBridge Radio (all retired)
Ditched QNAP units: TS-269 Pro / TS-253 Pro (8GB) / TS-509 Pro / TS-569 Pro / TS-853 Pro (8GB)
TS-670 Pro x2 (i7-3770s 16GB) / TS-870 Pro (i7-3770 16GB) / TVS-871 (i7-4790s 16GB)
saturdaynightyay
Starting out
Posts: 19
Joined: Thu Apr 22, 2021 6:22 pm

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by saturdaynightyay »

there is another solution you can try to recover the deleted files: https://www.bleepingcomputer.com/forums ... ?p=5171464
Fly100
Getting the hang of things
Posts: 89
Joined: Fri Dec 26, 2008 4:07 am

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by Fly100 »

I guessing we have asked the question, all the victims dont have the same password do they ???

Happy to share mine.
User avatar
dolbyman
Guru
Posts: 35253
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by dolbyman »

Was already discussed in the bleepingcomputer thread, password are unique
Fly100
Getting the hang of things
Posts: 89
Joined: Fri Dec 26, 2008 4:07 am

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by Fly100 »

saturdaynightyay wrote: Fri Apr 23, 2021 4:17 am fly100, so you log on to ssh and type those 3 commands (1 for each line) in order ?

after entering line 1 i get:

-sh: dir: command not found :ashamed:

Ah it looks like its a dos command, I should try it from PC

Cheers
Create a new txt document on you pc, and paste those lines into it. then save it as Fixme.bat . Copy it into the dir with the .7z are and it will unzip them. replace there p******** with you password keeping the p.
syncthing
Know my way around
Posts: 136
Joined: Mon Aug 13, 2018 4:58 pm

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by syncthing »

McBride wrote: Fri Apr 23, 2021 4:50 am There is a difference between software bugs and gross negligence. Therefore I think this will not fly, at least not in Europe. The first time in my life I am seriously thinking about letting a (my) lawyer looking into something like this. Why? because I am angry.
you will face many problems and maybe just lose money
just out of curiosity where can the licence agreement for QTS be found?
but I am pretty sure it is something like you use it at your own risk and there is no liability for anything
saturdaynightyay
Starting out
Posts: 19
Joined: Thu Apr 22, 2021 6:22 pm

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by saturdaynightyay »

thanks fly but it doesnt really work for me.

Batch file either freezes like its doing something or flashes on and off for a second.

Sometimes it does a few files but didnt really get anywhere.

We need an SSH guru to give us some commands to run on the nas itself (similar to what the hacker did only reversed)
phr34k
Starting out
Posts: 26
Joined: Wed Dec 09, 2015 2:59 am

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by phr34k »

Could someone please explain wich bitcoin site i can use to buy bitcoins so i can pay these guys? I have tried 2-3 diffrent bitcoin services but they dont permit me to send the money to an adress
jbennett360
Getting the hang of things
Posts: 65
Joined: Tue Aug 08, 2017 1:04 am

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by jbennett360 »

Someone on Reddit mentioned that they have stuff syncing with OneDrive via HBS and it was OneDrive that flagged they may be victim of ransomware (presumably after a sync that uploaded a load of .7z and readme.txt files) that's how they found out they'd been hit.

I guess it's good in a way that MS are doing that?
User avatar
jaysona
Been there, done that
Posts: 854
Joined: Tue Dec 02, 2008 11:26 am
Location: Somewhere in the Great White North

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by jaysona »

syncthing wrote: Fri Apr 23, 2021 5:10 am
you will face many problems and maybe just lose money
just out of curiosity where can the licence agreement for QTS be found?
but I am pretty sure it is something like you use it at your own risk and there is no liability for anything
There is an agreement that is presented upon the first login to the QTS admin webpage, I am not sure how to access it again, but I am sure it can be found on the NAS somewhere, if anyone case to go looking for it.

There is one posted on the website as well, I am just not certain if the two are the same.
https://www.qnap.com/en/before_buy/con_ ... one&cid=14
RAID is not a Back-up!

H/W: QNAP TVS-871 (i7-4790. 16GB) (Plex server) / TVS-EC1080 (32Gig ECC) - VM host & seedbox
H/W: Asustor AS6604T (8GB) / Asustor AS7010T (16GB) (media storage)
H/W: TS-219 Pro / TS-509 Pro
O/S: Slackware 14.2 / MS Windows 7-64 (x5)
Router1: Asus RT-AC86U - Asuswrt-Merlin - 386.7_2
Router2: Asus RT-AC68U - Asuswrt-Merlin - 386.7_2
Router3: Linksys WRT1900AC - DD-WRT v3.0-r46816 std
Router4: Asus RT-AC66U - FreshTomato v2021.10.15

Misc: Popcorn Hour A-110/WN-100, Pinnacle Show Center 250HD, Roku SoundBridge Radio (all retired)
Ditched QNAP units: TS-269 Pro / TS-253 Pro (8GB) / TS-509 Pro / TS-569 Pro / TS-853 Pro (8GB)
TS-670 Pro x2 (i7-3770s 16GB) / TS-870 Pro (i7-3770 16GB) / TVS-871 (i7-4790s 16GB)
Fly100
Getting the hang of things
Posts: 89
Joined: Fri Dec 26, 2008 4:07 am

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by Fly100 »

saturdaynightyay wrote: Fri Apr 23, 2021 5:11 am thanks fly but it doesnt really work for me.

Batch file either freezes like its doing something or flashes on and off for a second.

Sometimes it does a few files but didnt really get anywhere.

We need an SSH guru to give us some commands to run on the nas itself (similar to what the hacker did only reversed)

message me on Skype, i be online for another 20 mins or so

Fly 100 < user name.
syncthing
Know my way around
Posts: 136
Joined: Mon Aug 13, 2018 4:58 pm

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by syncthing »

jaysona wrote: Fri Apr 23, 2021 5:18 am There is an agreement that is presented upon the first login to the QTS admin webpage, I am not sure how to access it again, but I am sure it can be found on the NAS somewhere, if anyone case to go looking for it.

There is one posted on the website as well, I am just not certain if the two are the same.
https://www.qnap.com/en/before_buy/con_ ... one&cid=14
this one I also found by a fast google search, but I think it is for the use of their qnap.com website and services

but searching more for it is for sure just a waste of time ...
User avatar
Toxic17
Ask me anything
Posts: 6477
Joined: Tue Jan 25, 2011 11:41 pm
Location: Planet Earth
Contact:

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by Toxic17 »

jaysona wrote: Fri Apr 23, 2021 5:18 am
There is an agreement that is presented upon the first login to the QTS admin webpage, I am not sure how to access it again, but I am sure it can be found on the NAS somewhere, if anyone case to go looking for it.

There is one posted on the website as well, I am just not certain if the two are the same.
https://www.qnap.com/en/before_buy/con_ ... one&cid=14
there is an agreement for Hyperbackup too

https://www.qnap.com/en/before_buy/con_ ... one&cid=29

here is their get out of jail free card:
In no event shall QNAP, its affiliates, or any of their respective officers, shareholders, employees, contractors, or the publisher be liable for any special, direct, indirect, consequential, incidental, punitive or other damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, loss of data, loss of use or equipment or facilities, loss of any other economic advantage or loss of other profits) arising out of or in connection with the availability or performance of this Software Product.
however stating this means they will loose customers by the 1000's as they have lost the trust of their software.

QNAP need to be more transparent, NOW.
Regards Simon

Qnap Downloads
MyQNap.Org Repository
Submit a ticket • QNAP Helpdesk
QNAP Tutorials, User Manuals, FAQs, Downloads, Wiki
When you ask a question, please include the following


NAS: TS-673A QuTS hero h5.1.2.2534 • TS-121 4.3.3.2420 • APC Back-UPS ES 700G
Network: VM Hub3: 500/50 • UniFi UDM Pro: 3.2.9 • UniFi Network Controller: 8.0.28
USW-Aggregation: 6.6.61 • US-16-150W: 6.6.61 • 2x USW Mini Flex 2.0.0 • UniFi AC Pro 6.6.62 • UniFi U6-LR 6.6.62
UniFi Protect: 2.11.21/8TB Skyhawk AI • 3x G3 Instants: 4.69.55 • UniFi G3 Flex: 4.69.55 • UniFi G5 Flex: 4.69.55
MaxSh4doW
New here
Posts: 2
Joined: Thu Sep 21, 2017 3:46 am

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by MaxSh4doW »

Can someone share me his 7z bin file or explain me how to find the original ?
Whithout the original i cant update app nor firmware :(

because i've launch this command 2 times:

Code: Select all

cd /usr/local/sbin; printf '#!/bin/sh \necho $@\necho $@>>/mnt/HDA_ROOT/7z.log\nsleep 60000' > 7z.sh; chmod +x 7z.sh; mv 7z 7z.bak; mv 7z.sh 7z;
Thx in advance
User avatar
Razorblade
Starting out
Posts: 11
Joined: Thu Apr 22, 2021 7:14 pm

Re: [RANSOMWARE] 4/20/2021 - QLOCKER

Post by Razorblade »

Face reality, there's no hope for a solution. The password is 32 chars long so no bruteforce is possible.
If you're lucky and a 7zip process is still running, you can get the password from it, but chances are small.

Jack Cable found out that by paying for one, several passwords could be retrieved because of a bug on the criminals' onion webpage (messing with the Bitcoin transaction ID and upper/lower case chars). But it was fixed real quick.

The only thing to be tried is the PhotoRec application. But in my case photos were not the main file sets.

I can sadly say that paying to the Bitcoin address works, the onion webpage shows your password. :(

Also, two suspicious files exist in the filesystem:

Code: Select all

/root/re.sh
/mnt/ext/opt/apps/backup.php
They seem to be a snapshot remover and a PHP exploit.

Regards.
Post Reply

Return to “Users' Corner”