{"id":232836,"date":"2020-05-29T00:58:24","date_gmt":"2020-05-29T04:58:24","guid":{"rendered":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/ransomware-that-uses-onion-websites-ransomware-help-tech-support-bleepingcomputer\/"},"modified":"2020-05-29T00:58:24","modified_gmt":"2020-05-29T04:58:24","slug":"ransomware-that-uses-onion-websites-ransomware-help-tech-support-bleepingcomputer","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser\/ransomware-that-uses-onion-websites-ransomware-help-tech-support-bleepingcomputer\/","title":{"rendered":"Ransomware that uses .onion websites &#8211; Ransomware Help &amp; Tech Support &#8211; BleepingComputer"},"content":{"rendered":"<p><p>Edit: The reference I got from ID-ransomware is<\/p>\n<p>SHA1: 46b9428f694ed7d56874995acca80e92f3817363<\/p>\n<\/p>\n<p>-------<\/p>\n<\/p>\n<p>Yesterday, I discovered that my NAS has been contaminated with ransomware. I knew nothing about ransomware so I did some studying and eventually tried to find a decrypter using two website:<\/p>\n<\/p>\n<p>- <a href=\"https:\/\/id-ransomware.malwarehunterteam.com\" rel=\"nofollow\">https:\/\/id-ransomware.malwarehunterteam.com<\/a><\/p>\n<p>- <a href=\"https:\/\/www.emsisoft.com\/ransomware-decryption-tools\" rel=\"nofollow\">https:\/\/www.emsisoft.com\/ransomware-decryption-tools<\/a><\/p>\n<\/p>\n<p>Both websites were unable to determine the ransomware and both led me to this forum.<\/p>\n<p>One thing about my ransomware is that, on the ransome note, it directs you to .onion websites using TOR browser, something I knew nothing of. Apparently, it is a special-use domain that makes it difficult to trace access. Sounds fishy and I havent even tried accessing the website.<\/p>\n<p>My every limited knowledge about ransomware tells me that .onion websites is making it difficult to determine the ransomware. But I could be wrong altogether. It could just be a new ransomware. Again, I'm absolutely new to ransomware.<\/p>\n<\/p>\n<p>Either way, I'd like some suggestion on how to resolve this and decrypt my files. Thankfully, I do have a remote backup of my NAS but that backup was about 4 months ago. So a lot of files has been changed since. If decryption is possible, then I would like to go that route.<\/p>\n<\/p>\n<p>My files are decrypted with .encrypt extension<\/p>\n<p>e.g. IMG_20180515.jpg is changed to IMG_20180515.jpg.encrypt<\/p>\n<\/p>\n<p>Many thanks in advance.<\/p>\n<\/p>\n<p>README_FOR_DECRYPT.txt 312bytes4 downloads<\/p>\n<p>Edited by zgravity00, Yesterday, 11:01 PM.<\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See the rest here:<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/forums\/t\/722087\/ransomware-that-uses-onion-websites\/\" title=\"Ransomware that uses .onion websites - Ransomware Help &amp; Tech Support - BleepingComputer\" rel=\"noopener noreferrer\">Ransomware that uses .onion websites - Ransomware Help &amp; Tech Support - BleepingComputer<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Edit: The reference I got from ID-ransomware is SHA1: 46b9428f694ed7d56874995acca80e92f3817363 ------- Yesterday, I discovered that my NAS has been contaminated with ransomware.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/tor-browser\/ransomware-that-uses-onion-websites-ransomware-help-tech-support-bleepingcomputer\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94875],"tags":[],"class_list":["post-232836","post","type-post","status-publish","format-standard","hentry","category-tor-browser"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/232836"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=232836"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/232836\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=232836"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=232836"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=232836"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}