david-pace / wave-recovery-tool

Tool to display WAVE/AIFF file header information and to restore corrupted WAVE/AIFF file headers
GNU General Public License v3.0
14 stars 2 forks source link

Support Partial Restoration of Stop/Djvu Encrypted Files #9

Closed david-pace closed 2 years ago

david-pace commented 2 years ago

The Stop/Djvu ransomware encrypts the first 153605 bytes (150 kB + 5 bytes) of files and adds 334 additional bytes at the end. While still in encrypted state, the audio data after byte 153605 can still be recovered.

This involves:

This mode should be activated by providing the following application parameter:

-a djvu