Can you write me an PM? I don't see the button in your profile to do it...
Anyway, just set your debug level on 6 and search for the ins7423 cmd at the boot of your card. Look at the fourth byte and the last one, if the fourth byte is 02 it's DES/3DES encryption. The last byte shows you the card revision, if that is 01 it's definitely DES if you card is not in AES mode. Revision 1 cards doesnt have the ability to overcrypt with 3DES
What is your Oscam version? Is the ins7e set? There is no D3 74 23 00 26 INS command present in the log, but beside that, the card is in the right mode. You can see that at the 90 20 status return, so I think there is no need for sending the ins7423 to the card I think. Just try to bruteforce your eCW - dCW pair, it should be single DES or something else, the return of the ins54 looks different compared to other NDS cards.
Do you have access to a n-line/c-line with an open 0907 card? If not you need to bruteforce the decrypted CW with a short record of maybe 10 seconds of any encrypted tv channel where this card is used. If you have the n-line/c-line, it's just some simple steps to get the eCW dCW pair and bruteforce with "hashcat".
So for that card you already have your k1 overcrypt key? If yes, use this card to generate the eCW - dCW pair. Just bind both in one oscam, check the "ECM Doublecheck" option, set the debug on level 6 and grep the eCW from the card where the k1 overcrypt key is missing and the according dCW from the card that is clearing the channels.
I'm not pretty sure, but I think there are some tutorials how to do that on the internet in english, in german here in the forum.
I don't know if my card caid 0907 sky, uses k1, because 5 days ago it stopped some channels from working, I noticed a difference in the ECM of the channels, I'll send it to you to check if you know it could be. thank you
iCam is enabled on the not clearing channels, you can see that on the 4th + 5th byte of the ECM: 80 70 80 00 7C . On still clearing channels the descrambler (iCAM) is disabled, to see at the same bytes that are both set to null: 80 70 50 00 00.
So I'm not an expert in that, but there are some guys that already know how to handle that. iCAM is like a CW post-decryption in a specific way where you need the iCAM bytes of the ECM to do that. Maybe AES with a initial vector byte ....? Don't know
Do you have access to a n-line/c-line with an open 0907 card? If not you need to bruteforce the decrypted CW with a short record of maybe 10 seconds of any encrypted tv channel where this card is used.