Announcement

Collapse
No announcement yet.

New Virus/Malware/Ransomware you guys need to be aware of

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • New Virus/Malware/Ransomware you guys need to be aware of

    If you aren't already aware, there is a Virus/Malware/Ransomware going around called CryptoLocker. It encrypts files on your computer creating both a public encryption key that is stored on your computer, and a private decryption key that is kept on the criminals' server. After the virus has done its work, it changes your desktop background with a message that tells you to go to a random link, pay the criminals $300 to get your private key to decrypt the files, and it gives you a deadline to do so. If you miss this deadline, they destroy your private decryption key on their server, and whatever files were encrypted by the virus will be lost forever.:

    Cryptolocker is a nasty ransomware that encrypts infected users' personal files. Using Malwarebytes Premium will keep you safe.


    This virus hit three of our largest managed services clients yesterday, even with up-to-date ESET Antivirus running. Please make sure you have your personal files and critical business files backed up to a separate location lest things like this happen to you.

  • #2
    thanks for the heads up...

    Comment


    • #3
      These people need to die in a fire!
      Originally posted by Taya Kyle, American Gun
      There comes a time when honest debate, serious diplomatic efforts, and logical arguments have been exhausted and only men and women willing to take up arms against evil will suffice to save the freedom of a nation or continent.

      Comment


      • #4
        Thank you sir and passed on!

        Comment


        • #5
          Originally posted by Darren M View Post
          These people need to die in a fire!
          No kidding. The shear malice is incomprehensible.
          "Self-government won't work without self-discipline." - Paul Harvey

          Comment


          • #6
            Ratt, you're more smarterer than me, but presuming this this doesn't utilize privilege escalation, wouldn't the simplest defense be limited accts w/explicit exe whitelisting and no internet access for admin accts?

            Comment


            • #7
              Some people are going to have their eyes openned up. Maybe they'll stop clicking every fucking thing they come across when they get hit with this.
              sigpic

              Comment


              • #8
                Saw something on this on the SANS 610 Alumni list. Will pass along anything I hear on ways to get around this.
                2013 F150 STX Supercab 5.0L w/3.55 LSD
                1990 GT Convertible

                Comment


                • #9
                  What Is the delivery method?
                  Originally posted by Taya Kyle, American Gun
                  There comes a time when honest debate, serious diplomatic efforts, and logical arguments have been exhausted and only men and women willing to take up arms against evil will suffice to save the freedom of a nation or continent.

                  Comment


                  • #10
                    So they lock down a few gigs of porn and pirate bay movies?

                    Comment


                    • #11
                      POC tool for decrypting : http://tmp.emsisoft.com/fw/decrypt_harasom.exe

                      Info here at post 90 http://www.bleepingcomputer.com/foru...somware/page-6
                      2013 F150 STX Supercab 5.0L w/3.55 LSD
                      1990 GT Convertible

                      Comment


                      • #12
                        That tool is for a similar, but different infection called haransom.

                        Comment


                        • #13
                          Originally posted by Magnus View Post
                          Some people are going to have their eyes openned up. Maybe they'll stop clicking every fucking thing they come across when they get hit with this.
                          It's like 9/11 - people forget, get lazy again and whine about "security" being too much of a hassle.
                          Originally posted by MR EDD
                          U defend him who use's racial slurs like hes drinking water.

                          Comment


                          • #14
                            Guys, this cryptolocker ransomware is srs bsns. The FBI is now involved and trying to do everything they can to mitigate damages caused to government entities. All it takes is one uninformed (read: stupid/uneducated) user who has shared drive access, and a whole company can be infected before they realize what is going on.

                            Comment


                            • #15
                              Yea, we got a warning about it at work a couple of weeks ago. I keep my stuff backed up anyways, so it would be more of a nusance than anything for me. Even my personal machines are backed up to a NAS.

                              Comment

                              Working...
                              X