• Navigation
Page 3 of 4 FirstFirst 1 2 3 4 LastLast
Results 41 to 60 of 65
  1. #41
    Member since 2006 and still can't think of a title.
    Join Date
    Oct 2006
    Posts
    28,431
    BG Level
    10
    FFXIV Character
    Acanis Lindri
    FFXIV Server
    Midgardsormr
    FFXI Server
    Bismarck
    WoW Realm
    Kil'jaeden

    Moneypak and bitcoins are very difficult to track. Just like western Union scams.

  2. #42
    Sea Torques
    Join Date
    Oct 2006
    Posts
    714
    BG Level
    5
    FFXI Server
    Carbuncle

    I just had my first brush with Cryptolocker after someone opened an email attachment. Got a bit lucky. We detected it after only about two hours, but in that short space of time it still was able to encrypt 19998 files on a mapped drive before we got the user to shutdown their Terminal Server session. Thank god our backup routine worked without a hitch.
    Only good thing about this virus is that it keeps a log of encrypted files in the registry and we were able to use that to make a concise list of files to restore.

  3. #43
    Ridill
    Join Date
    Jul 2008
    Posts
    11,309
    BG Level
    9

    Quote Originally Posted by gt_killa View Post
    Friends, uncle, and grandma' got hit with this in the past few weeks..It's freaking annoying! Isn't there a way to trace where the money goes when the user actually pay for the ransom? I haven't look much into it but shouldn't the police be involve in this type of scam? It's like internet bullies toward the people who not so good with the computer, like my grandma.
    Can't trace it, I remember reading just recently some place or person was hacked into and they took a pretty significant chunk of $$ in bitcoins from him, he said he didn't bother reporting it to the police though since it's so difficult to even attempt to track.

    I just had my first brush with Cryptolocker after someone opened an email attachment. Got a bit lucky. We detected it after only about two hours, but in that short space of time it still was able to encrypt 19998 files on a mapped drive before we got the user to shutdown their Terminal Server session. Thank god our backup routine worked without a hitch.
    Only good thing about this virus is that it keeps a log of encrypted files in the registry and we were able to use that to make a concise list of files to restore.
    What scares me is while the main machines in our classrooms are frozen via Faronics, the networked drives are not, and a lot of those drives have R/W/E permissions for everyone set... Hell we have an instructor who is just deleting random shit on a network drive right now and breaking a program, i'd hate to see what would happen if this got loose.

  4. #44
    Ironing this Thread
    Sweaty Dick Punching Enthusiast

    Join Date
    Feb 2006
    Posts
    21,329
    BG Level
    10
    FFXIV Character
    Boyiee Star
    FFXIV Server
    Gilgamesh
    WoW Realm
    Kel'Thuzad

    I offered my dad a 32gb usb3.0 flash drive to back his shit up onto.

    Says he doesn't need it... Turns out, he writes everything down...

  5. #45

    Sweaty Dick Punching Enthusiast

    Join Date
    May 2005
    Posts
    9,265
    BG Level
    8
    FFXI Server
    Fenrir

    Quote Originally Posted by hey View Post
    That seems like bad advice. It sucks, but if you care about the data, and don't have it backed up, you better just pay it.
    He knows well the only chance to getting the pictures back is paying, but there's also no guarantee. There are numerous instances of people paying the ransom and either not getting a decoder or not getting the correct one for their encryption. Then you're out of the money and the data.

  6. #46
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Quote Originally Posted by Roranora View Post
    He knows well the only chance to getting the pictures back is paying, but there's also no guarantee. There are numerous instances of people paying the ransom and either not getting a decoder or not getting the correct one for their encryption. Then you're out of the money and the data.
    I kind of doubt that is typical. If they make a habit of not providing the key after being paid, then people will just stop paying them. Still, even if there's no guarentee, if you care about the data, it's still your best bet. If you don't, you are guaranteed to never get it back.

  7. #47

    Sweaty Dick Punching Enthusiast

    Join Date
    May 2005
    Posts
    9,265
    BG Level
    8
    FFXI Server
    Fenrir

    It's difficult to quantify the likelihood of getting proper decryption in return, but it's definitely not a sure thing from some accounts. I don't think he cares much about the data, but the wife does (photos, memories, etc.), and that will probably win out. They still have some 40+ hours for the cheaper price anyway. I just told him to hold off at first, at least to see if it's legit. (I hadn't heard about it or seen this thread at the time.) It's definitely legit, and one of the most gnarly malware ever.

  8. #48
    Ridill
    Join Date
    Jul 2008
    Posts
    11,309
    BG Level
    9

    Quote Originally Posted by Roranora View Post
    It's difficult to quantify the likelihood of getting proper decryption in return, but it's definitely not a sure thing from some accounts. I don't think he cares much about the data, but the wife does (photos, memories, etc.), and that will probably win out. They still have some 40+ hours for the cheaper price anyway. I just told him to hold off at first, at least to see if it's legit. (I hadn't heard about it or seen this thread at the time.) It's definitely legit, and one of the most gnarly malware ever.
    You should look into BadBios.

  9. #49
    Relic Weapons
    Join Date
    Mar 2009
    Posts
    300
    BG Level
    4

    If true, it could be pretty nasty. However, there are a couple sites out there (InfoWorld and Ars Technica) that are fairly skeptical about its authenticity.

  10. #50
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Quote Originally Posted by Meresgi View Post
    You should look into BadBios.
    lol

  11. #51
    A. Body
    Join Date
    Jul 2006
    Posts
    4,224
    BG Level
    7

    BadBios is the stuff of nightmares. Serious fucking nightmares, not that something encrypting your files and holding them for ransom is much better.

  12. #52
    Relic Weapons
    Join Date
    Mar 2009
    Posts
    300
    BG Level
    4

    From everything I've read so far, it hasn't been found in the wild. I'm under the impression that the only security company/guru that has seen it is Dragos Ruiu.

  13. #53
    Old Merits
    Join Date
    Nov 2007
    Posts
    1,002
    BG Level
    6
    FFXI Server
    Asura

    http://www.reddit.com/r/sysadmin/com..._cryptolocker/

    http://www.bleepingcomputer.com/viru...re-information

    I'm working an IT helpdesk now. Two of our clients have been hit since September. The first one was our first experience with this, and it destroyed some medical records, and we had to restore from a backup from almost a year ago. The second one was spotted in progress for a client that only kept one day of backups (which will be changing very soon). We lost the work done that day since we restored the server from the backup, but the behaviour was spotted early before the next backup destroyed the good data. The second client had a version of the malware that was less than 24 hours old, so none of the hardware firewalls or malware scanning devices on the network stripped it, and the software didn't either, only one malware vendor at the time even flagged the file when submitted for analysis.

    There's another way than off-site backups to recover from this. Running your servers as VMs, and backing them up outside of the VM can prevent the encryption from going after your backups. External backup devices in the server rack can also help.

    The coders of this malware are reading the Reddit and Bleeping computer threads and apparently providing tech support for people that paid and didn't get their decryption keys. I guess, as the saying goes, "you have to be honest to live outside the law". Unfortunately, they're also keeping up on the threads of how IT people are stopping their software and blocking it. They email it as a phishing attempt, or drop it in via stuff like the Zeus botnet. It used to be a plain EXE or ZIP file, now they've password protected it to prevent the scanners from stopping it. People paying the ransom to get their data back are funding the updates to this malware, and those of us sharing information publicly are helping them bug test it and make it harder to block.

    The one good thing to come out of this in the end will be that everyone will be aware of just how important 3-2-1 backup policy is (3 copies of the backup, 2 different physical storage media, 1 offsite backup) in recovering from data disasters. Businesses without a good backup policy (or any at all) will die from the data loss of this type of malware.

    The type of files this targets for encryption points to it mainly being aimed at businesses. As they mainly take BitCoin (MoneyPak is only for people in the US), they've also jumped the price of BTC up over 100% since I first encountered this malware. It was under $200 USD in September, and I checked yesterday and got a value of $410 per BTC. The ransom has also changed from wanting 2 BTC to just 1, unless the 72 hours passes without being paid, then they jump up to 5-10 BTC and stop taking MoneyPak.

    It's hard to track where the money goes because MoneyPak doesn't do chargebacks. BTC tracks every transaction for every BitCoin in the public bloackchain, but you have to have a way to tie the wallet the coin comes from to a physical entity, which means they have to exchange for physical goods or money. They are generating a different wallet for each person that pays the ransom, and don't seem to be cashing out the coins for money, so it's hard to trace. They're also taking payments through the TOR network, which makes an end IP hard to identify. Until the people taking the ransoms screw up the right way, with someone watching, they will be hard to catch. SilkRoad was only caught because the guy that started it screwed up early on in development of the site and deanonymized himself where people could see and check back later. Even then it took a few years to prove it enough to charge him.

  14. #54
    Ridill
    Join Date
    Jul 2008
    Posts
    11,309
    BG Level
    9

    Quote Originally Posted by Lucki View Post
    From everything I've read so far, it hasn't been found in the wild. I'm under the impression that the only security company/guru that has seen it is Dragos Ruiu.
    It is rather strange it hasn't been found in the wild. I would like to see an actual video presentation of it by Dragos, or at least some information other then "this is what's going on". Possibly he's actually creating said malware himself or w/e lol.

  15. #55
    Pens win! Pens Win!!! PENS WIN!!!!!
    Join Date
    Dec 2005
    Posts
    8,032
    BG Level
    8
    FFXI Server
    Odin

    Fucking scary shit. Please continue to share information.

  16. #56
    Ridill
    Join Date
    Feb 2006
    Posts
    11,977
    BG Level
    9

  17. #57
    Member since 2006 and still can't think of a title.
    Join Date
    Oct 2006
    Posts
    28,431
    BG Level
    10
    FFXIV Character
    Acanis Lindri
    FFXIV Server
    Midgardsormr
    FFXI Server
    Bismarck
    WoW Realm
    Kil'jaeden

    Reading the article it almost sounds like they intentionally paid a ransom to try to investigate the virus and that it was a purposeful infection.

  18. #58
    F5 Like A Boss.
    Join Date
    Sep 2005
    Posts
    7,396
    BG Level
    8
    FFXIV Character
    Kuroki Kaze
    FFXIV Server
    Sargatanas
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Twisting Nether

    In the past month we've had 7 clients infected with the virus. The worst one had the virus encrypt their network shares then DFS replicated it to the cloud servers. Shadow copies were also encrypted... Then to make matters worse, it replicated to DR. This client literally lost 2 months worth of data because we had to go that far back.

    This shit is easily the worst virus I've encountered. What we've been doing as a counter-measure is pitching offsite and offline backups to our clients. And to have the backups run on Linux boxes (since they're not targeted by the virus yet).

  19. #59
    jponry
    Join Date
    Jul 2006
    Posts
    1,391
    BG Level
    6
    FFXI Server
    Phoenix

    Quote Originally Posted by Kurokikaze View Post
    In the past month we've had 7 clients infected with the virus. The worst one had the virus encrypt their network shares then DFS replicated it to the cloud servers. Shadow copies were also encrypted... Then to make matters worse, it replicated to DR. This client literally lost 2 months worth of data because we had to go that far back.

    This shit is easily the worst virus I've encountered. What we've been doing as a counter-measure is pitching offsite and offline backups to our clients. And to have the backups run on Linux boxes (since they're not targeted by the virus yet).
    What virus protection suite are you guys running? How did it spawn onto 7 machines?

  20. #60
    F5 Like A Boss.
    Join Date
    Sep 2005
    Posts
    7,396
    BG Level
    8
    FFXIV Character
    Kuroki Kaze
    FFXIV Server
    Sargatanas
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Twisting Nether

    When I said "7 clients" I meant 7 different companies. Every encounter with the virus was always just 1 machine on the domain though. We push out Symantec Cloud now, used to be Symantec Endpoint Protection.

    Sorry if it wasn't clear. I do outsourced IT/Infrastructure management for hedge funds. Unfortunately not in-house IT.

    Whats everyone else here pushing out to their users in terms of virus/malware protection?

Page 3 of 4 FirstFirst 1 2 3 4 LastLast

Similar Threads

  1. Replies: 3
    Last Post: 2013-10-19, 19:36
  2. Replies: 4
    Last Post: 2008-12-18, 22:38
  3. Random pop ups with a browser up
    By Insanecyclone in forum Tech
    Replies: 4
    Last Post: 2007-06-11, 22:05