Moneypak and bitcoins are very difficult to track. Just like western Union scams.
Moneypak and bitcoins are very difficult to track. Just like western Union scams.
I just had my first brush with Cryptolocker after someone opened an email attachment. Got a bit lucky. We detected it after only about two hours, but in that short space of time it still was able to encrypt 19998 files on a mapped drive before we got the user to shutdown their Terminal Server session. Thank god our backup routine worked without a hitch.
Only good thing about this virus is that it keeps a log of encrypted files in the registry and we were able to use that to make a concise list of files to restore.
Can't trace it, I remember reading just recently some place or person was hacked into and they took a pretty significant chunk of $$ in bitcoins from him, he said he didn't bother reporting it to the police though since it's so difficult to even attempt to track.
What scares me is while the main machines in our classrooms are frozen via Faronics, the networked drives are not, and a lot of those drives have R/W/E permissions for everyone set... Hell we have an instructor who is just deleting random shit on a network drive right now and breaking a program, i'd hate to see what would happen if this got loose.I just had my first brush with Cryptolocker after someone opened an email attachment. Got a bit lucky. We detected it after only about two hours, but in that short space of time it still was able to encrypt 19998 files on a mapped drive before we got the user to shutdown their Terminal Server session. Thank god our backup routine worked without a hitch.
Only good thing about this virus is that it keeps a log of encrypted files in the registry and we were able to use that to make a concise list of files to restore.
I offered my dad a 32gb usb3.0 flash drive to back his shit up onto.
Says he doesn't need it... Turns out, he writes everything down...
He knows well the only chance to getting the pictures back is paying, but there's also no guarantee. There are numerous instances of people paying the ransom and either not getting a decoder or not getting the correct one for their encryption. Then you're out of the money and the data.
I kind of doubt that is typical. If they make a habit of not providing the key after being paid, then people will just stop paying them. Still, even if there's no guarentee, if you care about the data, it's still your best bet. If you don't, you are guaranteed to never get it back.
It's difficult to quantify the likelihood of getting proper decryption in return, but it's definitely not a sure thing from some accounts. I don't think he cares much about the data, but the wife does (photos, memories, etc.), and that will probably win out. They still have some 40+ hours for the cheaper price anyway. I just told him to hold off at first, at least to see if it's legit. (I hadn't heard about it or seen this thread at the time.) It's definitely legit, and one of the most gnarly malware ever.
If true, it could be pretty nasty. However, there are a couple sites out there (InfoWorld and Ars Technica) that are fairly skeptical about its authenticity.
BadBios is the stuff of nightmares. Serious fucking nightmares, not that something encrypting your files and holding them for ransom is much better.
From everything I've read so far, it hasn't been found in the wild. I'm under the impression that the only security company/guru that has seen it is Dragos Ruiu.
http://www.reddit.com/r/sysadmin/com..._cryptolocker/
http://www.bleepingcomputer.com/viru...re-information
I'm working an IT helpdesk now. Two of our clients have been hit since September. The first one was our first experience with this, and it destroyed some medical records, and we had to restore from a backup from almost a year ago. The second one was spotted in progress for a client that only kept one day of backups (which will be changing very soon). We lost the work done that day since we restored the server from the backup, but the behaviour was spotted early before the next backup destroyed the good data. The second client had a version of the malware that was less than 24 hours old, so none of the hardware firewalls or malware scanning devices on the network stripped it, and the software didn't either, only one malware vendor at the time even flagged the file when submitted for analysis.
There's another way than off-site backups to recover from this. Running your servers as VMs, and backing them up outside of the VM can prevent the encryption from going after your backups. External backup devices in the server rack can also help.
The coders of this malware are reading the Reddit and Bleeping computer threads and apparently providing tech support for people that paid and didn't get their decryption keys. I guess, as the saying goes, "you have to be honest to live outside the law". Unfortunately, they're also keeping up on the threads of how IT people are stopping their software and blocking it. They email it as a phishing attempt, or drop it in via stuff like the Zeus botnet. It used to be a plain EXE or ZIP file, now they've password protected it to prevent the scanners from stopping it. People paying the ransom to get their data back are funding the updates to this malware, and those of us sharing information publicly are helping them bug test it and make it harder to block.
The one good thing to come out of this in the end will be that everyone will be aware of just how important 3-2-1 backup policy is (3 copies of the backup, 2 different physical storage media, 1 offsite backup) in recovering from data disasters. Businesses without a good backup policy (or any at all) will die from the data loss of this type of malware.
The type of files this targets for encryption points to it mainly being aimed at businesses. As they mainly take BitCoin (MoneyPak is only for people in the US), they've also jumped the price of BTC up over 100% since I first encountered this malware. It was under $200 USD in September, and I checked yesterday and got a value of $410 per BTC. The ransom has also changed from wanting 2 BTC to just 1, unless the 72 hours passes without being paid, then they jump up to 5-10 BTC and stop taking MoneyPak.
It's hard to track where the money goes because MoneyPak doesn't do chargebacks. BTC tracks every transaction for every BitCoin in the public bloackchain, but you have to have a way to tie the wallet the coin comes from to a physical entity, which means they have to exchange for physical goods or money. They are generating a different wallet for each person that pays the ransom, and don't seem to be cashing out the coins for money, so it's hard to trace. They're also taking payments through the TOR network, which makes an end IP hard to identify. Until the people taking the ransoms screw up the right way, with someone watching, they will be hard to catch. SilkRoad was only caught because the guy that started it screwed up early on in development of the site and deanonymized himself where people could see and check back later. Even then it took a few years to prove it enough to charge him.
Fucking scary shit. Please continue to share information.
And lol police paid the random:
http://www.networkworld.com/communit...olocker-ransom
Reading the article it almost sounds like they intentionally paid a ransom to try to investigate the virus and that it was a purposeful infection.
In the past month we've had 7 clients infected with the virus. The worst one had the virus encrypt their network shares then DFS replicated it to the cloud servers. Shadow copies were also encrypted... Then to make matters worse, it replicated to DR. This client literally lost 2 months worth of data because we had to go that far back.
This shit is easily the worst virus I've encountered. What we've been doing as a counter-measure is pitching offsite and offline backups to our clients. And to have the backups run on Linux boxes (since they're not targeted by the virus yet).
When I said "7 clients" I meant 7 different companies. Every encounter with the virus was always just 1 machine on the domain though. We push out Symantec Cloud now, used to be Symantec Endpoint Protection.
Sorry if it wasn't clear. I do outsourced IT/Infrastructure management for hedge funds. Unfortunately not in-house IT.
Whats everyone else here pushing out to their users in terms of virus/malware protection?