Jump to content

Recommended Posts

Posted (edited)

Just a quick post, just finished a day from hell.

A new strain of TeslaCrypt is doing the rounds.

Undetected by Sophos/malware bytes etc.

Look for any remanent files will the following string.

_recovery_(5 digit string). And the usual file extensions, .txt, .doc, html,png

Nasty little :censored: encrypts files as .mp3.

 

I'll update the post with further info when we're back to normal.

Beware this is a new strain, stay vigilant !

Edited by ZeroHour
  • Thanks 3
Posted
yes we had this the other week only that i was crytolocker it effected our SIMS server and our Staff server, all in all we was only down a day or so thank god for veeam !!
Posted

For a bit of a newbie how do you go about starting to isolate something like this? / finding the cause?

 

We have had a few schools by up hit by ransomware so swotting up on it.

 

Cheers

Posted
Yep, back up and running in a day also thanks to VEEAM, took a while to isolate though.

The restore is just finishing up now! I think the cider is coming out after the day we have had!

  • Thanks 1
Posted
The restore is just finishing up now! I think the cider is coming out after the day we have had!

You mind you don't get one of your migraines [emoji12]

Posted
Had this on a teacher's laptop and Sophos did sod all to stop it - luckily they're diligent and back up their own files often (on to an external drive, no less!). One re-image later, issue is fixed.
Posted (edited)
For a bit of a newbie how do you go about starting to isolate something like this? / finding the cause?

 

We have had a few schools by up hit by ransomware so swotting up on it.

 

Cheers

 

You can find a few guides on the internet for setting up File Resources Manager to handle specific extension types. It requires keeping on top of once new versions of ransomware come about.

 

This is one I followed. I didn't set up the batch file to run but might be worth doing.

 

You can also setup File Resource Manager to block certain file types running in specific areas on a computer. So for example, you can stop exe files from running in the TEMP folder.

Edited by RLR
  • Thanks 1
Posted (edited)
For a bit of a newbie how do you go about starting to isolate something like this? / finding the cause?

 

We have had a few schools by up hit by ransomware so swotting up on it.

 

Cheers

 

It'll most likely come in on a compromised webpage, or more often an advert. Keeping your AV updated is one of the best ways of stopping something like this but as the above shows - not always useful as AV companies are continually playing catch-up and you may be unlucky enough to be in the first 'wave' of infection.

 

If you're lucky (unlucky?) enough to be about and notice one hit (I have actually seen this happen!) then first move is to unplug the infected machine from the network, hell - if you can't find it isolate the server instead. That way, you can hopefully minimise any spread and deal with infected clients one by one.

 

Still, as you can't prevent something like this happening (only reduce the chance) - a good backup solution is a handy safety net. At least then in the event of getting caught - you still have your data.

Edited by korifugi
Posted
Been called into a school that got hit by this, unfortunately the small site used Windows Backup, which was using VSS, and, you guessed it, that got deleted too, so really not in a good place, took two weeks to report it so sod all I could do to stop it having encrypted everything unfortunately.
Posted (edited)
Been called into a school that got hit by this, unfortunately the small site used Windows Backup, which was using VSS, and, you guessed it, that got deleted too, so really not in a good place, took two weeks to report it so sod all I could do to stop it having encrypted everything unfortunately.

 

Setup some FSRM monitoring! Our's e-mails me with the machine information, and the user telling them to shutdown their laptop ASAP.

 

https://community.spiceworks.com/how_to/100368-cryptolocker-canary-detect-it-early

Edited by Blue_Cookeh
Posted
You can find a few guides on the internet for setting up File Resources Manager to handle specific extension types. It requires keeping on top of once new versions of ransomware come about.

 

This is one I followed. I didn't set up the batch file to run but might be worth doing.

 

You can also setup File Resource Manager to block certain file types running in specific areas on a computer. So for example, you can stop exe files from running in the TEMP folder.

 

 

Looks like I've got something to do today!, i did have a load of restricted file/extensions/paths disabled in GPO but it stopped one piece of software working and had to be disabled :(

Posted

just found this list if anyone is interested:

 

*.aaa

*.crjoker

*.cryptotorlocker*

*.ecc

*.encrypted

*.exx

*.ezz

*.frtrss

*.hydracrypt_ID*

*.locky

*.micro

*.r5a

*.ttt

*.vault

*.vvv

*.xxx

*gmail*.crypt

*recover_instruction*.*

*restore_fi*.*

*want your files back.*

confirmation.key

cryptolocker.*

decrypt_instruct*.*

enc_files.txt

help_decrypt*.*

help_recover*.*

help_restore*.*

help_your_file*.*

how to decrypt*.*

how_recover*.*

how_to_decrypt*.*

how_to_recover*.*

howto_restore*.*

howtodecrypt*.*

install_tor*.*

last_chance.txt

message.txt

readme_decrypt*.*

readme_for_decrypt*.*

recovery_file.txt

recovery_key.txt

vault.hta

vault.key

vault.txt

your_files.url

recovery+*.*

*.cerber

decrypt my file*.*

  • Thanks 1
Posted

We got off with it likely last week! One student reported that he couldn't access any of his work and it had all changed to MP3s along with generating the recovery files!

Luckily the only data that was affected was his own user space and the shared drive students have access to, so just restored from previous nights backup.

 

Didn't spread anywhere else luckily, but had it been a member of staff it would have affected multiple network drives as encrypted all writable drives only.

 

Source appears to have come from an internet site as he was looking for unblocked games!

 

Our local council got hit with it in Jan, and I know another couple of schools that have had it.

 

Just fortunate ours was on a very small scale. System is quite locked down though, all shares have .exe files blocked along with blocking of zips, exe on removable devices and block exe files running in profiles and temp folders!

Posted
Adding to this, and maybe a bit off topic - Does anyone have a nicely worded email about email attachments and what to and not to open that i could get a copy of?
Posted
We were stuck with this because it adds the MP3 extension onto files when it encrypts them. Also the ransom notes had a five random characters in the name which makes it hard to automatically detect them.
Posted (edited)

Out is interest did you find the point of origin? I'd be keen to find out.

In my experiences it has always been email attachments, users sneakily accessing personal accounts.

A combination of antivirus and filtering has provided a breadcrumb trail.

Edited by Mr_Jiminy
Posted
We think that the user in question had downloaded what they thought was Firefox. @mrnoisy ran the .exe which was downloaded overnight last night on a standalone machine and it seems that it was the source of entry.
Posted
We just had this too, luckily we quickly isolated the infected client, and restored from backup. Sophos did sod all to stop it.

 

Malwarebytes was the first thing I ran on the client it was initiated by, and that didn't pick anything up either.

Posted
Beware this is a new strain, stay vigilant!

Some anti-virus vendors are falsely detecting the ransomware as TeslaCrypt. It's actually Locky. :(

 

Spike in ransomware spam prompts warnings « BBC News

 

Security firms are warning about a sudden "huge" surge in junk mail messages containing ransomware.

 

The surge is being blamed on the group behind a novel strain of ransomware called Locky.

 

One security firm reported that a version of Locky produced two weeks ago is now the second most prevalent form of ransomware it sees.

 

The US, France and Japan were the top targets for the gang behind Locky, statistics suggested.

 

The first versions of Locky hid the malicious attachment that did the encrypting in add-ons or macros for Microsoft Word. Now, say security firms, its creators have switched to using attachments written in Javascript.

 

"We are currently seeing extraordinarily huge volumes of Javascript attachments being spammed out," said Rodel Mendrez, a security expert at Trustwave in a blogpost.

 

The switch to Javascript has helped Locky avoid being spotted by anti-virus software, said Trustwave.

 

[...]

 

The attackers sending out large amounts of Locky spam were using the same network of hijacked computers, known as a botnet, that was used to distribute the Dridex banking trojan.

 

"It's the same botnet, different day, and different payload," said Mr Mendrez.

 

Massive Volume of Ransomware Downloaders being Spammed « TrustWave

 

The notorious payloads of ransomware have been covered many times in blogs and mainstream media. This type of malware has a very destructive payload. Here's a walkthrough on how this ransomware gets propagated and infects a system. This particular spam campaign was sending a JavaScript attachment that downloads Locky ransomware:

 

http://i.cubeupload.com/2jyteO.png

 

http://i.cubeupload.com/G5jp47.png

Posted

 

All good stuff to know but this is not what we had, unlike 6months ago when we had a new strain of crypto locker which we never actually found the root files for , TeslaCrypt this time was found but totally undetected by AV or malware bytes. This particular strain was very cleaver as on the machine which was infected it disguised itself as Sophos files, now we are back to normal I will be sending all the files to Sophos, although by the time they update it may be too late for most people.

  • Thanks 1
Posted

Sorry to hijack this thread, but out of curiosity what av/ endpoint solutions should we be looking at the ensure more peace of mind against such threats?

 

Obviously I'm aware of need for beefing up software restriction policies and the routine upkeep of that, but I'm keen to find out if any of the av/ endpoint products are worth the money.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...