Jump to content

Recommended Posts

Posted (edited)

Got hit by the CryptoWall 3.0 this morning, four files; HELP_DECRYPT.TXT, HELP_DECRYPT.PNG, HELP_DECRYPT.URL AND HELP_DECRYPT.HTML.

 

I'm guessing if the users had opened the URL or HTML it could have been a disaster, as it stands the file screening prevented the *.url/ html files from propagating to anywhere other than the media shared location... An oversight on my part and now also file screening for all web page files on this folder, other folders were file screening for web page files in accordance with our default policy.

 

Thankfully nothing was encrypted and only needed to scan and purge the aforementioned files, as well as looking at the file attributes for one of the files to associate a user to the outbreak. Interesting enough the AV remote admin console highlighted the threat (not as crpytowall), claimed to remove, yet really it did b*gger all. From this however, I managed to track what I believe was the client is originated from.

 

Fingers are quite literally crossed at this end.

Edited by Mr_Jiminy
Posted
Interesting enough the AV remote admin console highlighted the threat (not as crpytowall), claimed to remove, yet really it did b*gger all. From this however, I managed to track what I believe was the client is originated from.

 

Fingers are quite literally crossed at this end.

 

Which AV out of interest?

Posted (edited)
Got hit by the CryptoWall 3.0 this morning, four files; HELP_DECRYPT.TXT, HELP_DECRYPT.PNG, HELP_DECRYPT.URL AND HELP_DECRYPT.HTML.

 

I'm guessing if the users had opened the URL or HTML it could have been a disaster,

I doubt it. Your files are already encrypted. HELP_DECRYPT.URL is likely just pointing to a website that says "Oi. Give us bitcoins, yeah?" and the .HTML will likely be a local copy (combined with the .PNG, but the .PNG might also be a desktop background)

 

Get yer' backups sorted, reimage machines, get better AV.

Also taser-on-a-stick end-user education.

Edited by Garacesh
Posted (edited)
I doubt it. Your files are already encrypted. HELP_DECRYPT.URL is likely just pointing to a website that says "Oi. Give us bitcoins, yeah?" and the .HTML will likely be a local copy (combined with the .PNG, but the .PNG might also be a desktop background)

 

Get yer' backups sorted, reimage machines, get better AV.

Also taser-on-a-stick end-user education.

 

Indeed, already reimaged what we believe is/was the infected client.

 

Not convinced about the files actually being encrypted, unless it uses a scatter gun approach to randomly move files. One of the locations definitely didn't have files in that area prior to the infection. My sneaking suspicion is it created them to make it look like it had it encrypted files.

 

What AV would people recommend? We're are actually going into a tender process come next month, so recommendations would be helpful.

Edited by Mr_Jiminy
Posted (edited)

We use Sophos Endpoint here. It's worked wonders for quarantining naughties and letting us know.

 

Whether it looks like things are encrypted or not, restore from backup on those servers. You never know what it might have left laying around.. If I were writing a virus working with network shares, I'd occasionally make it replace $item.png/docx/etc with $item.exe so it could propagate further.

Edited by Garacesh
  • Thanks 1
Posted

 

What AV would people recommend? We're are actually going into a tender process come next month, so recommendations would be helpful.

 

Kaspersky was the only one that was straight out with detection for the version we got hit with earlier in the year and that trend seemed to continue of them being first out with new updates and protection over all the others, Symantec Endpoint Protection was one of the last to get it guess what we currently use.... :(

@Net-Ctrl are Kaspersky vendors and very helpful with it so well worth giving them a shout when its time :)

  • Thanks 1
Posted

Thank you for the mention @john.

@Mr_Jiminy if you would like to include Kaspersky and Net-Ctrl in your tender bid, please let me know and i'll be happy help.

 

In the meantime if you have any initial questions, send them over and i'll get some answers/info over to you.

 

Josh

Posted

Yeah we're now in the process of restoring a sizable quantity of data back to a 'before state'.

 

The unfortunate situation is the length time in which it went unnoticed and the loss of data in-between that period to present date... Still, it could be worse!

 

Thanks re all suggestions about antivirus solutions.

Posted
As much as some don't like it, we can't fault Sophos.

 

And at £1 per device per year, it's great value for money. https://www.phoenixs.co.uk/swgfl-sophos/

 

 

I'm using SCEP, with all the crypto crap going around I'm seriously thinking of switching to something a bit more proactive. I'm jus ta bit wary of sophos since when we had it from the LA 6+ years ago it murdered performance

Posted

This thread has reminded me that I haven't posted a quick guide for the various Cryptolocker prevention I've put in place. If all goes well and it works as intended (touch wood) then we'll at worst have to restore one folder on one share and that's all (and image the machine of course).

 

I'll try to get it posted today or tomorrow.

Posted
I'm using SCEP, with all the crypto crap going around I'm seriously thinking of switching to something a bit more proactive. I'm jus ta bit wary of sophos since when we had it from the LA 6+ years ago it murdered performance

 

SSDs in machines cover up many of Sophos' sins. It's still heavier than something like ESET but we've got too many servers that would need changing to make moving over worthwhile.

Posted (edited)
This thread has reminded me that I haven't posted a quick guide for the various Cryptolocker prevention I've put in place. If all goes well and it works as intended (touch wood) then we'll at worst have to restore one folder on one share and that's all (and image the machine of course).

 

I'll try to get it posted today or tomorrow.

 

 

i had a few GPOS enabled to stop it but as usual shoddy education software has meant disabling it...

 

SSDs in machines cover up many of Sophos' sins. It's still heavier than something like ESET but we've got too many servers that would need changing to make moving over worthwhile.

 

I introduced the SLT in one school to SSD's in their new laptops recently and all I've had since is complaints about everything else being slow.. :( might be time for an upgrade everywhere :p

Edited by DGardiner
Posted
i had a few GPOS enabled to stop it but as usual shoddy education software has meant disabling it...

 

We've got some GPOs (main thing was not allowing files to run from the Temp file locations) but also some file server rules that check for the creation of the ransom files, once they find them it pings off an email to myself and the network manager with username, file name and location and also runs a Powershell script to kill that users access to all file shares on all the file servers. Testing has shown that access is cut within seconds of the files appearing, thankfully we haven't been hit with it yet and I don't really want to either.

Posted

I feel for you our school got hit, luckily in some respect 3 days from the end of term, encrypted just about all data areas, we rolled back about a week, we use sophos, it was completely up to date, unfortunately it did not detect the virus at the time, it does now.

Sophos where next to useless, let me know if you need any help it's a nasty virus the new strain, we never hot presented with the ransom. Fortunately due to the timing we didn't really loose anything, would have been so much worse if it had been term time.

Posted
We've got some GPOs (main thing was not allowing files to run from the Temp file locations) but also some file server rules that check for the creation of the ransom files, once they find them it pings off an email to myself and the network manager with username, file name and location and also runs a Powershell script to kill that users access to all file shares on all the file servers. Testing has shown that access is cut within seconds of the files appearing, thankfully we haven't been hit with it yet and I don't really want to either.

 

Can you give me an example of the GPO and script used?

 

I feel for you our school got hit, luckily in some respect 3 days from the end of term, encrypted just about all data areas, we rolled back about a week, we use sophos, it was completely up to date, unfortunately it did not detect the virus at the time, it does now.

 

Do you know what the route to infection was? zip file over email? hyperlink in email? etc

Posted
We've got some GPOs (main thing was not allowing files to run from the Temp file locations) but also some file server rules that check for the creation of the ransom files, once they find them it pings off an email to myself and the network manager with username, file name and location and also runs a Powershell script to kill that users access to all file shares on all the file servers. Testing has shown that access is cut within seconds of the files appearing, thankfully we haven't been hit with it yet and I don't really want to either.

 

I wish to subscribe to your newsletter*.

 

*forum post.

Posted
Can you give me an example of the GPO and script used?

 

 

 

I wish to subscribe to your newsletter*.

 

*forum post.

 

I'm in the process of documenting it for our own records and will post it up to the "How do you do it" forum once that's done. I'll also include various links that I've used to compile the information.

 

Do you know what the route to infection was? zip file over email? hyperlink in email? etc

 

There are some strains that are delivering through Flash ads/banners as well, which is just one more reason that Flash needs to be shoved into a very deep hole and forgotten about.

Posted
Any schools gone down the route of completely blocking zip files over email? our local council has in replacement of 7zip files. I'm thinking of doing the same
Posted

So far to help us ive got a GPO with software restrictions on both the computers and users. If you do it on just the users it doesnt stop everything. Disabled is set to default. Takes a bit of setting up as things like the quicklaunch etc has to be unlocked. Have chosen to block lnk files as well.

 

Got AV all round.

 

Just testing out ad blocker on our ict machines which has gone well.

 

Next steps is to stop exe's being saved all together. May have to redirect app data first however.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...