Mr_Jiminy Posted September 15, 2015 Posted September 15, 2015 (edited) Got hit by the CryptoWall 3.0 this morning, four files; HELP_DECRYPT.TXT, HELP_DECRYPT.PNG, HELP_DECRYPT.URL AND HELP_DECRYPT.HTML. I'm guessing if the users had opened the URL or HTML it could have been a disaster, as it stands the file screening prevented the *.url/ html files from propagating to anywhere other than the media shared location... An oversight on my part and now also file screening for all web page files on this folder, other folders were file screening for web page files in accordance with our default policy. Thankfully nothing was encrypted and only needed to scan and purge the aforementioned files, as well as looking at the file attributes for one of the files to associate a user to the outbreak. Interesting enough the AV remote admin console highlighted the threat (not as crpytowall), claimed to remove, yet really it did b*gger all. From this however, I managed to track what I believe was the client is originated from. Fingers are quite literally crossed at this end. Edited September 15, 2015 by Mr_Jiminy
gshaw Posted September 15, 2015 Posted September 15, 2015 Interesting enough the AV remote admin console highlighted the threat (not as crpytowall), claimed to remove, yet really it did b*gger all. From this however, I managed to track what I believe was the client is originated from. Fingers are quite literally crossed at this end. Which AV out of interest?
Mr_Jiminy Posted September 15, 2015 Author Posted September 15, 2015 I really don't want to say, out of shame... AVG. ***runs off to locate stocks and basket of rotten tomatoes***
Mr_Jiminy Posted September 15, 2015 Author Posted September 15, 2015 Here's the capture of the files in the media folder.
Garacesh Posted September 15, 2015 Posted September 15, 2015 (edited) Got hit by the CryptoWall 3.0 this morning, four files; HELP_DECRYPT.TXT, HELP_DECRYPT.PNG, HELP_DECRYPT.URL AND HELP_DECRYPT.HTML. I'm guessing if the users had opened the URL or HTML it could have been a disaster, I doubt it. Your files are already encrypted. HELP_DECRYPT.URL is likely just pointing to a website that says "Oi. Give us bitcoins, yeah?" and the .HTML will likely be a local copy (combined with the .PNG, but the .PNG might also be a desktop background) Get yer' backups sorted, reimage machines, get better AV. Also taser-on-a-stick end-user education. Edited September 15, 2015 by Garacesh
Mr_Jiminy Posted September 15, 2015 Author Posted September 15, 2015 (edited) I doubt it. Your files are already encrypted. HELP_DECRYPT.URL is likely just pointing to a website that says "Oi. Give us bitcoins, yeah?" and the .HTML will likely be a local copy (combined with the .PNG, but the .PNG might also be a desktop background) Get yer' backups sorted, reimage machines, get better AV. Also taser-on-a-stick end-user education. Indeed, already reimaged what we believe is/was the infected client. Not convinced about the files actually being encrypted, unless it uses a scatter gun approach to randomly move files. One of the locations definitely didn't have files in that area prior to the infection. My sneaking suspicion is it created them to make it look like it had it encrypted files. What AV would people recommend? We're are actually going into a tender process come next month, so recommendations would be helpful. Edited September 15, 2015 by Mr_Jiminy
halbaradkenafin Posted September 15, 2015 Posted September 15, 2015 CryptoWall/Locker/etc go through each mapped drive and encrypt each folder in turn, after it encrypts a folder it drops those files in it to let people know how to recover their data. 1
Garacesh Posted September 15, 2015 Posted September 15, 2015 (edited) We use Sophos Endpoint here. It's worked wonders for quarantining naughties and letting us know. Whether it looks like things are encrypted or not, restore from backup on those servers. You never know what it might have left laying around.. If I were writing a virus working with network shares, I'd occasionally make it replace $item.png/docx/etc with $item.exe so it could propagate further. Edited September 15, 2015 by Garacesh 1
john Posted September 15, 2015 Posted September 15, 2015 What AV would people recommend? We're are actually going into a tender process come next month, so recommendations would be helpful. Kaspersky was the only one that was straight out with detection for the version we got hit with earlier in the year and that trend seemed to continue of them being first out with new updates and protection over all the others, Symantec Endpoint Protection was one of the last to get it guess what we currently use.... @Net-Ctrl are Kaspersky vendors and very helpful with it so well worth giving them a shout when its time 1
Net-Ctrl Posted September 15, 2015 Posted September 15, 2015 Thank you for the mention @john. @Mr_Jiminy if you would like to include Kaspersky and Net-Ctrl in your tender bid, please let me know and i'll be happy help. In the meantime if you have any initial questions, send them over and i'll get some answers/info over to you. Josh
sippo Posted September 15, 2015 Posted September 15, 2015 As much as some don't like it, we can't fault Sophos. And at £1 per device per year, it's great value for money. https://www.phoenixs.co.uk/swgfl-sophos/
Mr_Jiminy Posted September 15, 2015 Author Posted September 15, 2015 Yeah we're now in the process of restoring a sizable quantity of data back to a 'before state'. The unfortunate situation is the length time in which it went unnoticed and the loss of data in-between that period to present date... Still, it could be worse! Thanks re all suggestions about antivirus solutions.
DGardiner Posted September 15, 2015 Posted September 15, 2015 As much as some don't like it, we can't fault Sophos. And at £1 per device per year, it's great value for money. https://www.phoenixs.co.uk/swgfl-sophos/ I'm using SCEP, with all the crypto crap going around I'm seriously thinking of switching to something a bit more proactive. I'm jus ta bit wary of sophos since when we had it from the LA 6+ years ago it murdered performance
halbaradkenafin Posted September 15, 2015 Posted September 15, 2015 This thread has reminded me that I haven't posted a quick guide for the various Cryptolocker prevention I've put in place. If all goes well and it works as intended (touch wood) then we'll at worst have to restore one folder on one share and that's all (and image the machine of course). I'll try to get it posted today or tomorrow.
gshaw Posted September 15, 2015 Posted September 15, 2015 I'm using SCEP, with all the crypto crap going around I'm seriously thinking of switching to something a bit more proactive. I'm jus ta bit wary of sophos since when we had it from the LA 6+ years ago it murdered performance SSDs in machines cover up many of Sophos' sins. It's still heavier than something like ESET but we've got too many servers that would need changing to make moving over worthwhile.
DGardiner Posted September 15, 2015 Posted September 15, 2015 (edited) This thread has reminded me that I haven't posted a quick guide for the various Cryptolocker prevention I've put in place. If all goes well and it works as intended (touch wood) then we'll at worst have to restore one folder on one share and that's all (and image the machine of course). I'll try to get it posted today or tomorrow. i had a few GPOS enabled to stop it but as usual shoddy education software has meant disabling it... SSDs in machines cover up many of Sophos' sins. It's still heavier than something like ESET but we've got too many servers that would need changing to make moving over worthwhile. I introduced the SLT in one school to SSD's in their new laptops recently and all I've had since is complaints about everything else being slow.. might be time for an upgrade everywhere Edited September 15, 2015 by DGardiner
halbaradkenafin Posted September 15, 2015 Posted September 15, 2015 i had a few GPOS enabled to stop it but as usual shoddy education software has meant disabling it... We've got some GPOs (main thing was not allowing files to run from the Temp file locations) but also some file server rules that check for the creation of the ransom files, once they find them it pings off an email to myself and the network manager with username, file name and location and also runs a Powershell script to kill that users access to all file shares on all the file servers. Testing has shown that access is cut within seconds of the files appearing, thankfully we haven't been hit with it yet and I don't really want to either.
cpjitservices Posted September 16, 2015 Posted September 16, 2015 We had A client where this happened, client was using Avast... Previous versions and good backups prevented any data loss and they have now moved over to Eset.
mrnoisy Posted September 16, 2015 Posted September 16, 2015 I feel for you our school got hit, luckily in some respect 3 days from the end of term, encrypted just about all data areas, we rolled back about a week, we use sophos, it was completely up to date, unfortunately it did not detect the virus at the time, it does now. Sophos where next to useless, let me know if you need any help it's a nasty virus the new strain, we never hot presented with the ransom. Fortunately due to the timing we didn't really loose anything, would have been so much worse if it had been term time.
rrrrr Posted September 17, 2015 Posted September 17, 2015 We've got some GPOs (main thing was not allowing files to run from the Temp file locations) but also some file server rules that check for the creation of the ransom files, once they find them it pings off an email to myself and the network manager with username, file name and location and also runs a Powershell script to kill that users access to all file shares on all the file servers. Testing has shown that access is cut within seconds of the files appearing, thankfully we haven't been hit with it yet and I don't really want to either. Can you give me an example of the GPO and script used? I feel for you our school got hit, luckily in some respect 3 days from the end of term, encrypted just about all data areas, we rolled back about a week, we use sophos, it was completely up to date, unfortunately it did not detect the virus at the time, it does now. Do you know what the route to infection was? zip file over email? hyperlink in email? etc
sonofsanta Posted September 17, 2015 Posted September 17, 2015 We've got some GPOs (main thing was not allowing files to run from the Temp file locations) but also some file server rules that check for the creation of the ransom files, once they find them it pings off an email to myself and the network manager with username, file name and location and also runs a Powershell script to kill that users access to all file shares on all the file servers. Testing has shown that access is cut within seconds of the files appearing, thankfully we haven't been hit with it yet and I don't really want to either. I wish to subscribe to your newsletter*. *forum post.
halbaradkenafin Posted September 17, 2015 Posted September 17, 2015 Can you give me an example of the GPO and script used? I wish to subscribe to your newsletter*. *forum post. I'm in the process of documenting it for our own records and will post it up to the "How do you do it" forum once that's done. I'll also include various links that I've used to compile the information. Do you know what the route to infection was? zip file over email? hyperlink in email? etc There are some strains that are delivering through Flash ads/banners as well, which is just one more reason that Flash needs to be shoved into a very deep hole and forgotten about.
Garacesh Posted September 17, 2015 Posted September 17, 2015 I wish to subscribe to your newsletter*. *forum post. THANK YOU for subscribing to Cat Facts!
rrrrr Posted September 17, 2015 Posted September 17, 2015 Any schools gone down the route of completely blocking zip files over email? our local council has in replacement of 7zip files. I'm thinking of doing the same
DCUK6 Posted September 17, 2015 Posted September 17, 2015 So far to help us ive got a GPO with software restrictions on both the computers and users. If you do it on just the users it doesnt stop everything. Disabled is set to default. Takes a bit of setting up as things like the quicklaunch etc has to be unlocked. Have chosen to block lnk files as well. Got AV all round. Just testing out ad blocker on our ict machines which has gone well. Next steps is to stop exe's being saved all together. May have to redirect app data first however.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now