halbaradkenafin Posted September 17, 2015 Posted September 17, 2015 Next steps is to stop exe's being saved all together. May have to redirect app data first however. File Screen rules are your friend for this. Server 2012R2 comes with an already defined Block Executables template and I'd guess 2008R2 does as well.
rrrrr Posted September 17, 2015 Posted September 17, 2015 Next steps is to stop exe's being saved all together. May have to redirect app data first however. We cant do this as students do VB programming for ICT
3s-gtech Posted September 17, 2015 Posted September 17, 2015 Any schools gone down the route of completely blocking zip files over email? our local council has in replacement of 7zip files. I'm thinking of doing the same Yup, from external senders. We're trying to get an SPF filter set up to prevent spoofed internal emails carrying a payload too.
halbaradkenafin Posted September 17, 2015 Posted September 17, 2015 For those who requested it: http://www.edugeek.net/forums/how-do-you-do/159149-cryptolocker-prevention.html#post1359677 2
sonofsanta Posted September 17, 2015 Posted September 17, 2015 Any schools gone down the route of completely blocking zip files over email? our local council has in replacement of 7zip files. I'm thinking of doing the same We set up a rule in Office 365 that any emails with ZIP (etc.) or HTML attachments get redirected to our shared mailbox to evaluate and pass on. We tried blocking outright only to find out how many people emailed ZIPs in with cover work. New system is a small amount extra work for us (probably a couple of emails a day) but also much better for stopping these outbreaks, as we are armed with the appropriate level of cynicism for the internet. [ATTACH=CONFIG]32170[/ATTACH] Incidentally, if anyone can work out a way of excluding ATT00001.HTM attachments from this rule, I'd be very grateful. I think it's iPads that arbitrarily put this attachment on, and it's a pain. HTML files are blocked, incidentally, due to the high volume of "fill out this tax rebate form!" emails people kept falling for
DCUK6 Posted September 17, 2015 Posted September 17, 2015 File Screen rules are your friend for this. Server 2012R2 comes with an already defined Block Executables template and I'd guess 2008R2 does as well. Just done it. Took all of two seconds. Yep the list is fairly big. Shame windows 7 doesnt have something like this that we could set with gpo. That way i dont have to redirect the appdata folder.
halbaradkenafin Posted September 17, 2015 Posted September 17, 2015 Just done it. Took all of two seconds. Yep the list is fairly big. Shame windows 7 doesnt have something like this that we could set with gpo. That way i dont have to redirect the appdata folder. You can do it in GPO using Software Restriction Policies, and using things like %temp% and %appdata% so it will work whether you redirect appdata or not.
Arthur Posted September 17, 2015 Posted September 17, 2015 That way I don't have to redirect the appdata folder. Redirecting the AppData folder is a bad idea since it affects performance. e.g. searching for programs on the Start menu will be incredibly slow. I would do what @halbaradkenafin suggested above (ideally through AppLocker, but if you don't have that then SRP).
mrnoisy Posted September 17, 2015 Posted September 17, 2015 Can you give me an example of the GPO and script used? Do you know what the route to infection was? zip file over email? hyperlink in email? etc Yep it was mail, infected word doc attached, sophos did not detect the new strain until a good few weeks after the event, and as normal with our sophos it detects loads but cleans up nowt !
mrnoisy Posted September 17, 2015 Posted September 17, 2015 In case anyone is interested we also trailed malware bytes enterprise anti exploit solution, it's awesome we are hoping to purchase it shortly.
rrrrr Posted September 17, 2015 Posted September 17, 2015 Yep it was mail, infected word doc attached, sophos did not detect the new strain until a good few weeks after the event, and as normal with our sophos it detects loads but cleans up nowt ! Macro virus in word? A software restriction policy wouldn't stop this
rrrrr Posted September 17, 2015 Posted September 17, 2015 File Screen rules are your friend for this. Server 2012R2 comes with an already defined Block Executables template and I'd guess 2008R2 does as well. If the virus is running from the appdata folder, i take it screen rules would only work if this has been redirected to a server location and not on the local machine?
halbaradkenafin Posted September 17, 2015 Posted September 17, 2015 Macro virus in word? A software restriction policy wouldn't stop this No but the Office GPOs will allow you to restrict the running of macros. Plus I'd imagine that the macro just downloads the exe for it and runs that rather than having the main payload itself.
rrrrr Posted September 17, 2015 Posted September 17, 2015 (edited) Did noones utm pick this up? The utm should detect malicious activity and block communication to blacklisted ip addresses? If the virus cannot communicate with the control server it cannot create an encryption key and wont encrypt files By the looks of it, it has the below home servers hard coded into it. By blocking communication to these should stop encryption taking place, if you was to be infected. Also alerting you of infected computer Edited September 17, 2015 by rrrrr
mrnoisy Posted September 17, 2015 Posted September 17, 2015 Did noones utm pick this up? The utm should detect malicious activity and block communication to blacklisted ip addresses? If the virus cannot communicate with the control server it cannot create an encryption key and wont encrypt files By the looks of it, it has the below home servers hard coded into it. By blocking communication to these should stop encryption taking place, if you was to be infected. Also alerting you of infected computer [ATTACH]32182[/ATTACH] Great if you know the ip's up front, when we got hit it took less than 20 minutes to encrypt all data across approximately 20 virtual servers, it's a clever virus just wish the people who make them would find something more productive to do [emoji3]
rrrrr Posted September 17, 2015 Posted September 17, 2015 Great if you know the ip's up front, when we got hit it took less than 20 minutes to encrypt all data across approximately 20 virtual servers, it's a clever virus just wish the people who make them would find something more productive to do [emoji3] Just thought it was another line of defence as this thread is now mainly how to defend against it moving forward. What utm do you use? Would have thought this should have stopped it using blacklisted ip's and ids. Did you have live protection enabled on sophos av?
mrnoisy Posted September 17, 2015 Posted September 17, 2015 Just thought it was another line of defence as this thread is now mainly how to defend against it moving forward. What utm do you use? Would have thought this should have stopped it using blacklisted ip's and ids. Did you have live protection enabled on sophos av? Yeah it's good advice wasn't having a go, we have smoothwall and no sophos live protection did nothing, I spoke to sophos at great length, not very helpful, told us to check all machines manually, yeah 2k machine no time for that. [emoji23]
bossman Posted September 17, 2015 Posted September 17, 2015 We had a narrow escape but thankfully only three workstations were infected, took them off the network immediately and rebuilt, checked out all the file servers for registry entries and also ran scans on all of the servers using Avast for business, we found one exe which had a number for its name in a users Appdata which Avast had quarantined and 4 files on the root folder of one mapped drive but no encrypted files, I have since turned up our security even tighter with whitelisting the appdata files through GPO and tightened up on our e-mail server with all known files extensions which are dodgy as well with the Spam filters on to the max in Zimbra, Clam antivirus updated to latest version and the users all locked down tight as I can possibly get them, I wouldn't mind though, the previous evening we had a safeguarding presentation from the LA and the presenter warned all staff about being extra vigilant with e-mails as there had been a spate of really bad ones which had caught a number of schools out. The next day we were hit and I have been on alert for the past 2 weeks, I have now been asked to open up the network with this damned BCS exams software from Enlight which requires of all things "Macros to be enabled!!!" in Excel plus totally reliant on Java, the website doesn't even have a decent certificate as our internet explorer came up with untrusted certificate when I first went to access it, absolutely ludicrous that the BCS of all societies should allow another company to run its exams in such a shoddy way!! Why did they not use Pearson as everyone else does? I could go on but I feel my role is getting increasingly more complex and frustrating as each term comes along does anyone else feel that way? Avast does claim that their product does detect all known variants of the cryptlocker ransomware but there maybe unknown variants out there just have to educate the Staff into being extra vigilant when accessing their e-mail and websites. Have fun everyone and listen "Lets be careful out there!"
gshaw Posted September 30, 2015 Posted September 30, 2015 Ohhh I remember the "joys" of Enlight and how it'd randomly crash and lose its connection to the app the user was being tested on. It also used to be very fussy about how the candidate performed certain actions, no keyboard shortcuts unless you wanted to fail 😕
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now