Popular Post Arthur Posted January 29, 2016 Popular Post Posted January 29, 2016 (edited) A new program from Malwarebytes specially for preventing ransomware infections on Windows PCs. Website / Download (Direct Link) For the last four years, ransomware has evolved into one of the biggest threats to cyber security that I’ve seen in a long time. Names like CryptoLocker, CryptoWall, and CTBLocker keep average computer users and IT security Jedis alike up at night. For good reason: Ransomware is cunning, effective, and proliferating, and the cyber security industry hasn’t really had an answer for it. But we’ve got one now. Ransomware is easy to understand but hard to beat. It infects the machine, encrypts all files and then demands payment to get the files back. Ransomware works so well that most variants will even remove themselves when the damage is done, knowing you have the choice of either paying the ransomware author to get your files back, or risk losing them forever. The ransomware we see today is so sophisticated that the advanced encryption it uses makes it impossible to get your files back without paying the ransom. Even using backup systems isn’t an effective countermeasure because ransomware would actively look for different types of backup systems and encrypt them, too. Most of today’s security software simply cannot protect you from ransomware. Ransomware does not act like traditional malware: some are automatically updated every day, and even use polymorphic (shapeshifting!) code to evade detection. This makes it exceedingly hard to detect. This is the type of challenge we love. When ransomware hit the headlines, we immediately started looking for a long-term answer. Our answer started with a company named EasySync Solutions, owned by Nathan Scott, which created an application called CryptoMonitor. CryptoMonitor was doing an excellent job of stopping ransomware at that time, but having a few ideas of our own, we acquired EasySync Solutions and hired Nathan to come work on stopping ransomware for us. Nathan has been leading the anti-ransomware technology development at Malwarebytes for the last few months. Now I’m stoked to announce that after months of late nights and a few hundred gallons of Red Bull, Malwarebytes Anti-Ransomware is ready for beta testing. As this is the very first beta we do encourage beta users to install the product in non-production environments for testing purposes. Installation is very straight forward. Simply download and install from the link below. You can safely install Malwarebytes Anti-Ransomware beta alongside Malwarebytes Anti-Malware and Malwarebytes Anti-Exploit. If you encounter a problem or false positive please read this. http://i.cubeupload.com/dyNBjg.png https://www.youtube.com/watch?v=WOkUhGlXnRg Edited January 31, 2016 by Arthur 6
MatthewL Posted January 29, 2016 Posted January 29, 2016 Think someone needs to forward this to Lincolnshire County Council! Systems been offline all week due to a ransom ware attack on systems, had a bit of a knock on affect to Fire and Rescue due to the same network, luckily control run a separate network but still bit close for comfort. 1
southhamster Posted January 30, 2016 Posted January 30, 2016 Yes. +1 that! We've now added malwarebytes pro to our administration PCs SLT laptops and server as Mcafee is pretty useless at catching a lot of dodgy stuff. Also found spice works alien vault picks up the odd IP probe to add to our block list.
Paid_Peanuts Posted January 31, 2016 Posted January 31, 2016 Yes. +1 that! We've now added malwarebytes pro to our administration PCs SLT laptops and server as Mcafee is pretty useless at catching a lot of dodgy stuff. Also found spice works alien vault picks up the odd IP probe to add to our block list. Just out of interest what was the cost of doing this?
speckytecky Posted January 31, 2016 Posted January 31, 2016 Thanks for posting this @Arthur it makes me wonder what Sophos and the other mainstream Security company's are doing about incorporating something that works like Maywarebytes into their products. As someone else responding to this thread has said we have Malwarebytes on our servers and main public accessing kit now. Malwarebytes seems to be leading this fight. This leaves me wondering what Governments as well are doing toward getting a grip on this issue? The scumbags who are making havoc and money out of this criminal activity need tracking down and having the full weight of justice coming down on them.
mrbios Posted January 31, 2016 Posted January 31, 2016 Once that's out of beta and built into the main product (as is often there way, test it separate, then couple it together) I think I'll be quite tempted to do what southhamster has done. On the same track, has anyone found a comprehensive list of all the potential cryptolocker protection techniques? There's quite a few now, some only apply to older versions of crypto and some only to newer, it's hard to keep track of all the different protections that need to be in place to protect ourselves against this.
Arthur Posted January 31, 2016 Author Posted January 31, 2016 (edited) MBAR quarantined Chrome Canary while I was trying to login to my Google Account and then prevented me from restoring it. A bit annoying, although I suppose that's to be expected while the program is in beta. http://i.cubeupload.com/945XDg.png http://i.cubeupload.com/z1iMYr.png Edited January 31, 2016 by Arthur
Arthur Posted January 31, 2016 Author Posted January 31, 2016 Once that's out of beta and built into the main product I don't think Anti-Ransomware will be integrated into the main Malwarebytes program since Anti-Exploit hasn't been. it makes me wonder what Sophos and the other mainstream security companies are doing about incorporating something that works like Malwarebytes into their products. Sophos recently purchased SurfRight who make the highly regarded Hitman Pro and Hitman Pro.Alert. Both of which will almost certainly be integrated into existing Sophos products. I hope Intel (McAfee) or Symantec don't end up buying Malwarebytes. That wouldn't be good! 1
southhamster Posted January 31, 2016 Posted January 31, 2016 Just out of interest what was the cost of doing this? I think it was around £15 per machine per year. The UK reseller we used was Computerworld Business Solutions T: 0121 643 5362 F: 0121 643 1267 W: www.cbs.cc who've been very helpful. Annoying to have to spend this kind of money on top of our Mcafee subscription, but at least we can protect our most important machines (hopefully...)
mrbios Posted January 31, 2016 Posted January 31, 2016 I don't think Anti-Ransomware will be integrated into the main Malwarebytes program since Anti-Exploit hasn't been. One of the MBAM employees confirmed it would be rolled into the main program the same way anti root kit was on the reddit /r/sysadmin page about this recently. I hope it goes that way anyway. 2
speckytecky Posted February 1, 2016 Posted February 1, 2016 We purchased a limited number of MWB licences from the company direct. It had to be paid for online on a card. I think it was around £15 per machine per year. The UK reseller we used was Computerworld Business Solutions T: 0121 643 5362 F: 0121 643 1267 W: www.cbs.cc who've been very helpful. Annoying to have to spend this kind of money on top of our Mcafee subscription, but at least we can protect our most important machines (hopefully...)
Arthur Posted February 1, 2016 Author Posted February 1, 2016 it's hard to keep track of all the different protections that need to be in place to protect ourselves against this. Given how ineffective tranditional anti-virus is at protecting against ransomware, perhaps we need to start looking at alternative products such as Palo Alto TRAPS or SentinelOne's EDR? 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now