Jump to content

Recommended Posts

Posted

Think someone needs to forward this to Lincolnshire County Council!

 

Systems been offline all week due to a ransom ware attack on systems, had a bit of a knock on affect to Fire and Rescue due to the same network, luckily control run a separate network but still bit close for comfort.

  • Thanks 1
Posted

Yes. +1 that!

We've now added malwarebytes pro to our administration PCs SLT laptops and server as Mcafee is pretty useless at catching a lot of dodgy stuff.

Also found spice works alien vault picks up the odd IP probe to add to our block list.

Posted
Yes. +1 that!

We've now added malwarebytes pro to our administration PCs SLT laptops and server as Mcafee is pretty useless at catching a lot of dodgy stuff.

Also found spice works alien vault picks up the odd IP probe to add to our block list.

 

Just out of interest what was the cost of doing this?

Posted
Thanks for posting this @Arthur it makes me wonder what Sophos and the other mainstream Security company's are doing about incorporating something that works like Maywarebytes into their products. As someone else responding to this thread has said we have Malwarebytes on our servers and main public accessing kit now. Malwarebytes seems to be leading this fight. This leaves me wondering what Governments as well are doing toward getting a grip on this issue? The scumbags who are making havoc and money out of this criminal activity need tracking down and having the full weight of justice coming down on them.
Posted

Once that's out of beta and built into the main product (as is often there way, test it separate, then couple it together) I think I'll be quite tempted to do what southhamster has done.

 

On the same track, has anyone found a comprehensive list of all the potential cryptolocker protection techniques? There's quite a few now, some only apply to older versions of crypto and some only to newer, it's hard to keep track of all the different protections that need to be in place to protect ourselves against this.

Posted (edited)

MBAR quarantined Chrome Canary while I was trying to login to my Google Account and then prevented me from restoring it. :(

 

A bit annoying, although I suppose that's to be expected while the program is in beta.

 

http://i.cubeupload.com/945XDg.png

 

http://i.cubeupload.com/z1iMYr.png

Edited by Arthur
Posted
Once that's out of beta and built into the main product

I don't think Anti-Ransomware will be integrated into the main Malwarebytes program since Anti-Exploit hasn't been.

 

it makes me wonder what Sophos and the other mainstream security companies are doing about incorporating something that works like Malwarebytes into their products.

Sophos recently purchased SurfRight who make the highly regarded Hitman Pro and Hitman Pro.Alert. Both of which will almost certainly be integrated into existing Sophos products.

 

I hope Intel (McAfee) or Symantec don't end up buying Malwarebytes. That wouldn't be good!

  • Thanks 1
Posted
Just out of interest what was the cost of doing this?

I think it was around £15 per machine per year. The UK reseller we used was

Computerworld Business Solutions

T: 0121 643 5362

F: 0121 643 1267

W: www.cbs.cc

 

who've been very helpful.

 

Annoying to have to spend this kind of money on top of our Mcafee subscription, but at least we can protect our most important machines (hopefully...)

Posted
I don't think Anti-Ransomware will be integrated into the main Malwarebytes program since Anti-Exploit hasn't been.

 

One of the MBAM employees confirmed it would be rolled into the main program the same way anti root kit was on the reddit /r/sysadmin page about this recently. I hope it goes that way anyway.

  • Thanks 2
Posted

We purchased a limited number of MWB licences from the company direct. It had to be paid for online on a card.

 

I think it was around £15 per machine per year. The UK reseller we used was

Computerworld Business Solutions

T: 0121 643 5362

F: 0121 643 1267

W: www.cbs.cc

 

who've been very helpful.

 

Annoying to have to spend this kind of money on top of our Mcafee subscription, but at least we can protect our most important machines (hopefully...)

Posted
it's hard to keep track of all the different protections that need to be in place to protect ourselves against this.

Given how ineffective tranditional anti-virus is at protecting against ransomware, perhaps we need to start looking at alternative products such as Palo Alto TRAPS or SentinelOne's EDR?

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...