mrnoisy Posted March 9, 2016 Posted March 9, 2016 (edited) Just a quick post, just finished a day from hell. A new strain of TeslaCrypt is doing the rounds. Undetected by Sophos/malware bytes etc. Look for any remanent files will the following string. _recovery_(5 digit string). And the usual file extensions, .txt, .doc, html,png Nasty little encrypts files as .mp3. I'll update the post with further info when we're back to normal. Beware this is a new strain, stay vigilant ! Edited March 9, 2016 by ZeroHour 3
kevin_lane Posted March 9, 2016 Posted March 9, 2016 yes we had this the other week only that i was crytolocker it effected our SIMS server and our Staff server, all in all we was only down a day or so thank god for veeam !!
mrnoisy Posted March 9, 2016 Author Posted March 9, 2016 Yep, back up and running in a day also thanks to VEEAM, took a while to isolate though.
tj2419 Posted March 9, 2016 Posted March 9, 2016 For a bit of a newbie how do you go about starting to isolate something like this? / finding the cause? We have had a few schools by up hit by ransomware so swotting up on it. Cheers
jdoldridge Posted March 9, 2016 Posted March 9, 2016 Yep, back up and running in a day also thanks to VEEAM, took a while to isolate though. The restore is just finishing up now! I think the cider is coming out after the day we have had! 1
mrnoisy Posted March 9, 2016 Author Posted March 9, 2016 The restore is just finishing up now! I think the cider is coming out after the day we have had! You mind you don't get one of your migraines [emoji12]
korifugi Posted March 10, 2016 Posted March 10, 2016 Had this on a teacher's laptop and Sophos did sod all to stop it - luckily they're diligent and back up their own files often (on to an external drive, no less!). One re-image later, issue is fixed.
RLR Posted March 10, 2016 Posted March 10, 2016 (edited) For a bit of a newbie how do you go about starting to isolate something like this? / finding the cause? We have had a few schools by up hit by ransomware so swotting up on it. Cheers You can find a few guides on the internet for setting up File Resources Manager to handle specific extension types. It requires keeping on top of once new versions of ransomware come about. This is one I followed. I didn't set up the batch file to run but might be worth doing. You can also setup File Resource Manager to block certain file types running in specific areas on a computer. So for example, you can stop exe files from running in the TEMP folder. Edited March 10, 2016 by RLR 1
lostsoul Posted March 10, 2016 Posted March 10, 2016 We just had this too, luckily we quickly isolated the infected client, and restored from backup. Sophos did sod all to stop it.
korifugi Posted March 10, 2016 Posted March 10, 2016 (edited) For a bit of a newbie how do you go about starting to isolate something like this? / finding the cause? We have had a few schools by up hit by ransomware so swotting up on it. Cheers It'll most likely come in on a compromised webpage, or more often an advert. Keeping your AV updated is one of the best ways of stopping something like this but as the above shows - not always useful as AV companies are continually playing catch-up and you may be unlucky enough to be in the first 'wave' of infection. If you're lucky (unlucky?) enough to be about and notice one hit (I have actually seen this happen!) then first move is to unplug the infected machine from the network, hell - if you can't find it isolate the server instead. That way, you can hopefully minimise any spread and deal with infected clients one by one. Still, as you can't prevent something like this happening (only reduce the chance) - a good backup solution is a handy safety net. At least then in the event of getting caught - you still have your data. Edited March 10, 2016 by korifugi
mowgli82 Posted March 10, 2016 Posted March 10, 2016 Is there is comprehensive list of strings anywhere? or would anyone mind sharing theirs?
gomalley Posted March 10, 2016 Posted March 10, 2016 Been called into a school that got hit by this, unfortunately the small site used Windows Backup, which was using VSS, and, you guessed it, that got deleted too, so really not in a good place, took two weeks to report it so sod all I could do to stop it having encrypted everything unfortunately.
Blue_Cookeh Posted March 10, 2016 Posted March 10, 2016 (edited) Been called into a school that got hit by this, unfortunately the small site used Windows Backup, which was using VSS, and, you guessed it, that got deleted too, so really not in a good place, took two weeks to report it so sod all I could do to stop it having encrypted everything unfortunately. Setup some FSRM monitoring! Our's e-mails me with the machine information, and the user telling them to shutdown their laptop ASAP. https://community.spiceworks.com/how_to/100368-cryptolocker-canary-detect-it-early Edited March 10, 2016 by Blue_Cookeh
DGardiner Posted March 10, 2016 Posted March 10, 2016 You can find a few guides on the internet for setting up File Resources Manager to handle specific extension types. It requires keeping on top of once new versions of ransomware come about. This is one I followed. I didn't set up the batch file to run but might be worth doing. You can also setup File Resource Manager to block certain file types running in specific areas on a computer. So for example, you can stop exe files from running in the TEMP folder. Looks like I've got something to do today!, i did have a load of restricted file/extensions/paths disabled in GPO but it stopped one piece of software working and had to be disabled
mowgli82 Posted March 10, 2016 Posted March 10, 2016 just found this list if anyone is interested: *.aaa *.crjoker *.cryptotorlocker* *.ecc *.encrypted *.exx *.ezz *.frtrss *.hydracrypt_ID* *.locky *.micro *.r5a *.ttt *.vault *.vvv *.xxx *gmail*.crypt *recover_instruction*.* *restore_fi*.* *want your files back.* confirmation.key cryptolocker.* decrypt_instruct*.* enc_files.txt help_decrypt*.* help_recover*.* help_restore*.* help_your_file*.* how to decrypt*.* how_recover*.* how_to_decrypt*.* how_to_recover*.* howto_restore*.* howtodecrypt*.* install_tor*.* last_chance.txt message.txt readme_decrypt*.* readme_for_decrypt*.* recovery_file.txt recovery_key.txt vault.hta vault.key vault.txt your_files.url recovery+*.* *.cerber decrypt my file*.* 1
ITGURU Posted March 10, 2016 Posted March 10, 2016 We got off with it likely last week! One student reported that he couldn't access any of his work and it had all changed to MP3s along with generating the recovery files! Luckily the only data that was affected was his own user space and the shared drive students have access to, so just restored from previous nights backup. Didn't spread anywhere else luckily, but had it been a member of staff it would have affected multiple network drives as encrypted all writable drives only. Source appears to have come from an internet site as he was looking for unblocked games! Our local council got hit with it in Jan, and I know another couple of schools that have had it. Just fortunate ours was on a very small scale. System is quite locked down though, all shares have .exe files blocked along with blocking of zips, exe on removable devices and block exe files running in profiles and temp folders!
DGardiner Posted March 10, 2016 Posted March 10, 2016 Adding to this, and maybe a bit off topic - Does anyone have a nicely worded email about email attachments and what to and not to open that i could get a copy of?
jdoldridge Posted March 10, 2016 Posted March 10, 2016 We were stuck with this because it adds the MP3 extension onto files when it encrypts them. Also the ransom notes had a five random characters in the name which makes it hard to automatically detect them.
Mr_Jiminy Posted March 10, 2016 Posted March 10, 2016 (edited) Out is interest did you find the point of origin? I'd be keen to find out. In my experiences it has always been email attachments, users sneakily accessing personal accounts. A combination of antivirus and filtering has provided a breadcrumb trail. Edited March 10, 2016 by Mr_Jiminy
jdoldridge Posted March 10, 2016 Posted March 10, 2016 We think that the user in question had downloaded what they thought was Firefox. @mrnoisy ran the .exe which was downloaded overnight last night on a standalone machine and it seems that it was the source of entry.
ITGURU Posted March 10, 2016 Posted March 10, 2016 We just had this too, luckily we quickly isolated the infected client, and restored from backup. Sophos did sod all to stop it. Malwarebytes was the first thing I ran on the client it was initiated by, and that didn't pick anything up either.
Arthur Posted March 10, 2016 Posted March 10, 2016 Beware this is a new strain, stay vigilant! Some anti-virus vendors are falsely detecting the ransomware as TeslaCrypt. It's actually Locky. Spike in ransomware spam prompts warnings « BBC News Security firms are warning about a sudden "huge" surge in junk mail messages containing ransomware. The surge is being blamed on the group behind a novel strain of ransomware called Locky. One security firm reported that a version of Locky produced two weeks ago is now the second most prevalent form of ransomware it sees. The US, France and Japan were the top targets for the gang behind Locky, statistics suggested. The first versions of Locky hid the malicious attachment that did the encrypting in add-ons or macros for Microsoft Word. Now, say security firms, its creators have switched to using attachments written in Javascript. "We are currently seeing extraordinarily huge volumes of Javascript attachments being spammed out," said Rodel Mendrez, a security expert at Trustwave in a blogpost. The switch to Javascript has helped Locky avoid being spotted by anti-virus software, said Trustwave. [...] The attackers sending out large amounts of Locky spam were using the same network of hijacked computers, known as a botnet, that was used to distribute the Dridex banking trojan. "It's the same botnet, different day, and different payload," said Mr Mendrez. Massive Volume of Ransomware Downloaders being Spammed « TrustWave The notorious payloads of ransomware have been covered many times in blogs and mainstream media. This type of malware has a very destructive payload. Here's a walkthrough on how this ransomware gets propagated and infects a system. This particular spam campaign was sending a JavaScript attachment that downloads Locky ransomware: http://i.cubeupload.com/2jyteO.png http://i.cubeupload.com/G5jp47.png
mrnoisy Posted March 10, 2016 Author Posted March 10, 2016 Some anti-virus vendors are falsely detecting the ransomware as TeslaCrypt. It's actually Locky. Spike in ransomware spam prompts warnings « BBC News Massive Volume of Ransomware Downloaders being Spammed « TrustWave All good stuff to know but this is not what we had, unlike 6months ago when we had a new strain of crypto locker which we never actually found the root files for , TeslaCrypt this time was found but totally undetected by AV or malware bytes. This particular strain was very cleaver as on the machine which was infected it disguised itself as Sophos files, now we are back to normal I will be sending all the files to Sophos, although by the time they update it may be too late for most people. 1
Mr_Jiminy Posted March 11, 2016 Posted March 11, 2016 Sorry to hijack this thread, but out of curiosity what av/ endpoint solutions should we be looking at the ensure more peace of mind against such threats? Obviously I'm aware of need for beefing up software restriction policies and the routine upkeep of that, but I'm keen to find out if any of the av/ endpoint products are worth the money.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now