caffrey Posted March 11, 2016 Posted March 11, 2016 This is one thing that legit scares me, feels like it's only a matter of time before it hits here, I've already sent emails telling end users not to open unsolicited attachments, I've done as much as I can but I've explained to management that with our disaster management as it is, it would take quite a while to recover
Arthur Posted March 11, 2016 Posted March 11, 2016 (edited) out of curiosity what av/endpoint solutions should we be looking at the ensure more peace of mind against such threats? I am currently looking into Microsoft's Advanced Threat Protection for Exchange Online (for Office 365 Education) and CylancePROTECT. The former costs £10.44 per user/year (so £1,566 for 150 FTEs), while the latter I am still trying to find out a price for. If it ends up being too expensive I guess there's always Malwarebytes Anti-malware and Anti-Exploit. The Cylance anti-virus software looks very impressive based on the reviews/demos I have seen online. www.scmagazine.com/cylanceprotect/review/4419/ Edited March 11, 2016 by Arthur 1
mrnoisy Posted March 11, 2016 Author Posted March 11, 2016 @MrJiminy, good question, we tried Malware Bytes endpoint protection last year, amazing product but they did not have an educational pricing structure, it was circa 40k over 3 years which clearly is beyond the reach of most schools, I've just mailed them to find out if things have changed with regards to pricing, if not what are the alternatives, I'm not aware of any other products !
Arthur Posted March 11, 2016 Posted March 11, 2016 I'm not aware of any other products! HitmanPro for Enterprise + EMET?
The_IT_Guy Posted March 18, 2016 Posted March 18, 2016 What concerns me is now what they are saying in that most people have their backups connected to the network. If an admin account was the source of the problem would that mean your backups become encrypted as well? How do you get around that? A dangerous piece of PC ransomware is now impossible to crack According to this article the FBI are saying that more variants are searching for backups to encrypt? Does anyone have a written procedure in place for if your network became infected by a ransomware or virus? Thinking of putting something in place.
Geoff Posted March 18, 2016 Posted March 18, 2016 You need to restore from before the point of infection. This requires that you be able to detected the infection in a timely manner and have backups going back far enough that you can do a restore successfully. Our detection time is minutes for known ransomware and worst case so far 24 hours for unknown. Our backups go back 12 months.
jaminben Posted March 18, 2016 Posted March 18, 2016 Our detection time is minutes for known ransomware and worst case so far 24 hours for unknown. How do you know in minutes?
bossman Posted March 18, 2016 Posted March 18, 2016 I had this piece of information sent to me yesterday: According to recent reports, massive volumes of JavaScript attachments are being spammed out that contain dangerous ransomware. We recommend taking the following additional precautions to protect your install base: • Make sure your mail protection solution is blocking macro-enabled documents and .js scripts • Ensure that you have blocked user access to downloading Tor by blacklisting the following URL:https://www.torproject.org/download/download-easy.html(the Locky virus in particular relies on downloading and installing the Tor browser and some versions may use Tor to contact the command and control servers) • Disable Java in client browsers (for more information, see the following links) • And we suggest that access to the following IPs be completely blocked at the firewall: ◦ 5.34.183.195 ◦ 51.254.19.227 ◦ 185.14.29.188 ◦ 31.184.197.119 ◦ 91.219.29.55 Also a link: https://nakedsecurity.sophos.com/2016/02/17/locky-ransomware-what-you-need-to-know/ It seems the variants are getting very clever and we look like we are fighting a desperate battle! Just asking staff to be ultra vigilant when viewing e-mails etc is like plaiting fog!
DGardiner Posted March 18, 2016 Posted March 18, 2016 I had this piece of information sent to me yesterday: According to recent reports, massive volumes of JavaScript attachments are being spammed out that contain dangerous ransomware. We recommend taking the following additional precautions to protect your install base: • Make sure your mail protection solution is blocking macro-enabled documents and .js scripts • Ensure that you have blocked user access to downloading Tor by blacklisting the following URL:https://www.torproject.org/download/download-easy.html(the Locky virus in particular relies on downloading and installing the Tor browser and some versions may use Tor to contact the command and control servers) • Disable Java in client browsers (for more information, see the following links) • And we suggest that access to the following IPs be completely blocked at the firewall: ◦ 5.34.183.195 ◦ 51.254.19.227 ◦ 185.14.29.188 ◦ 31.184.197.119 ◦ 91.219.29.55 Also a link: https://nakedsecurity.sophos.com/2016/02/17/locky-ransomware-what-you-need-to-know/ It seems the variants are getting very clever and we look like we are fighting a desperate battle! Just asking staff to be ultra vigilant when viewing e-mails etc is like plaiting fog! its starting to become the daily chore of keeping up with these things 1
mowgli82 Posted March 18, 2016 Posted March 18, 2016 Where did you get the list of IP's from? I looked at the article in the link and couldn't see them.
ITGuyWestMidlands Posted March 18, 2016 Posted March 18, 2016 I now force all office attachments into quarantine and release as needed. Macros are disabled without nofitificaton for all except sso report users. Applocker whitelisting and emetic in place. Flash and silver light updated asap Not sure what else we can do
rrrrr Posted March 19, 2016 Posted March 19, 2016 I now force all office attachments into quarantine and release as needed. Macros are disabled without nofitificaton for all except sso report users. Applocker whitelisting and emetic in place. Flash and silver light updated asap Not sure what else we can do Its good to make any needed plugins "click to run" to stop hidden inline frame malicious applets running as well as any compromised adverts. IPS and Air Gapped backups too.
Mr_Jiminy Posted March 19, 2016 Posted March 19, 2016 Not a brilliant start for me: https://community.office365.com/en-us/f/158/t/413882
caffrey Posted March 19, 2016 Posted March 19, 2016 For those that use Gmail and are not sure how to block attachments https://support.google.com/a/answer/2364580?hl=en I've only blocked executables for now, but I may set up an attachment quarantine and block them all We had an incident with phishing emails this week though, not sure how to stop that, it was one of those with a fake google doc attachment that redirects you to a fake google login page to steal your password, good job the end user phoned me asking why the attachment wasn't opening (It was from a genuine sender and looked really innocuous) I dread to think if anyone else has done it. All I can do is keep sending users blanket emails to be vigilant
Arthur Posted March 21, 2016 Posted March 21, 2016 Not a brilliant start for me: https://community.office365.com/en-us/f/158/t/413882 Spotted this in the admin portal. Common Attachment Types Filter is a new Exchange Online Protection feature. This feature will start rolling out today and should be completed over the coming weeks. How does this affect me? There is a new feature that provides an easy-to-setup method of filtering out unwanted and potentially malicious attachments by their file types. This feature only requires one click to turn on, and can easily be configured from a list of the file types commonly found to be dangerous. This will also help in consolidating attachment filtering within a malware policy rather than through multiple Exchange transport rules. The feature resides within the Malware Policy page in the Exchange Admin Center, and can be accessed by going under the Protection tab on the left and the malware filter tab on the top. From there, you can choose between creating a new malware policy where the most commonly abused files are preselected by default or editing an existing one to include the new functionality. What do I need to do to prepare for this change? This feature has administrative controls to enable and disable in your Exchange admin portal. This feature is off by default. You may turn it on in an existing or newly-created malware policy. Click Additional Information to learn more. 2
ITGuyWestMidlands Posted March 21, 2016 Posted March 21, 2016 Saw that a while ago. Still waiting for it to be added to ours
DGardiner Posted March 21, 2016 Posted March 21, 2016 Is there anything that can be done with google apps to stop the delivery of these things? i mean 99% of suspect emails go straight to spam - stopping them turning up without killing legit traffic would be a decent help
Bruce123 Posted March 21, 2016 Posted March 21, 2016 (edited) Hi, Is there any further news on the TeslaCrypt variant? We were hit a couple of weeks ago, but the effect was limited to the network drives that infected user had write-access to, which fortunately wasn't very much. We were able to restore the user's home folder and several shared folders that they had write-access to, from a recent shadow copy. We notice that Symantec EndPoint Protection didn't do anything to detect or stop it (and I understand from forums that other AV firms were slow to detect it). With recent updates, are they now able to detect it? According to: Achievement Locked: New Crypto-Ransomware Pwns Video Gamers | Bromium Labs It attempts to delete shadow copies using the Windows command: vssadmin.exe delete shadows /all I assume that this command is only capable of deleting local volume shadow copies (and only if it has admin rights). I wonder if this command is capable of deleting shadow copies of remote servers (as would usually be the case when non-admin users are affected)? Of course, if the malware infects a Windows server which is used for storage of files, and a user logs on with admin rights, then it is a different matter. This malware also puts into the question backup systems that depend on Disk to Disk backups, especially those that use Microsoft technologies (such as Microsoft Data Protection Manager). And one of the poor aspects of DPM is that it doesn't allow you to use an inbound firewall, as certain types of backups require the agent to initiate the connection to the DPM server. Many Thanks, Bruce. Edited March 21, 2016 by Bruce123
gaz350b Posted March 21, 2016 Posted March 21, 2016 Shadow copies are deleted server side I can confirm this
Bruce123 Posted March 21, 2016 Posted March 21, 2016 Shadow copies are deleted server side I can confirm this But does the server have to be infected, or can they be deleted by an infected client? Our files are stored on a SAN (Linux) with no Windows server infront of it, so cannot be infected by this malware. Thanks, Bruce.
john Posted March 22, 2016 Posted March 22, 2016 But does the server have to be infected, or can they be deleted by an infected client? Our files are stored on a SAN (Linux) with no Windows server infront of it, so cannot be infected by this malware. Thanks, Bruce. If the user gets it on the PC they are using it doesn;t matter what OS your file server is if the user has rights it will encrypt it and bye bye files
Bruce123 Posted March 22, 2016 Posted March 22, 2016 If the user gets it on the PC they are using it doesn;t matter what OS your file server is if the user has rights it will encrypt it and bye bye files Sorry, I was just referring to deleting the shadow copies (on servers) from an infected client. I suspect it can't, and where shadow copies have been deleted it was because the OS hosting the file system was infected. Thanks, Bruce.
john Posted March 22, 2016 Posted March 22, 2016 Sorry, I was just referring to deleting the shadow copies (on servers) from an infected client. I suspect it can't, and where shadow copies have been deleted it was because the OS hosting the file system was infected. Thanks, Bruce. Can assure you when I was hit with it the Server that hosted files wasn't impacted as we scanned that and checked and inspected it and all clean itself, we found 1 client that had the infection and all the files that user who's Pc it was got impacted but VSS had gone so I still don't believe a nix or other variant file server would have helped although I guess it depends on how it deleted the VSS snaps if it relied upon PowerShell that maybe a way around it as the Nix won't have that on it but it may have just gone in and deleted things and the user would have rights into those areas most likely....
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now