Jump to content

Recommended Posts

Posted
Samba 4 on Linux uses LVM snapshots for VSS emulation. There is no way to delete them from the client side as they are mounted read only.
Posted (edited)
Can assure you when I was hit with it the Server that hosted files wasn't impacted as we scanned that and checked and inspected it and all clean itself, we found 1 client that had the infection and all the files that user who's Pc it was got impacted but VSS had gone so I still don't believe a nix or other variant file server would have helped although I guess it depends on how it deleted the VSS snaps if it relied upon PowerShell that maybe a way around it as the Nix won't have that on it but it may have just gone in and deleted things and the user would have rights into those areas most likely....

 

Hi John and Geoff,

 

From what's been said/observed, I assume that the malware has the ability to remotely connect to a Windows Server (using RPC/Powershell/WMI) and delete the Shadow copies that way, or it could simply remotely run a command (e.g. vssadmin.exe delete shadows /all) on the server. Although all these methods would require admin rights (assume domain admin rights) on the target server. If a user with domain admin rights logs onto an infected PC the malware would inherit the admin rights and could delete the shadow copies from the target server, without actually infecting it.

 

So if this *is* the case, then non-Windows-based file servers should be protected (as it shouldn't understand the remote commands to delete the shadow copies - I assume). I mentioned our SAN is Linux based, it is actually NetApp, so I don't know if it uses SAMBA or something else, but if the above is correct, either way it should be protected.

 

Thanks,

 

Bruce.

Edited by Bruce123
Posted
Hi John and Geoff,

 

From what's been said/observed, I assume that the malware has the ability to remotely connect to a Windows Server (using RPC/Powershell/WMI) and delete the Shadow copies that way, or it could simply remotely run a command (e.g. vssadmin.exe delete shadows /all) on the server. Although all these methods would require admin rights (assume domain admin rights) on the target server. If a user with domain admin rights logs onto an infected PC the malware would inherit the admin rights and could delete the shadow copies from the target server, without actually infecting it.

 

So if this *is* the case, then non-Windows-based file servers should be protected (as it shouldn't understand the remote commands to delete the shadow copies - I assume). I mentioned our SAN is Linux based, it is actually NetApp, so I don't know if it uses SAMBA or something else, but if the above is correct, either way it should be protected.

 

Thanks,

 

Bruce.

 

I would suggest you talk to NetApp about how it would or wouldn't possibly work, in my case the user very much didn't have any rights to the server the data was on as it was a central file server so don't believe it required that level of rights to work.

Posted
My network got hit a few weeks ago by this. I had to restore the entire SIMs directory from backup as everything was renamed to .mp3 and encrypted. User who got it was member of staff. Somehow it didn't infect other network drives she had access to. I have SOPHOS endpoint protection and it's useless so looking for alternatives. I have completed a trial of Cylance PROTECT which is excellent but costs a bomb. £34 per endpoint per year to be exact. £12,000PA for my network!! Looking at Kaspersky at the moment and that comes in at just under £2900PA. Would love Cylance but it's just crazy money when we all have to save money in our budgets.
  • Thanks 1
Posted
My network got hit a few weeks ago by this. I had to restore the entire SIMs directory from backup as everything was renamed to .mp3 and encrypted. User who got it was member of staff. Somehow it didn't infect other network drives she had access to. I have SOPHOS endpoint protection and it's useless so looking for alternatives. I have completed a trial of Cylance PROTECT which is excellent but costs a bomb. £34 per endpoint per year to be exact. £12,000PA for my network!! Looking at Kaspersky at the moment and that comes in at just under £2900PA. Would love Cylance but it's just crazy money when we all have to save money in our budgets.

 

Our quote came in at 34k PA @Darylrese for Cylance. Sophos just doesn't seem to be doing its job for us at the moment. It doesn't detect stuff and when it does, 9 times out of 10 it can't clean up. Kaspersky price doesn't seem too bad to be honest, it's maybe worth looking into here @mrnoisy

Posted
I have completed a trial of Cylance PROTECT which is excellent but costs a bomb. £34 per endpoint per year to be exact. £12,000 PA for my network!!

Wow. That's expensive! Was £34 the educational price from Ignition Technology (UK Cylance distributor)?

Posted
Our quote came in at 34k PA @Darylrese for Cylance. Sophos just doesn't seem to be doing its job for us at the moment. It doesn't detect stuff and when it does, 9 times out of 10 it can't clean up. Kaspersky price doesn't seem too bad to be honest, it's maybe worth looking into here @mrnoisy

 

OMG! 34K...I do think its a fantastic product but that is crazy money. No school can afford that surely? I have already had this conversation with Cylance and I did get a discounted price eventually but it was still out of my reach.

 

The thing with education is you cant really put a price on your data because if the network goes down for a few days whilst you get things restored, it doesn't really have a cost implication. Therefore spending £34,000PA on AV isn't viable. I can totally understand it in a bank or business that makes large sums of money.

 

Kaspersky seems very good. Easy to deploy, good price and easy to use. SOPHOS has been useless for us. Deployment is very hit and miss. Requires loads of machine settings to work correctly and never reports correctly to the enterprise console. Also experienced everything you have mentioned. Had enough of it and moving away. I haven't tried ESET yet but I doubt it is much different to Kaspersky.

 

Anything has to be better than SOPHOS.

Posted
Wow. That's expensive! Was £34 the educational price from Ignition Technology (UK Cylance distributor)?

 

That was with a different provider, with educational pricing. I also went direct to Cylance for help on the pricing, I managed to get it down but was still out of my reach.

Posted
For those that use Gmail and are not sure how to block attachments

https://support.google.com/a/answer/2364580?hl=en

I've only blocked executables for now, but I may set up an attachment quarantine and block them all

 

Looks like Google automatically block executable or did you add others?

Note: For your protection, all executables are automatically rejected. You can also enter Custom file types to look for matches based on specific file extensions; for example, exe, bat, and cmd.
Posted
Surely preventative measures are the key to beating this?

 

Yes indeed, however in my experience no matter how much advice you give users there will always be a handful who will still open unknown emails and download junk from the internet. The best we can do is take good offsite backups, get permissions sorted and invest in a good AV.

Posted

Can't be too careful, I added "exe, ini, ins, iw, class, js, scr, vbs, com, pif, cpl, fon, asp, bat, cmd, hta, jse, shs, vb, vbe, ws, wsc, wsf, wsh" as per their file types and extensions.

 

I recently had a user that fell victim to a scam email that for all intents and purposes looked legit, it came from one of their contacts (who had obviously been hacked) and it had a Google doc download icon, that really wasn't a Google doc download icon, it was a hyperlink to a fake Google login page asking you to login in which they duly followed. Luckily they got in touch with me as the attachment wouldn't open and in their words said it keeps taking me to a login page, I just warned them and changed their password immediately.

 

No matter what we do end users are always the weakest point

  • 1 month later...
Posted

Good news for once!

 

TeslaCrypt shuts down and releases master decryption key / TeslaDecoder (Direct Download Link)

 

In surprising end to TeslaCrypt, the developers shut down their ransomware and released the master decryption key. Over the past few weeks, an analyst for ESET had noticed that the developers of TeslaCrypt have been slowly closing their doors, while their previous distributors have been switching over to distributing the CryptXXX ransomware.

 

When the ESET researcher realized what was happening, he took a shot in the dark and used the support chat on the Tesla payment site to ask if they would release the master TeslaCrypt decryption key. To his surprise and pleasure, they agreed to do so and posted it on their now defunct payment site.

 

Now that the decryption key has been made publicly available, this allowed TeslaCrypt expert BloodDolly to update TeslaDecoder to version 1.0 so that it can decrypt version 3.0 and version 4.0 of TeslaCrypt encrypted files. This means that anyone who has TeslasCrypt encrypted files with the .xxx, .ttt, .micro, .mp3, or encrypted files without an extension can now decrypt their files for free!

Posted
Excellent! We had it about a month ago and it encrypted our SIMs drive and a staffs home directory, was a total pain! Glad to hear its no longer a real threat.
Posted
Excellent! We had it about a month ago and it encrypted our SIMs drive and a staffs home directory, was a total pain! Glad to hear its no longer a real threat.

 

Do you know how you got it?

Posted
Do you know how you got it?

 

Not confirmed no but the member of staff checks her home email at work so i think it came through on an email.

 

It renamed everything to .mp3 including all her documents, all SIMs docs and system files and some of the shared drive. Luckily for me i take good daily backups and just restored everything over night and we were back up and running.

Posted
assume if a user was using the desktop apps, for onedrive, google or dropbox etc then got infected the encrypted files would then sync up to the cloud
Posted

So, let me be the one to ask the obvious question:

In summary... What can we really do?

We use SOPHOS here which, as mentioned, is hit and miss for deployment - never mind actually picking things up!

 

File extensions are locked down in shared drives (exceptions in one folder, to allow Small Basic applications to run).

 

But isn't this one of those situations where you can only be re-active? Not pro-active? WE don't know what hideous ransomware is going to come out next, so can't really stop it? Or can we... Am I missing something?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...