Geoff Posted March 22, 2016 Posted March 22, 2016 Samba 4 on Linux uses LVM snapshots for VSS emulation. There is no way to delete them from the client side as they are mounted read only.
Bruce123 Posted March 23, 2016 Posted March 23, 2016 (edited) Can assure you when I was hit with it the Server that hosted files wasn't impacted as we scanned that and checked and inspected it and all clean itself, we found 1 client that had the infection and all the files that user who's Pc it was got impacted but VSS had gone so I still don't believe a nix or other variant file server would have helped although I guess it depends on how it deleted the VSS snaps if it relied upon PowerShell that maybe a way around it as the Nix won't have that on it but it may have just gone in and deleted things and the user would have rights into those areas most likely.... Hi John and Geoff, From what's been said/observed, I assume that the malware has the ability to remotely connect to a Windows Server (using RPC/Powershell/WMI) and delete the Shadow copies that way, or it could simply remotely run a command (e.g. vssadmin.exe delete shadows /all) on the server. Although all these methods would require admin rights (assume domain admin rights) on the target server. If a user with domain admin rights logs onto an infected PC the malware would inherit the admin rights and could delete the shadow copies from the target server, without actually infecting it. So if this *is* the case, then non-Windows-based file servers should be protected (as it shouldn't understand the remote commands to delete the shadow copies - I assume). I mentioned our SAN is Linux based, it is actually NetApp, so I don't know if it uses SAMBA or something else, but if the above is correct, either way it should be protected. Thanks, Bruce. Edited March 23, 2016 by Bruce123
john Posted March 24, 2016 Posted March 24, 2016 Hi John and Geoff, From what's been said/observed, I assume that the malware has the ability to remotely connect to a Windows Server (using RPC/Powershell/WMI) and delete the Shadow copies that way, or it could simply remotely run a command (e.g. vssadmin.exe delete shadows /all) on the server. Although all these methods would require admin rights (assume domain admin rights) on the target server. If a user with domain admin rights logs onto an infected PC the malware would inherit the admin rights and could delete the shadow copies from the target server, without actually infecting it. So if this *is* the case, then non-Windows-based file servers should be protected (as it shouldn't understand the remote commands to delete the shadow copies - I assume). I mentioned our SAN is Linux based, it is actually NetApp, so I don't know if it uses SAMBA or something else, but if the above is correct, either way it should be protected. Thanks, Bruce. I would suggest you talk to NetApp about how it would or wouldn't possibly work, in my case the user very much didn't have any rights to the server the data was on as it was a central file server so don't believe it required that level of rights to work.
Arthur Posted March 24, 2016 Posted March 24, 2016 Where did you get the list of IP's from? Here are some more... Website of security certification provider spreading ransomware Indicators of Compromise (IOCs) Bedep C&C servers 89.163.240.118 / kjnoa9sdi3mrlsdnfi[.]com 85.25.41.95 / moregoodstafsforus[.]com 89.163.241.90 / jimmymorisonguitars[.]com 162.244.32.121 / bookersmartest[.]xyz TeslaCrypt C&C servers 50.87.127.96 / mkis[.]org 213.186.33.104 / tradinbow[.]com
DGardiner Posted March 29, 2016 Posted March 29, 2016 Petya ransomware reportedly encrypts hard drives, manipulates operating system boot process joy....
Arthur Posted March 29, 2016 Posted March 29, 2016 joy. At least that ransomware is easy to protect yourself against if you have relatively modern PCs. www.edugeek.net/forums/how-do-you-do/159149-cryptolocker-prevention-4.html#post1439788
Darylrese Posted April 5, 2016 Posted April 5, 2016 My network got hit a few weeks ago by this. I had to restore the entire SIMs directory from backup as everything was renamed to .mp3 and encrypted. User who got it was member of staff. Somehow it didn't infect other network drives she had access to. I have SOPHOS endpoint protection and it's useless so looking for alternatives. I have completed a trial of Cylance PROTECT which is excellent but costs a bomb. £34 per endpoint per year to be exact. £12,000PA for my network!! Looking at Kaspersky at the moment and that comes in at just under £2900PA. Would love Cylance but it's just crazy money when we all have to save money in our budgets. 1
jdoldridge Posted April 5, 2016 Posted April 5, 2016 My network got hit a few weeks ago by this. I had to restore the entire SIMs directory from backup as everything was renamed to .mp3 and encrypted. User who got it was member of staff. Somehow it didn't infect other network drives she had access to. I have SOPHOS endpoint protection and it's useless so looking for alternatives. I have completed a trial of Cylance PROTECT which is excellent but costs a bomb. £34 per endpoint per year to be exact. £12,000PA for my network!! Looking at Kaspersky at the moment and that comes in at just under £2900PA. Would love Cylance but it's just crazy money when we all have to save money in our budgets. Our quote came in at 34k PA @Darylrese for Cylance. Sophos just doesn't seem to be doing its job for us at the moment. It doesn't detect stuff and when it does, 9 times out of 10 it can't clean up. Kaspersky price doesn't seem too bad to be honest, it's maybe worth looking into here @mrnoisy
Arthur Posted April 5, 2016 Posted April 5, 2016 I have completed a trial of Cylance PROTECT which is excellent but costs a bomb. £34 per endpoint per year to be exact. £12,000 PA for my network!! Wow. That's expensive! Was £34 the educational price from Ignition Technology (UK Cylance distributor)?
Darylrese Posted April 5, 2016 Posted April 5, 2016 Our quote came in at 34k PA @Darylrese for Cylance. Sophos just doesn't seem to be doing its job for us at the moment. It doesn't detect stuff and when it does, 9 times out of 10 it can't clean up. Kaspersky price doesn't seem too bad to be honest, it's maybe worth looking into here @mrnoisy OMG! 34K...I do think its a fantastic product but that is crazy money. No school can afford that surely? I have already had this conversation with Cylance and I did get a discounted price eventually but it was still out of my reach. The thing with education is you cant really put a price on your data because if the network goes down for a few days whilst you get things restored, it doesn't really have a cost implication. Therefore spending £34,000PA on AV isn't viable. I can totally understand it in a bank or business that makes large sums of money. Kaspersky seems very good. Easy to deploy, good price and easy to use. SOPHOS has been useless for us. Deployment is very hit and miss. Requires loads of machine settings to work correctly and never reports correctly to the enterprise console. Also experienced everything you have mentioned. Had enough of it and moving away. I haven't tried ESET yet but I doubt it is much different to Kaspersky. Anything has to be better than SOPHOS.
Darylrese Posted April 5, 2016 Posted April 5, 2016 Wow. That's expensive! Was £34 the educational price from Ignition Technology (UK Cylance distributor)? That was with a different provider, with educational pricing. I also went direct to Cylance for help on the pricing, I managed to get it down but was still out of my reach.
ITGuyWestMidlands Posted April 5, 2016 Posted April 5, 2016 Surely preventative measures are the key to beating this?
TwistedHelixis Posted April 5, 2016 Posted April 5, 2016 For those that use Gmail and are not sure how to block attachments https://support.google.com/a/answer/2364580?hl=en I've only blocked executables for now, but I may set up an attachment quarantine and block them all Looks like Google automatically block executable or did you add others? Note: For your protection, all executables are automatically rejected. You can also enter Custom file types to look for matches based on specific file extensions; for example, exe, bat, and cmd.
Darylrese Posted April 5, 2016 Posted April 5, 2016 Surely preventative measures are the key to beating this? Yes indeed, however in my experience no matter how much advice you give users there will always be a handful who will still open unknown emails and download junk from the internet. The best we can do is take good offsite backups, get permissions sorted and invest in a good AV.
caffrey Posted April 6, 2016 Posted April 6, 2016 Can't be too careful, I added "exe, ini, ins, iw, class, js, scr, vbs, com, pif, cpl, fon, asp, bat, cmd, hta, jse, shs, vb, vbe, ws, wsc, wsf, wsh" as per their file types and extensions. I recently had a user that fell victim to a scam email that for all intents and purposes looked legit, it came from one of their contacts (who had obviously been hacked) and it had a Google doc download icon, that really wasn't a Google doc download icon, it was a hyperlink to a fake Google login page asking you to login in which they duly followed. Luckily they got in touch with me as the attachment wouldn't open and in their words said it keeps taking me to a login page, I just warned them and changed their password immediately. No matter what we do end users are always the weakest point
Geoff Posted April 6, 2016 Posted April 6, 2016 For stuff like Google accounts set up two factor auth.
Arthur Posted May 19, 2016 Posted May 19, 2016 Good news for once! TeslaCrypt shuts down and releases master decryption key / TeslaDecoder (Direct Download Link) In surprising end to TeslaCrypt, the developers shut down their ransomware and released the master decryption key. Over the past few weeks, an analyst for ESET had noticed that the developers of TeslaCrypt have been slowly closing their doors, while their previous distributors have been switching over to distributing the CryptXXX ransomware. When the ESET researcher realized what was happening, he took a shot in the dark and used the support chat on the Tesla payment site to ask if they would release the master TeslaCrypt decryption key. To his surprise and pleasure, they agreed to do so and posted it on their now defunct payment site. Now that the decryption key has been made publicly available, this allowed TeslaCrypt expert BloodDolly to update TeslaDecoder to version 1.0 so that it can decrypt version 3.0 and version 4.0 of TeslaCrypt encrypted files. This means that anyone who has TeslasCrypt encrypted files with the .xxx, .ttt, .micro, .mp3, or encrypted files without an extension can now decrypt their files for free!
Darylrese Posted May 19, 2016 Posted May 19, 2016 Excellent! We had it about a month ago and it encrypted our SIMs drive and a staffs home directory, was a total pain! Glad to hear its no longer a real threat.
Whisky Posted May 19, 2016 Posted May 19, 2016 Excellent! We had it about a month ago and it encrypted our SIMs drive and a staffs home directory, was a total pain! Glad to hear its no longer a real threat. Do you know how you got it?
Darylrese Posted May 19, 2016 Posted May 19, 2016 Do you know how you got it? Not confirmed no but the member of staff checks her home email at work so i think it came through on an email. It renamed everything to .mp3 including all her documents, all SIMs docs and system files and some of the shared drive. Luckily for me i take good daily backups and just restored everything over night and we were back up and running.
caffrey Posted May 19, 2016 Posted May 19, 2016 (edited) edit *oops i cant read* Edited May 19, 2016 by caffrey
network41 Posted May 19, 2016 Posted May 19, 2016 Just recovered from "Angler" encrypted a load of stuff , what a pain. All restored from backups, hey ho
ozydave Posted May 19, 2016 Posted May 19, 2016 assume if a user was using the desktop apps, for onedrive, google or dropbox etc then got infected the encrypted files would then sync up to the cloud
GRitchie Posted May 19, 2016 Posted May 19, 2016 So, let me be the one to ask the obvious question: In summary... What can we really do? We use SOPHOS here which, as mentioned, is hit and miss for deployment - never mind actually picking things up! File extensions are locked down in shared drives (exceptions in one folder, to allow Small Basic applications to run). But isn't this one of those situations where you can only be re-active? Not pro-active? WE don't know what hideous ransomware is going to come out next, so can't really stop it? Or can we... Am I missing something?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now