Jump to content

Recommended Posts

Posted
This is one thing that legit scares me, feels like it's only a matter of time before it hits here, I've already sent emails telling end users not to open unsolicited attachments, I've done as much as I can but I've explained to management that with our disaster management as it is, it would take quite a while to recover
Posted (edited)
out of curiosity what av/endpoint solutions should we be looking at the ensure more peace of mind against such threats?

I am currently looking into Microsoft's Advanced Threat Protection for Exchange Online (for Office 365 Education) and CylancePROTECT. The former costs £10.44 per user/year (so £1,566 for 150 FTEs), while the latter I am still trying to find out a price for. If it ends up being too expensive I guess there's always Malwarebytes Anti-malware and Anti-Exploit.

 

The Cylance anti-virus software looks very impressive based on the reviews/demos I have seen online.

 

www.scmagazine.com/cylanceprotect/review/4419/

 

 

Edited by Arthur
  • Thanks 1
Posted
@MrJiminy, good question, we tried Malware Bytes endpoint protection last year, amazing product but they did not have an educational pricing structure, it was circa 40k over 3 years which clearly is beyond the reach of most schools, I've just mailed them to find out if things have changed with regards to pricing, if not what are the alternatives, I'm not aware of any other products !
Posted

What concerns me is now what they are saying in that most people have their backups connected to the network. If an admin account was the source of the problem would that mean your backups become encrypted as well?

 

How do you get around that?

 

A dangerous piece of PC ransomware is now impossible to crack

 

According to this article the FBI are saying that more variants are searching for backups to encrypt?

 

Does anyone have a written procedure in place for if your network became infected by a ransomware or virus? Thinking of putting something in place.

Posted
You need to restore from before the point of infection. This requires that you be able to detected the infection in a timely manner and have backups going back far enough that you can do a restore successfully. Our detection time is minutes for known ransomware and worst case so far 24 hours for unknown. Our backups go back 12 months.
Posted

I had this piece of information sent to me yesterday:

 

According to recent reports, massive volumes of JavaScript attachments are being spammed out that contain dangerous ransomware. We recommend taking the following additional precautions to protect your install base:

• Make sure your mail protection solution is blocking macro-enabled documents and .js scripts

• Ensure that you have blocked user access to downloading Tor by blacklisting the following URL:https://www.torproject.org/download/download-easy.html(the Locky virus in particular relies on downloading and installing the Tor browser and some versions may use Tor to contact the command and control servers)

• Disable Java in client browsers (for more information, see the following links)

• And we suggest that access to the following IPs be completely blocked at the firewall:

 

◦ 5.34.183.195

◦ 51.254.19.227

◦ 185.14.29.188

◦ 31.184.197.119

◦ 91.219.29.55

 

Also a link: https://nakedsecurity.sophos.com/2016/02/17/locky-ransomware-what-you-need-to-know/

 

It seems the variants are getting very clever and we look like we are fighting a desperate battle!

 

Just asking staff to be ultra vigilant when viewing e-mails etc is like plaiting fog!

Posted
I had this piece of information sent to me yesterday:

 

According to recent reports, massive volumes of JavaScript attachments are being spammed out that contain dangerous ransomware. We recommend taking the following additional precautions to protect your install base:

• Make sure your mail protection solution is blocking macro-enabled documents and .js scripts

• Ensure that you have blocked user access to downloading Tor by blacklisting the following URL:https://www.torproject.org/download/download-easy.html(the Locky virus in particular relies on downloading and installing the Tor browser and some versions may use Tor to contact the command and control servers)

• Disable Java in client browsers (for more information, see the following links)

• And we suggest that access to the following IPs be completely blocked at the firewall:

 

◦ 5.34.183.195

◦ 51.254.19.227

◦ 185.14.29.188

◦ 31.184.197.119

◦ 91.219.29.55

 

Also a link: https://nakedsecurity.sophos.com/2016/02/17/locky-ransomware-what-you-need-to-know/

 

It seems the variants are getting very clever and we look like we are fighting a desperate battle!

 

Just asking staff to be ultra vigilant when viewing e-mails etc is like plaiting fog!

 

its starting to become the daily chore of keeping up with these things

  • Thanks 1
Posted

I now force all office attachments into quarantine and release as needed. Macros are disabled without nofitificaton for all except sso report users. Applocker whitelisting and emetic in place. Flash and silver light updated asap

Not sure what else we can do

Posted
I now force all office attachments into quarantine and release as needed. Macros are disabled without nofitificaton for all except sso report users. Applocker whitelisting and emetic in place. Flash and silver light updated asap

Not sure what else we can do

 

Its good to make any needed plugins "click to run" to stop hidden inline frame malicious applets running as well as any compromised adverts.

 

IPS and Air Gapped backups too.

Posted

For those that use Gmail and are not sure how to block attachments

 

https://support.google.com/a/answer/2364580?hl=en

 

I've only blocked executables for now, but I may set up an attachment quarantine and block them all

 

We had an incident with phishing emails this week though, not sure how to stop that, it was one of those with a fake google doc attachment that redirects you to a fake google login page to steal your password, good job the end user phoned me asking why the attachment wasn't opening (It was from a genuine sender and looked really innocuous) I dread to think if anyone else has done it. All I can do is keep sending users blanket emails to be vigilant

Posted

Spotted this in the admin portal.

 

Common Attachment Types Filter is a new Exchange Online Protection feature. This feature will start rolling out today and should be completed over the coming weeks.

 

How does this affect me?

There is a new feature that provides an easy-to-setup method of filtering out unwanted and potentially malicious attachments by their file types. This feature only requires one click to turn on, and can easily be configured from a list of the file types commonly found to be dangerous. This will also help in consolidating attachment filtering within a malware policy rather than through multiple Exchange transport rules. The feature resides within the Malware Policy page in the Exchange Admin Center, and can be accessed by going under the Protection tab on the left and the malware filter tab on the top. From there, you can choose between creating a new malware policy where the most commonly abused files are preselected by default or editing an existing one to include the new functionality.

 

What do I need to do to prepare for this change?

This feature has administrative controls to enable and disable in your Exchange admin portal. This feature is off by default. You may turn it on in an existing or newly-created malware policy. Click Additional Information to learn more.

  • Thanks 2
Posted
Is there anything that can be done with google apps to stop the delivery of these things? i mean 99% of suspect emails go straight to spam - stopping them turning up without killing legit traffic would be a decent help
Posted (edited)

Hi,

 

Is there any further news on the TeslaCrypt variant?

 

We were hit a couple of weeks ago, but the effect was limited to the network drives that infected user had write-access to, which fortunately wasn't very much. We were able to restore the user's home folder and several shared folders that they had write-access to, from a recent shadow copy.

 

We notice that Symantec EndPoint Protection didn't do anything to detect or stop it (and I understand from forums that other AV firms were slow to detect it). With recent updates, are they now able to detect it?

 

According to:

 

Achievement Locked: New Crypto-Ransomware Pwns Video Gamers | Bromium Labs

 

It attempts to delete shadow copies using the Windows command:

 

vssadmin.exe delete shadows /all

 

I assume that this command is only capable of deleting local volume shadow copies (and only if it has admin rights). I wonder if this command is capable of deleting shadow copies of remote servers (as would usually be the case when non-admin users are affected)?

 

Of course, if the malware infects a Windows server which is used for storage of files, and a user logs on with admin rights, then it is a different matter.

 

This malware also puts into the question backup systems that depend on Disk to Disk backups, especially those that use Microsoft technologies (such as Microsoft Data Protection Manager). And one of the poor aspects of DPM is that it doesn't allow you to use an inbound firewall, as certain types of backups require the agent to initiate the connection to the DPM server.

 

Many Thanks,

 

Bruce.

Edited by Bruce123
Posted
Shadow copies are deleted server side I can confirm this :(

 

But does the server have to be infected, or can they be deleted by an infected client?

 

Our files are stored on a SAN (Linux) with no Windows server infront of it, so cannot be infected by this malware.

 

Thanks,

 

Bruce.

Posted
But does the server have to be infected, or can they be deleted by an infected client?

 

Our files are stored on a SAN (Linux) with no Windows server infront of it, so cannot be infected by this malware.

 

Thanks,

 

Bruce.

 

If the user gets it on the PC they are using it doesn;t matter what OS your file server is if the user has rights it will encrypt it and bye bye files :)

Posted
If the user gets it on the PC they are using it doesn;t matter what OS your file server is if the user has rights it will encrypt it and bye bye files :)

 

Sorry, I was just referring to deleting the shadow copies (on servers) from an infected client. I suspect it can't, and where shadow copies have been deleted it was because the OS hosting the file system was infected.

 

Thanks,

 

Bruce.

Posted
Sorry, I was just referring to deleting the shadow copies (on servers) from an infected client. I suspect it can't, and where shadow copies have been deleted it was because the OS hosting the file system was infected.

 

Thanks,

 

Bruce.

 

Can assure you when I was hit with it the Server that hosted files wasn't impacted as we scanned that and checked and inspected it and all clean itself, we found 1 client that had the infection and all the files that user who's Pc it was got impacted but VSS had gone so I still don't believe a nix or other variant file server would have helped although I guess it depends on how it deleted the VSS snaps if it relied upon PowerShell that maybe a way around it as the Nix won't have that on it but it may have just gone in and deleted things and the user would have rights into those areas most likely....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...