Jump to content

Recommended Posts

Posted (edited)

Hi Guys,

 

I just wanted to ask if anyone could shed any light on this for me please, we got called out to a school today as they couldn't access data on a staff shared drive, looking at the data it all looks fin although there is 3 files in each folder labeled as follows,

 

 

  • RECOVERvixun.html
  • RECOVERvixun.png
  • RECOVERvixun.txt

 

This is in each of the affected folders a copy of the .txt file is attached, it looks like a form of the teslacrypt ransomware but all scanners I run at the moment find nothing. The file structure in each folder appears to be fine and all documents have remained with the same name and file extension (it would appear at first glance they are more corrupt than encrypted).

 

The school announced on site they do not have any form of backup to replace the affected files :-( so really does anyone have any suggestions of anything I can run on the server and clients to check they are clean and also is the data gone for ever or is there some way of recovery ???

 

Cheers in Advance

Edited by elsiegee40
Potentially infected txt file removed as precaution
Posted
When we were hit the way that we found the infected computer was to search for the recovery files (one of the ones you have listed) in the user areas. Whichever user's area has been hit will have the infected computer. We completely re-imaged the infected computer. If they do not have backups then they either have to pay the ransom or accept that the files are gone for ever.
Posted
Hi Guys,

 

I just wanted to ask if anyone could shed any light on this for me please, we got called out to a school today as they couldn't access data on a staff shared drive, looking at the data it all looks fin although there is 3 files in each folder labeled as follows,

 

 

  • RECOVERvixun.html
  • RECOVERvixun.png
  • RECOVERvixun.txt

 

This is in each of the affected folders a copy of the .txt file is attached, it looks like a form of the teslacrypt ransomware but all scanners I run at the moment find nothing. The file structure in each folder appears to be fine and all documents have remained with the same name and file extension (it would appear at first glance they are more corrupt than encrypted).

 

The school announced on site they do not have any form of backup to replace the affected files :-( so really does anyone have any suggestions of anything I can run on the server and clients to check they are clean and also is the data gone for ever or is there some way of recovery ???

 

Cheers in Advance

 

Our AV flagged your attached file as a virus, so be careful when opening it.

Posted
Our AV flagged your attached file as a virus, so be careful when opening it.

 

Attachment has been removed.

 

 

Potentially infected files should not be posted on edugeek for obvious reasons

  • Thanks 2
Posted (edited)

Sorry guys this was the content,

 

NOT YOUR LANGUAGE? USE

 

What's the matter with your files?

 

 

Your data was secured using a strong encryption with RSA4096.

Use the link down below to find additional information on the encryption keys using RSA4096:

 

 

What exactly that means?

 

 

It means that on a structural level your files have been transformed. You won't be able to use, read, see or work with them anymore.

In other words they are useless, however, there is a possibility to restore them with our help.

 

 

What exactly happened to your files?

 

 

*** Two personal RSA4096 keys were generated for your PC/Laptop; one key is public, another key is private.

*** All your data and files were encrypted by the means of the public key, which you received over the web.

*** In order to decrypt your data and gain access to your computer you need a private key and a decryption software, which can be found on one of our secret servers.

 

 

What should you do next?

 

 

There are several options for you to consider:

1. You can wait for a while until the price of a private key will raise, so you will have to pay twice as much to access your files or

2. You can start getting BitCoins right now and get access to your data quite fast.

In case you have valuable files, we advise you to act fast as there is no other option rather than paying in order to get back your data.

 

 

In order to obtain specific instructions, please access your personal homepage by choosing one of the few addresses down below:

: Decrypt service

: Decrypt service

: Decrypt service

 

 

If you can't access your personal homepage or the addresses are not working, complete the following steps:

1 Download TOR Browser -

2 Install TOR Browser

3 Open TOR Browser

4 Insert the following link in the address bar: k7tlx3ghr3m4n2tu.onion/C156F11A451C1280

5 Follow the steps on your screen

 

 

IMPORTANT INFORMATION

 

 

Your personal homepages:

: Decrypt service

: Decrypt service

: Decrypt service

 

 

Your personal page Tor-Browser

Your personal identification ID: C156F11A451C1280

Edited by elsiegee40
Links nuked
Posted
From what I have heard and read with the encryption methodolgy the files are not renamed but encrypted, so would read as gibberish or corrupt, so, seems there has been an infection, so @Narwhal is unfortunately right. They had no backup at all? Not even volume shadow copy on the shares? :( Out of interest what anti-virus were they running?
Posted
Our AV flagged your attached file as a virus, so be careful when opening it.

 

Maybe the bods @ Edugeek need to have a rethink on the possible dangers and implications of users posting material on here that could cause a problem.

 

Just a thought...

Posted (edited)

Seen this a lot in recent weeks.

 

Users with encrypted files... seen some where the file extensions have been renamed to .locky or .whatever it is they choose. In some cases you can just rename the files back. Most times reload the machine and reinstall from fresh and reinstate files from backups.. please note: these viruses attack mapped network drives also so if backups are held on mapped network drives they might be affected as well. Along with any other drives attached to the infected machine.

 

And do pay any ransoms to decrypt your files... there are no guarantees! (obviously we know this as we are IT Gods), but some people don't think and pay the money.

 

One of the ones Ive seen recently starts at the letter A on a drive and work its way through the alphabet, next Folder/File Starting with B, Next with C and so on.

Edited by cpjitservices
Posted
They had no backup at all? Not even volume shadow copy on the shares? :( Out of interest what anti-virus were they running?

 

Nope no backup at all only a hardware mirror and as the date stamp of the infection files was last Wednesday at 13:47 I presume the mirror is infected as well as for Anti-Virus they were running Avast for Education on the server.

Posted
Users with encrypted files... seen some where the file extensions have been renamed to .locky or .whatever it is they choose.

 

Yeh we did have a machine in the library that had .locky on a lot of files :-( is there any decent software out that that can be used to test all the windows clients for infection or is malwarebytes the best around at the moment.

Posted
Maybe the bods @ Edugeek need to have a rethink on the possible dangers and implications of users posting material on here that could cause a problem.

 

Just a thought...

 

I am having a think on how to deal with this sort of thing more instantly.

  • Thanks 4
Posted (edited)
we had a teacher who was one of the lucky ones to be part of the zero day attacked with locky. after some reading best way to block these was to delete attachments with macro's. We get about one user a day forwarding an email where the attachment was removed because of macros and the user wants to know why they cant open the invoice :-) we decided to instead of just removing the attachment to block the whole mail if it contains macro's. BTW how did your user get the virus @NewBoy? Edited by elsiegee40
Posted
we decided to instead of just removing the attachment to block the whole mail if it contains macro's.

Do you also block executable content like .js files inside zip attachments? Locky uses those too.

 

A lot of the dodgy e-mails I have seen recently don't include any attachments at all and simply contain a message in a non-English language like German plus a link to website usually ending with a gTLD such as .pw, .club, .webcam, .science etc. :(

Posted
We block executable files and we scan compressed files for executable content. Do people still allow compressed files through mail? Was thinking of adding this to our block list but haven't found time to search if it's now best practice to block it. our Fortigate firewall is usually quite quick in blocking those dodgy websites through clickable links. But again those zero day attacks are difficult.
Posted
Seen this a lot in recent weeks.

 

Users with encrypted files... seen some where the file extensions have been renamed to .locky or .whatever it is they choose. In some cases you can just rename the files back. Most times reload the machine and reinstall from fresh and reinstate files from backups.. please note: these viruses attack mapped network drives also so if backups are held on mapped network drives they might be affected as well. Along with any other drives attached to the infected machine.

 

And do pay any ransoms to decrypt your files... there are no guarantees! (obviously we know this as we are IT Gods), but some people don't think and pay the money.

 

One of the ones Ive seen recently starts at the letter A on a drive and work its way through the alphabet, next Folder/File Starting with B, Next with C and so on.

 

Sorry typo... DONT pay any ransoms!!

Posted
Sorry typo... DONT pay any ransoms!!

 

Most of the crypto variants have actually supplied the decryption keys on payment, only a few haven't...

 

absolute worst case scenario with no backups etc etc obviously though.

Posted

Well, we were hit last week..........................wow............sleepless nights.... Restored file server from backup......

 

Email is the most likely cause?????? Any light on it?

Posted
No we narrowed it down to the particular user we thought brought it into the system but she claims everyone knows her password and uses her account (amazing how some people try and get out of things) but hers was the only home directory that was riddled with the issue.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...