NewBoy Posted March 24, 2016 Author Posted March 24, 2016 Somewhat scary isn't it...do we pretty much have to accept it's a matter of when rather than if we get hit? I'm afraid it certainly looks that way due to some peoples lack of either interest or knowledge.
Gibson335 Posted March 24, 2016 Posted March 24, 2016 I'm afraid it certainly looks that way due to some peoples lack of either interest or knowledge. A couple of weeks ago, despite constant termly reminders, we had around 6 members of staff confess to having opened an attachment from an obviously scam mail sent to group accounts...I wonder how many others did so without coughing to it.
DJ-1701 Posted April 11, 2016 Posted April 11, 2016 Looks like one type of ransomware (Petya) has been cracked. Petya ransomware encryption system cracked - BBC News
gshaw Posted April 12, 2016 Posted April 12, 2016 Somewhat scary isn't it...do we pretty much have to accept it's a matter of when rather than if we get hit? Seeing as many places are running Outlook I find it really poor form from Microsoft that they haven't backported the new GPO to prevent running macro code from email attachments into Office 2013. I know they want to force everyone onto Office 365 variants of the suite but could pretty much cut these infections out at source and save organisations a lot of grief.
gavlar Posted April 12, 2016 Posted April 12, 2016 Has anyone tried the BitDefender Anti-Ransomewaretool? It claims to be able to protect against the CTB-Locker, Locky and TeslaCrypt crypto ransomware families. https://labs.bitdefender.com/2016/03/combination-crypto-ransomware-vaccine-released/
abillybob Posted April 12, 2016 Posted April 12, 2016 Has anyone tried the BitDefender Anti-Ransomewaretool? It claims to be able to protect against the CTB-Locker, Locky and TeslaCrypt crypto ransomware families. https://labs.bitdefender.com/2016/03/combination-crypto-ransomware-vaccine-released/ News story about it here. Researcher publishes free tool to crack nasty ransomware | Information Age
Arthur Posted April 12, 2016 Posted April 12, 2016 could pretty much cut these infections out at source and save organisations a lot of grief. http://blog.checkpoint.com/2016/04/11/new-locky-variant-implements-evasion-techniques Unlike previous Locky variants, which were spread mainly via email and documents containing malicious macros, this new variant is spread mainly through the Nuclear exploit kit, making the infection process more efficient while bypassing any email or document security inspections. Using an Exploit Kit for infection makes it much easier to infect victims with Locky, since the malware is delivered to the system using known browser exploits and does not require any user interaction at all.
twin--turbo Posted April 13, 2016 Posted April 13, 2016 We had a demonstration of Cylance last week. It does not use any definition database but even spots zero day ( real real ZERO! ) malware and blocks it with no perfomance impact. TT
Arthur Posted April 13, 2016 Posted April 13, 2016 We had a demonstration of Cylance last week. It does not use any definition database but even spots zero day ( real real ZERO! ) malware and blocks it with no performance impact. Shame about the price though.
twin--turbo Posted April 13, 2016 Posted April 13, 2016 Yeah... We run Terminal Services for the majority of our users so just 20 Servers for 400 users. But unlike Kaspersky, Cylance don't want to licence on the number of TS hosts. TT
Gibson335 Posted April 26, 2016 Posted April 26, 2016 Has anyone removed mapped drives in order to prevent the spread of crypto and its variants? If so, did you encounter any problems? Cheers
Opendium_Steve Posted April 27, 2016 Posted April 27, 2016 Obviously no excuse for not having backups, but I wonder if this kind of thing will start to make ZFS based file servers popular, for their ability to just roll back the changes when ransomware hits...
zag Posted April 27, 2016 Posted April 27, 2016 (edited) Has anyone removed mapped drives in order to prevent the spread of crypto and its variants? If so, did you encounter any problems? Cheers Just make the root of the mapped drive unwritable to all users. This stops it dead in its tracks. I also prevent it with FSRM, some more info here on creating the cyptolocker file screens http://jpelectron.com/sample/Info%20and%20Documents/Stop%20crypto%20badware%20before%20it%20ruins%20your%20day/1-PreventCrypto-Readme.htm Edited April 27, 2016 by zag
CAWJames Posted April 27, 2016 Posted April 27, 2016 One of my offsite users got hit, was in a hurry, opened an email that purported to be from a student, double clicked the ZIP and....Everything encrypted. She had drives mapped and was on VPN but thankfully it only did her hard drive. Unit back to base to be wiped. I now block ALL zips in Exchange, with rules to send sorry emails to recipient and sender to let them know there are modern ways to send files and email is not one of them!
HarryMonkey Posted December 12, 2016 Posted December 12, 2016 You could get your files decrypted for free, providing you infect two other people ... Ransomware may turn victims into attackers, infect 2 others and decryption is free | Computerworld
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now