Jump to content

Recommended Posts

Posted
Somewhat scary isn't it...do we pretty much have to accept it's a matter of when rather than if we get hit?

 

I'm afraid it certainly looks that way due to some peoples lack of either interest or knowledge.

Posted
I'm afraid it certainly looks that way due to some peoples lack of either interest or knowledge.

 

A couple of weeks ago, despite constant termly reminders, we had around 6 members of staff confess to having opened an attachment from an obviously scam mail sent to group accounts...I wonder how many others did so without coughing to it.

  • 3 weeks later...
Posted
Somewhat scary isn't it...do we pretty much have to accept it's a matter of when rather than if we get hit?

 

Seeing as many places are running Outlook I find it really poor form from Microsoft that they haven't backported the new GPO to prevent running macro code from email attachments into Office 2013. I know they want to force everyone onto Office 365 variants of the suite but could pretty much cut these infections out at source and save organisations a lot of grief.

Posted
could pretty much cut these infections out at source and save organisations a lot of grief.

 

http://blog.checkpoint.com/2016/04/11/new-locky-variant-implements-evasion-techniques

 

Unlike previous Locky variants, which were spread mainly via email and documents containing malicious macros, this new variant is spread mainly through the Nuclear exploit kit, making the infection process more efficient while bypassing any email or document security inspections. Using an Exploit Kit for infection makes it much easier to infect victims with Locky, since the malware is delivered to the system using known browser exploits and does not require any user interaction at all.
Posted

We had a demonstration of Cylance last week.

 

It does not use any definition database but even spots zero day ( real real ZERO! ) malware and blocks it with no perfomance impact.

 

TT

Posted
We had a demonstration of Cylance last week.

 

It does not use any definition database but even spots zero day ( real real ZERO! ) malware and blocks it with no performance impact.

Shame about the price though. :(

Posted

Yeah... We run Terminal Services for the majority of our users so just 20 Servers for 400 users.

 

But unlike Kaspersky, Cylance don't want to licence on the number of TS hosts.

 

TT

  • 2 weeks later...
Posted
Obviously no excuse for not having backups, but I wonder if this kind of thing will start to make ZFS based file servers popular, for their ability to just roll back the changes when ransomware hits...
Posted (edited)
Has anyone removed mapped drives in order to prevent the spread of crypto and its variants? If so, did you encounter any problems?

 

Cheers

 

Just make the root of the mapped drive unwritable to all users. This stops it dead in its tracks.

 

I also prevent it with FSRM, some more info here on creating the cyptolocker file screens

 

http://jpelectron.com/sample/Info%20and%20Documents/Stop%20crypto%20badware%20before%20it%20ruins%20your%20day/1-PreventCrypto-Readme.htm

Edited by zag
Posted

One of my offsite users got hit, was in a hurry, opened an email that purported to be from a student, double clicked the ZIP and....Everything encrypted. She had drives mapped and was on VPN but thankfully it only did her hard drive. Unit back to base to be wiped.

 

I now block ALL zips in Exchange, with rules to send sorry emails to recipient and sender to let them know there are modern ways to send files and email is not one of them!

  • 7 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...