|
 |
|
|
|
 |
|
 |
|
StriperTalk! All things Striper |
 |
04-08-2016, 07:53 AM
|
#1
|
Certifiable Intertidal Anguiologist
Join Date: Feb 2000
Location: Somewhere between OOB & west of Watch Hill
Posts: 35,270
|
PSA: Malware / Ransomware
A lot of targeted malware \ ransomware is going out, particularly via email. The ransomware essentially locks up your computer, encrypts all of your files so you cannot access them, and request 500 to several thousand dollars to restore them. You either Pay or restore from Backup. No way around it.
The email is very normal looking, might be from your boss, or company owner, may be from a local name or even a customer you have worked with before. You open the email and infect your system and usually connected systems.
I have had almost all of my clients targeted with this and fortunately most not successful due to training and filtering but there have been some instances where it has happened.
What can you do? Not run as local administrator on your machine helps, but have good backup, run your system and application updates (JAVA, FireFox, Flash are crucial).
If you are a small biz (5-300employees) in RI, Eastern CT, Norfolk/WCTR county Mass I can put you in touch with my company or deal directly.
For home: BACKUP BACKUP BACKUP. Go get Carbonite or BackBlaze and have your computer files and photos backup up offline. This is the minimum and allows you top at least get some of your files back.
Better: Get an external drive or two, a copy of ShadowProtect and do full system image backups locally AND run offsite to Carbonite/BackBlaze
|
~Fix the Bait~ ~Pogies Forever~
Striped Bass Fishing - All Stripers
Kobayashi Maru Election - there is no way to win.
Apocalypse is Coming:
|
|
|
04-08-2016, 08:20 AM
|
#2
|
It's about respect baby!
Join Date: Apr 2003
Location: ri
Posts: 6,358
|
Seeing some targeted (phishing) emails directed/ tailored to suit individuals based on their social media ie. you posted juniors little league opening day was today he plays for the providence Mets. Email pops up at your @work email address with hyperlink to @Providence mets final schedule changes league approved etc, you click link = bad news for your network
|
Domination takes full concentration..
|
|
|
04-08-2016, 08:50 AM
|
#3
|
Certifiable Intertidal Anguiologist
Join Date: Feb 2000
Location: Somewhere between OOB & west of Watch Hill
Posts: 35,270
|
Quote:
Originally Posted by ThrowingTimber
Seeing some targeted (phishing) emails directed/ tailored to suit individuals based on their social media ie. you posted juniors little league opening day was today he plays for the providence Mets. Email pops up at your @work email address with hyperlink to @Providence mets final schedule changes league approved etc, you click link = bad news for your network
|
Yep. Targeted. Spear Phishing.
|
~Fix the Bait~ ~Pogies Forever~
Striped Bass Fishing - All Stripers
Kobayashi Maru Election - there is no way to win.
Apocalypse is Coming:
|
|
|
04-08-2016, 09:10 AM
|
#4
|
time to go
Join Date: Oct 2007
Posts: 2,318
|
Quote:
Originally Posted by ThrowingTimber
Seeing some targeted (phishing) emails directed/ tailored to suit individuals based on their social media ie. you posted juniors little league opening day was today he plays for the providence Mets. Email pops up at your @work email address with hyperlink to @Providence mets final schedule changes league approved etc, you click link = bad news for your network
|
Thanks for the translation, I was going to ask my niece but now I understand. (Insert blushing smiley thingy here...lol)
Posted from my iPhone/Mobile device
|
|
|
|
04-08-2016, 11:34 AM
|
#5
|
Registered User
Join Date: Feb 2003
Location: Hyde Park, MA
Posts: 4,152
|
Imagine how many people, particularly elderly and not-so-computer-savvy individuals that may be affected?
|
I am a legend in my own mind!
|
|
|
04-08-2016, 04:23 PM
|
#6
|
Registered User
Join Date: Oct 2001
Location: Southeastern MA
Posts: 394
|
John do the emails you mention have some kind of attachment or is it just a link?
By the way we did receive a couple at my office that were caught. A scan of the attachment by IT found it was loaded with either malware or ransomware.
|
|
|
|
04-09-2016, 11:38 AM
|
#7
|
Certifiable Intertidal Anguiologist
Join Date: Feb 2000
Location: Somewhere between OOB & west of Watch Hill
Posts: 35,270
|
Quote:
Originally Posted by jeffsod
John do the emails you mention have some kind of attachment or is it just a link?
By the way we did receive a couple at my office that were caught. A scan of the attachment by IT found it was loaded with either malware or ransomware.
|
Both - usually an attachment but often enough a link to an infected site.
|
~Fix the Bait~ ~Pogies Forever~
Striped Bass Fishing - All Stripers
Kobayashi Maru Election - there is no way to win.
Apocalypse is Coming:
|
|
|
04-11-2016, 10:52 AM
|
#8
|
Registered User
Join Date: Aug 2005
Location: Rhode Island
Posts: 258
|
?
How about if you open it on an Iphone?
|
|
|
|
04-12-2016, 07:15 AM
|
#9
|
Certifiable Intertidal Anguiologist
Join Date: Feb 2000
Location: Somewhere between OOB & west of Watch Hill
Posts: 35,270
|
Quote:
Originally Posted by Headhunter
How about if you open it on an Iphone?
|
The ransomware / malware payload is mostly engineered to a specific desktop / network operating system such as Windows/Mac/Linux but there are some variants in phones. This particular type doesn't make as much sense to target phones due to less critical information and phones are lucrative from other forms of financial crime.
|
~Fix the Bait~ ~Pogies Forever~
Striped Bass Fishing - All Stripers
Kobayashi Maru Election - there is no way to win.
Apocalypse is Coming:
|
|
|
04-15-2016, 01:23 PM
|
#10
|
Registered User
Join Date: Aug 2005
Location: Rhode Island
Posts: 258
|
So wouldn't it make sense to open all your emails from your phone to see if they make sense, then if they have subject mater that is pertinent you know its ok?
|
|
|
|
04-15-2016, 01:46 PM
|
#11
|
Registered User
Join Date: Apr 2001
Posts: 4,449
|
I've seen ransomware that can infect iOs. The editor from Wired that said his accounts were so secure got hacked like that...somebody SE'd Apple support, added a credit card, then got in that way.
Phones are pretty safe, though. It pays to have great anti-virus, good web-based backup or a hard drive backup that's encrypted, and I just never open attachments.
|
John Redmond Thinks He's Smart By Changing My Avatar
|
|
|
04-15-2016, 01:54 PM
|
#12
|
Registered User
Join Date: Mar 2003
Location: Gloucester Massachusetts
Posts: 2,678
|
I had some sort of attack a couple weeks ago...looking something up on computer and wham up pops this notice with microsoft heading... kept flashing flashing call this number tried clicking off a dozen times would not undo....called number they wanted to sell me a Defender product for 500 bucks...told them i would call them back....all I did was restart computer everything was fine....had to B a scam.... mentioned to friends at coffee and one said he got it too on business computer, he paid and thought for a minute and called bank to cancel the payment...he got money back..... 
|
"When its not about money,it's all about money."...
|
|
|
04-16-2016, 07:35 AM
|
#13
|
Afterhours Custom Plugs
Join Date: Mar 2004
Location: R.I.
Posts: 8,642
|
are any of these #^^^^&wads ever caught and prosecuted ? never seem to heard of any being so. do they run rampant until the anti v's catch on and update ?
|
|
|
|
04-20-2016, 11:27 AM
|
#14
|
It's about respect baby!
Join Date: Apr 2003
Location: ri
Posts: 6,358
|
Quote:
Originally Posted by afterhours
are any of these #^^^^&wads ever caught and prosecuted ? never seem to heard of any being so. do they run rampant until the anti v's catch on and update ?
|
They actually run their code through checks like virus total to ensure their stuff makes it through/ past anti virii. Make no mistake, this is a business to them. Support helpdesks, the more you buy you get percentages off, they have dev. Cycles. This is not some twit running scripts. Theyre basically "companies"
Some, caught sure. In a coordinated effort (attack) a concerted effort was organized and set of their encryptions keys was stolen and made public. (Fight fire with fire sort if deal)
Krebs on security has an excellent view on security and finger on the pulse of what is happening if you'd like to keep informed 😃 Its not over wordy and easy to read. (Interesting actually)
Posted from my iPhone/Mobile device
|
Domination takes full concentration..
|
|
|
04-20-2016, 02:05 PM
|
#15
|
Registered User
Join Date: Feb 2004
Location: RI
Posts: 5,704
|
After reading threads like this I thank myself for switching to a Linux distro back in '06.
|
|
|
|
04-22-2016, 09:33 AM
|
#16
|
Registered User
Join Date: Jan 2009
Posts: 1,044
|
Just saw this from SecurityWeek
3.2 million devices exposed to ransomware attacks: Cisco.
Security researchers from Cisco Talos discovered that approximately 3.2 million computers were
vulnerable to file-encrypting ransomware due to out-of-date software after an Internet scan on already
compromised devices revealed that more than 2,100 backdoors across 1,600 Internet Protocol (IP)
addresses were associated with governments, schools, aviation companies, and other organizations. Cisco
advised administrators to disable external access to infected machine to keep attackers away.
Source: http://www.securityweek.com/32-milli...-attacks-cisco
|
|
|
|
04-22-2016, 10:02 AM
|
#17
|
got gas?
Join Date: Mar 2002
Posts: 1,716
|
thanks John
|
|
|
|
 |
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 11:09 AM.
|
| |