Go Back   IceInSpace > Equipment > Software and Computers
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread
  #1  
Old 01-03-2016, 01:47 PM
Exfso's Avatar
Exfso (Peter)
Registered User

Exfso is offline
 
Join Date: Sep 2006
Location: Adelaide
Posts: 1,699
New ransomware threat

Please be careful, this one like other ransomware can cause big grief.

http://techtalk.pcpitstop.com/2016/0...ockyransomware=
Reply With Quote
  #2  
Old 01-03-2016, 02:53 PM
killswitch's Avatar
killswitch (Edison)
Registered User

killswitch is offline
 
Join Date: Feb 2013
Location: Western Sydney, NSW
Posts: 537
Thanks for the heads up.

Our company got hit by one last year, some butthead opened 'auspost' spam and it slowly ate through the local drive and then the network drives.

I was able to restore from backups after spending a day. We considered paying the ransom as well.
Reply With Quote
  #3  
Old 01-03-2016, 03:03 PM
multiweb's Avatar
multiweb (Marc)
ze frogginator

multiweb is offline
 
Join Date: Oct 2007
Location: Sydney
Posts: 22,079
Quote:
Originally Posted by killswitch View Post
We considered paying the ransom as well.
Unfortunately with low-life like these people it doesn't work. They'll only be encouraged to ask for more.
Reply With Quote
  #4  
Old 01-03-2016, 04:01 PM
AstralTraveller's Avatar
AstralTraveller (David)
Registered User

AstralTraveller is offline
 
Join Date: Mar 2008
Location: Wollongong
Posts: 3,819
Am I right in thinking (hoping) that this only affects Windows machines and Macs and Linux are immune?
Reply With Quote
  #5  
Old 01-03-2016, 04:35 PM
killswitch's Avatar
killswitch (Edison)
Registered User

killswitch is offline
 
Join Date: Feb 2013
Location: Western Sydney, NSW
Posts: 537
Quote:
Originally Posted by multiweb View Post
Unfortunately with low-life like these people it doesn't work. They'll only be encouraged to ask for more.
I've heard of companies just paying the ransom as its not worth their time.

In my instance, they asked for bitcoins equivalent to $600, which is nothing compared to downtime it caused the company. We would have had to pay if we didnt have backups or if the backup restorations failed.

Obviously once the files are decrypted, it needs to be copied off and everything be sterilized.

Quote:
Originally Posted by AstralTraveller View Post
Am I right in thinking (hoping) that this only affects Windows machines and Macs and Linux are immune?
Highly likely since the code is written in VB which is designed for a Microsoft environment. Even if you had Word for Mac, i can see it having a hard time encrypting files in a Mac file system.
Reply With Quote
  #6  
Old 01-03-2016, 07:09 PM
ZeroID's Avatar
ZeroID (Brent)
Lost in Space ....

ZeroID is offline
 
Join Date: May 2010
Location: Auckland, NZ
Posts: 4,949
It's a bugga that one, I've had to rebuild a few systems because of it. Fortunately all our data is on servers and backed up so it's just new OS and apps to install. Those and the eternal updates !!
Reply With Quote
  #7  
Old 07-03-2016, 02:53 PM
killswitch's Avatar
killswitch (Edison)
Registered User

killswitch is offline
 
Join Date: Feb 2013
Location: Western Sydney, NSW
Posts: 537
Looks like they've now developed ransomware for macs.

http://www.reuters.com/article/us-ap...-idUSKCN0W80VX
Reply With Quote
  #8  
Old 09-03-2016, 11:50 PM
billdan's Avatar
billdan (Bill)
Registered User

billdan is offline
 
Join Date: Mar 2012
Location: Narangba, SE QLD
Posts: 1,551
My wife got an email from Hong Kong yesterday telling her she had just won a million dollars and could she fill out the attached form with her bank details for a direct deposit. She promptly deleted it, but I am sure others would be tempted.


Bill
Reply With Quote
  #9  
Old 10-03-2016, 02:08 AM
Exfso's Avatar
Exfso (Peter)
Registered User

Exfso is offline
 
Join Date: Sep 2006
Location: Adelaide
Posts: 1,699
Just for information Malwarebytes are working on a version of their program to stop these in their tracks. It is in beta at present. I downloaded and tried it but got immediate BSOD, so gave it a miss for now. Here is the forum:

https://forums.malwarebytes.org/index.php?/forum/172-malwarebytes-anti-ransomware-beta/
Reply With Quote
  #10  
Old 24-03-2016, 11:08 PM
hamiland (Anders)
Registered User

hamiland is offline
 
Join Date: Jan 2016
Location: Mornington Peninsula, Australia
Posts: 44
One thing to note is that the ransomware servers (where the decryption key is stored) are being targeted by law enforcement agencies. So if you do decide to pay a ransom, the key may have already been destroyed even if the mongrels who distribute this had the best of intentions *ahem* to decrypt your data it may not be possible. So you'd be left with a whole heap of useless files, be $$$ out of pocket, and have funded the development of a better version of ransomware.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 07:54 PM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Advertisement
Bintel
Advertisement