CryptoLocker

Discussion in 'malware problems & news' started by DX2, Sep 10, 2013.

  1. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
    Whitehats recover, release keys to CryptoLocker ransomware
     
  2. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
    Cryptolocker flogged on YouTube
    http://www.theregister.co.uk/2014/08/20/cryptolocker_flogged_on_youtube/
     
  3. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,546
    Location:
    Triassic
    Just updated CryptoPrevent to V7.1

    Using default configuration. Would be interested if anybody is using any of the advanced options.

    NB: No compat issues with my AV, MBAM, SBIE or EMET
     
  4. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  5. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,546
    Location:
    Triassic
    With CrytoPrevent V6 some users reported compat issues with MBAM and MBAR, but I did not see those in V7.1 Maybe one or the other preset an exclusion.
     
  6. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
    Ransomware takes malware from bad to worse
    http://www.csoonline.com/article/2836976/data-protection/ransomware-malware-bad-worse.html
     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
    https://www.us-cert.gov/ncas/alerts/TA14-295A
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    New cryptoware title borrows page from drug dealers
    http://arstechnica.com/security/2014/11/new-cryptoware-title-borrows-page-from-drug-dealers/
     
  9. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
    Ransom malware attacks underscore limitations of anti-virus software
    http://news.techworld.com/security/...nderscore-limitations-of-anti-virus-software/
     
  10. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  11. DX2

    DX2 Guest

    Odd question. What if you have a encrypted drive, say from Truecrypt or Bitlocker. Can Cryptolocker still lock your files that are encrypted?
     
  12. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,152
    Location:
    Hengelo, The Netherlands
    Yes. As Cryptolocker and variant encrypt at file system level and Truecrypt at sector level.
     
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    If drive is encrypted and is not accessible to user (password was not entered), malware wouldn't see files stored on drive so wouldn't have anything to encrypt. Except if it decides to encrypt whole drive (I didn't hear of such case yet) - then you would have your data encrypted twice.
    If drive is accessible to user (decrypted by password) malware can encrypt those files just as any others.
    Same goes for encrypted containers.
     
  14. DX2

    DX2 Guest

    Thanks for your answers. Just a question I was wondering about.
     
  15. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    New ransomware isn't just malware, it's a virus – a true virus; a self-replicating parasite that spreads of its own accord.

    "Notes from SophosLabs: Ransomware with a difference - this one is a true virus!...

    But this new ransomware isn't just malware, it's a virus – a true virus; a self-replicating parasite that spreads of its own accord.

    Once it gets into your network, even if it infects only a single computer, it may soon end up all over the place, even if no-one opens dodgy attachments or already has zombie malware infections waiting to be exploited.

    A parasitic virus, in contrast to a worm, doesn't spread merely by making copies of itself.

    Parasitics find other programs and modify them to include a copy of the virus, using the original file as a host or carrier.
    Worms versus parasitics

    Most worms leave you with one, or perhaps a handful, of infected files that weren't there before and need to be deleted.

    Parasitic viruses, in contrast, may leave you with hundreds of infected files on each computer, or thousands, or more.

    If you leave even one of those infected files behind after a clean-up, the infection will start up all over again.

    Worse still, the infected files can't just be deleted, because they are your own files that were there before the infection started."

    https://nakedsecurity.sophos.com/20...Feed: nakedsecurity (Naked Security - Sophos)
     
  16. deBoetie

    deBoetie Registered Member

    Joined:
    Aug 7, 2013
    Posts:
    1,832
    Location:
    UK
    While the current Cryptolocker and variants select particular file types for encryption, do not presume that future versions won't go for encrypted containers. These are identifiable, and some people do not adequately back up the header, for example. Containers are also not protected against arbitrary corruption (at the sector level), which would damage the contents.

    As well as system controls, offline backup is your friend. I also use Sandboxie as a primitive form of disk firewall to apps, but I'd like something far more powerful, perhaps built into a Truecrypt derivative.
     
  17. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "Here Comes Reveton: Ransomware

    The ransomware scourge that made many small and midsize businesses scramble to recover locked-up systems in 2014 is continuing to clobber PCs despite a law enforcement crackdown that effectively squashed the nefarious CryptoLocker malware.

    Reveton, a threat that spread mainly in Europe and tied up systems while displaying a phony law enforcement warning, has surged in recent months and is now being detected hammering systems in the U.S. The health-care industry appears to have felt the brunt of the latest surge of the malware, according to an analysis of the latest variant issued by Trend Micro Thursday.

    More than 60 percent of Reveton infections spotted by the security vendor have been in the U.S. and the malware's new infection method is behind the expansion, the company said. Rather than an executable file, Reveton infects systems with a DLL file extension.
    "The difference here is that a user whose system is infected by any of these recent Reveton malware variants won't easily suspect that there's a malicious application running in the system via Task Manager," Trend Micro said..............."

    Full Story:http://www.crn.com/news/security/30...e-is-keeping-solution-providers-very-busy.htm
     
  18. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    http://www.nytimes.com/2015/01/04/opinion/sunday/how-my-mom-got-hacked.html
     
  19. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
  20. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
  21. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    CryptoPrevent 7.4.2 was released on 11/1/14

    https://www.foolishit.com/vb6-projects/cryptoprevent/

    "There are a number of new CryptoLocker clones emerging that can also be prevented by CryptoPrevent. The majority of these are protected against by default protections with their older versions, but newer variants are coming out that can only be stopped by the Maximum Protection + Program Filtering (BETA) option, which uses a definitions based system to keep current with known malware threats. This is however a “BETA” which means it is not fully tested on all platforms. Note this option is not available with the portable edition of CryptoPrevent.


    Update 11/1/14 – some reports indicated that there were issues with existing security software and the BETA protection, however with the 7.4.2 release those issues appear to be resolved."
     
  22. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  23. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
  24. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Last edited: Jan 14, 2015
  25. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,618
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.