Ransomware and Recent Variants

Discussion in 'malware problems & news' started by ronjor, Mar 31, 2016.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,071
    Location:
    Texas
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    http://www.welivesecurity.com/2017/02/22/new-crypto-ransomware-hits-macos/
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    http://news.softpedia.com/news/avas...versions-of-cryptomix-ransomware-513188.shtml
     
  5. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://labsblog.f-secure.com/2017/02/22/bitcoin-friction-is-ransomwares-only-constraint/
     
  6. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,071
    Location:
    Texas
    Android Ransomware Demands Victims Speak Unlock Code
     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,071
    Location:
    Texas
    New Unlock26 Ransomware and RaaS Portal Discovered
     
  8. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,985
    Location:
    U.S.A.
     
  9. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  10. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  11. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.infosecurity-magazine.com/news/61-of-orgs-infected-with-ransomware/
     
  12. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.infosecurity-magazine.com/news/ransomware-demands-political-not/
     
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  14. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.bleepingcomputer.com/ne...s-a-petya-offspring-used-in-targeted-attacks/

    What's interesting about this ransomware is the author hacked the original ransomware author.
     
  15. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    http://www.2-spyware.com/hackers-take-revenge-id-ransomware-servers-hit-by-ddos-attacks
     
  16. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  17. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
    Star Trek Themed Kirk Ransomware

    https://www.bleepingcomputer.com/ne...mware-brings-us-monero-and-a-spock-decryptor/

     
  18. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
  19. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "Ransomware-As-A-Service: The Next Great Cyber Threat?...

    ...RaaS (Ransomware-As-A-Service) is designed to make cybercrime accessible to anyone, no matter how limited their programming mastery. Advanced cybercriminals author the malicious code, then make it available for others to download and use. The authors may provide the ransomware for free or charge a small fee up front, often opting to take a cut of each ransom. This incentivizes a higher volume of attacks and higher ransom requests..."

    https://www.forbes.com/sites/forbes...ice-the-next-great-cyber-threat/#ba663114123a
     
  20. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://threatpost.com/locky-cerber-ransomware-skilled-at-hiding
     
  21. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    http://www.csoonline.com/article/31...mware-is-a-user-failure-you-re-a-failure.html
     
  22. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Here is a my real life example of how it was and wasn't the IT people's fault. at the last place I worked, My manager received an e-mail that had Poweliks in it which I am sure he clicked on and it infected the rest of the network. I was the only one on Windows 7 at the time. The only software they had was Norton Endpoint. Norton would alert that I was infected. Said it cleaned it, reboot and was back. I installed Malwarbytes to no avail. Found a cleaning app from Eset which cured my computer but not the others. Manager was inflamed because he received a lot of email every day from customers. He is the problem. We techs needed admin rights because we were always installing new software for the products we worked on. And of course the Owner and manager had admin rights. The management new we needed admin rights and so that is what the IT people were told. I am sure their are plenty tech companies around that need to have their employees in admin mode. And so it is not so cut and dry. To not have my company that I worked for employees admin rights would cost them a tone of downtime and money.
     
  23. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  24. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Cerber Ransomware Served Up From HTTPS Web Site

    According to this TrendMicro article: https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/w2km_cerber.ppdoh , this Cerber variant arrives in e-mail as an embedded macro in a Word document. Not anymore!

    Eset nailed it upon web site access and couldn't think of a better example for why SSL protocol scanning needs to be employed. Below are Eset log details:

    Time: 3/30/2017 3:16:03 PM
    Scanner: HTTP filter
    Object type: file
    Object: hxxps://www. greyhathacker.net/?p=948
    Threat: PowerShell/TrojanDownloader.Agent.DV trojan
    Action: connection terminated
    User: XXX-PC\XXX-XXXX
    Information: Threat was detected upon access to web by the application: C:\Program Files\Internet Explorer\iexplore.exe (8288B566340C2BFEC37768F5A029027DDA7C2A5B)
    Hash: 793568AC8277B3F03FAC123E0898A16AF1E103A5
    First seen here:
     
    Last edited: Mar 30, 2017
  25. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Skype Users Hit By Ransomware Through In-App Malicious Ads
    http://www.zdnet.com/article/skype-served-up-malware-through-in-app-malicious-ads/

    -EDIT- A bit more detail of this attack here: https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/
     
    Last edited: Mar 31, 2017
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.