Ransomware and Recent Variants

Discussion in 'malware problems & news' started by ronjor, Mar 31, 2016.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
  2. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,110
    Location:
    UK
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.bleepingcomputer.com/ne...lorado-dot-agency-shuts-down-2-000-computers/
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    https://www.bleepingcomputer.com/ne...tims-two-days-after-release-on-dark-web-raas/
     
  5. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    Recently Bitdefender has also released a decryptor for the Annabelle Ransomware.
    https://labs.bitdefender.com/2018/03/annabelle-ransomware-decryption-tool/

    I'm not sure how much it differs from the BleepingComputer and MalwareHunterTeam tool.
    As far as I can tell from the Bitdefender site, you have to recover the MBR but it doesn't give guidelines for that.
    The BleepingComputer article points to RKill for replacing the MBR.

    The Bitdefender decryptor is also listed at the No More Ransom project:
    https://www.nomoreransom.org
     
    Last edited: Mar 6, 2018
  6. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,185
    Location:
    Texas
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Not a very good recommendation for McAfee.
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Trends 2018: The ransomware revolution
    https://www.welivesecurity.com/2018/03/07/ransomware-revolution/
     
  9. guest

    guest Guest

    Zenis Ransomware Encrypts Your Data & Deletes Your Backups
    March 16, 2018
    https://www.bleepingcomputer.com/ne...-encrypts-your-data-and-deletes-your-backups/
     
  10. guest

    guest Guest

    New R2D2 Technique Protects Files Against Wiper Malware
    March 21, 2018
    https://www.bleepingcomputer.com/ne...chnique-protects-files-against-wiper-malware/
     
  11. guest

    guest Guest

    The AVCrypt Ransomware Tries To Uninstall Your AV Software
    March 23, 2018
    https://www.bleepingcomputer.com/ne...nsomware-tries-to-uninstall-your-av-software/
     
  12. guest

    guest Guest

    Rapid 2.0 Ransomware Released, Will Not Encrypt Data on PCs with Russian Locale
    March 23, 2018
    https://www.bleepingcomputer.com/ne...-not-encrypt-data-on-pcs-with-russian-locale/
     
  13. guest

    guest Guest

    The Week in Ransomware - March 23rd 2018 - Govt Infections, Zenis, and More
    March 23, 2018
    https://www.bleepingcomputer.com/ne...rch-23rd-2018-govt-infections-zenis-and-more/
     
  14. guest

    guest Guest

    The DiskWriter or UselessDisk BootLocker May Be A Wiper
    March 24, 2018
    https://www.bleepingcomputer.com/ne...ter-or-uselessdisk-bootlocker-may-be-a-wiper/
     
  15. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Not at all a good day to find something that devious made a visit into a system.
     
  16. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Restoring an image should be an easy fix
     
  17. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Of note about this bugger is none of the AI engines on VT are detecting it. This also explains why Windows Defender also isn't. Hey, but people believe signature detection is useless - right? No, wrong.
     
  18. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Typical MBR locker. Anything that will stop the mechanism of the Petya's will squash this one.The only mystery here is why anyone would waste the time to code it (Entrance Exam to Blackhat U?).
     
  19. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Unlike Petya, this malware is a diskwiper; not ransomware. The ransomware screen is totally bogus. Per the bleepingcomputer.com article, this bugger also wipes the MFT. So there is no way to recover your files.
     
  20. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    What I meant was that the products that had the anti-MBR trasher in place will stop this one quite nicely.
     
  21. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi itman

    Sure there is, just restore an image.
     
  22. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    About the only thing to do would be a Restore, but God Forbid if folk are using security solutions that would allow it in the first place.

    The malware itself is nothing special; Petya (Green flavour) and Satana also messed with the MFT, and the NotPetya variant was also called a wiper. But any of these actions needs direct disk access to work, so the generic block to this process (seen in about all anti-ransomware products and any AV worth using) stops this malware.
     
  23. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Cruelsister

    You are so right. Anything that detects ransomware at work means you are already infected. People just don't get that.
     
  24. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Organizations blame legacy antivirus protection for failed ransomware prevention
    https://www.helpnetsecurity.com/2018/03/29/failed-ransomware-prevention/
     
  25. guest

    guest Guest

    Power Company in India Hacked and Billing Data Ransomed for 10 Million Rupees
    March 29, 2018
    https://www.bleepingcomputer.com/ne...-billing-data-ransomed-for-10-million-rupees/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.