Announcement

Collapse
No announcement yet.

Anyone noticed an outbreak of Cryptolocker malware lately?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Anyone noticed an outbreak of Cryptolocker malware lately?

    I've been noticing that lately, I seem to be getting customers at work nearly every day with the cryptolocker (or the similar cryptowall) virus, and needless to say, most are less than impressed that there is nothing that can be done to recover their data. The pattern seems to have been a fake email claiming that they have had a speeding ticket. If you click on a link in it (supposedly to a photo of the car in question), it gives you the virus.

    Has anyone else noticed an increase in this type of malware of late?
    Last edited by c_hegge; 07-07-2015, 06:15 AM.
    I love putting bad caps and flat batteries in fire and watching them explode!!

    No wonder it doesn't work! You installed the jumper wires backwards

    Main PC: Core i7 3770K 3.5GHz, Gigabyte GA-Z77M-D3H-MVP, 8GB Kingston HyperX DDR3 1600, 240GB Intel 335 Series SSD, 750GB WD HDD, Sony Optiarc DVD RW, Palit nVidia GTX660 Ti, CoolerMaster N200 Case, Delta DPS-600MB 600W PSU, Hauppauge TV Tuner, Windows 7 Home Premium

    Office PC: HP ProLiant ML150 G3, 2x Xeon E5335 2GHz, 4GB DDR2 RAM, 120GB Intel 530 SSD, 2x 250GB HDD, 2x 450GB 15K SAS HDD in RAID 1, 1x 2TB HDD, nVidia 8400GS, Delta DPS-650BB 650W PSU, Windows 7 Pro

    #2
    Re: Anyone noticed an outbreak of Cryptolocker malware lately?

    Originally posted by c_hegge View Post
    I've been noticing that lately, I seem to be getting customers at work nearly every day with the cryptolocker (or the similar cryptowall) virus, and needless to say, most are less than impressed that there is nothing that can be done to recover their data. The pattern seem to have been a fake email claiming that they have had a speeding ticket. If you click on a link in it (supposedly to a photo of the car in question), it gives you the virus.

    Has anyone else noticed an increase in this type of malware of late?
    Not recently, it was worse the first of the year here.

    Comment


      #3
      Re: Anyone noticed an outbreak of Cryptolocker malware lately?

      yes.
      Things I've fixed: anything from semis to crappy Chinese $2 radios, and now an IoT Dildo....

      "Dude, this is Wyoming, i hopped on and sent 'er. No fucking around." -- Me

      Excuse me while i do something dangerous


      You must have a sad, sad boring life if you hate on people harmlessly enjoying life with an animal costume.

      Sometimes you need to break shit to fix it.... Thats why my lawnmower doesn't have a deadman switch or engine brake anymore

      Follow the white rabbit.

      Comment


        #4
        Re: Anyone noticed an outbreak of Cryptolocker malware lately?

        Originally posted by c_hegge View Post
        most are less than impressed that there is nothing that can be done to recover their data.
        I read this a while back. Worth trying?

        http://blogs.cisco.com/security/talos/teslacrypt
        --- begin sig file ---

        If you are new to this forum, we can help a lot more if you please post clear focused pictures (max resolution 2000x2000 and 2MB) of your boards using the manage attachments button so they are hosted here. Information and picture clarity compositions should look like this post.

        We respectfully ask that you make some time and effort to read some of the guides available for basic troubleshooting. After you have read through them, then ask clarification questions or report your findings.

        Please do not post inline and offsite as they slow down the loading of pages.

        --- end sig file ---

        Comment


          #5
          Re: Anyone noticed an outbreak of Cryptolocker malware lately?

          Which antivirus are they using ?

          Home users or corporate ?
          Last edited by diif; 07-07-2015, 12:26 AM.

          Comment


            #6
            Re: Anyone noticed an outbreak of Cryptolocker malware lately?

            ^
            The last one I saw had no antivirus at all, but the majority of victims have free antivirus programs (usually either AVG or MS Security essentials). I haven't seen it with a corporate antivirus (or for a corporate user) as yet. On my file server, I have the group policy set to disallow .exe files from running within the AppData folder (which most ransomware does), so it should be impossible for it to get infected with it.

            The malware itself isn't hard to remove (A scan with Malwarebytes has always done it). Getting the files back is another story, though. This latest variant (Cryptowall 3.0 - http://www.bleepingcomputer.com/viru...re-information). I'll give that tool a go next time I run into one, but not that hopeful, as it's for a completely different virus with a different form of encryption.
            I love putting bad caps and flat batteries in fire and watching them explode!!

            No wonder it doesn't work! You installed the jumper wires backwards

            Main PC: Core i7 3770K 3.5GHz, Gigabyte GA-Z77M-D3H-MVP, 8GB Kingston HyperX DDR3 1600, 240GB Intel 335 Series SSD, 750GB WD HDD, Sony Optiarc DVD RW, Palit nVidia GTX660 Ti, CoolerMaster N200 Case, Delta DPS-600MB 600W PSU, Hauppauge TV Tuner, Windows 7 Home Premium

            Office PC: HP ProLiant ML150 G3, 2x Xeon E5335 2GHz, 4GB DDR2 RAM, 120GB Intel 530 SSD, 2x 250GB HDD, 2x 450GB 15K SAS HDD in RAID 1, 1x 2TB HDD, nVidia 8400GS, Delta DPS-650BB 650W PSU, Windows 7 Pro

            Comment


              #7
              Re: Anyone noticed an outbreak of Cryptolocker malware lately?

              you know it's funny,
              governments will spend millions to kill some camel rider in another country with a drone-launched 100,000$ missile for a twitter-post,
              but they dont do shit about this type of thing.

              is it "them" doing it?
              if i had my way, viruses and mal-ware would be countered with deathsquads - not security software!!

              Comment


                #8
                Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                Thanks c_hegge, clicking on a link shouldn't mean automatic infection, is there something else going on ? Something not updated ? I know Flash is usually the weakness if Java isn't installed.
                I've yet to have a call from my customers, so i guess the answer is not yet.
                From the tests i've done in the past, MSE detected virus infected exes as they ran but didn't actually stop the file from running.

                There is a program here that might be worth giving out to your customers. recommended Krebs as well as others. by https://www.foolishit.com/cryptoprev...re-prevention/

                Comment


                  #9
                  Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                  Originally posted by stj View Post
                  you know it's funny,
                  governments will spend millions to kill some camel rider in another country with a drone-launched 100,000$ missile for a twitter-post,
                  but they dont do shit about this type of thing.

                  is it "them" doing it?
                  if i had my way, viruses and mal-ware would be countered with deathsquads - not security software!!
                  The problem is that the virus writers are not usually from the US but Eastern Block countries (Russia, Ukraine, etc.) and they are careful to not target users in their own countries.

                  There was recently the high profile arrest of the alleged Zeus Botmaster.

                  Comment


                    #10
                    Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                    if you think someone like putin wouldnt have 20 military police beat the cap out of them and arrest them, your wrong.
                    i suspect they are simply not being hunted.
                    ofcourse ukraine is now a crimescene run my assorted filth that would probably simply take a percentage from such behaviour.
                    Mikhail Saakashvili the wanted criminal and previous leader of georgia now hiding in odessa for example.

                    Comment


                      #11
                      Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                      They are attacking the West, not Russia etc, Putin has no interest in people not attacking his country or peoples. that is why they are not being hunted, they are not criminals in their own country.

                      Ukraine is not that bad. I have a customer who goes over regularly and is setting up a business there.
                      Last edited by diif; 07-07-2015, 05:03 AM.

                      Comment


                        #12
                        Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                        Originally posted by diif View Post
                        Thanks c_hegge, clicking on a link shouldn't mean automatic infection, is there something else going on ? Something not updated ? I know Flash is usually the weakness if Java isn't installed.
                        I've yet to have a call from my customers, so i guess the answer is not yet.
                        From the tests i've done in the past, MSE detected virus infected exes as they ran but didn't actually stop the file from running.

                        There is a program here that might be worth giving out to your customers. recommended Krebs as well as others. by https://www.foolishit.com/cryptoprev...re-prevention/
                        Yeah. I know about the cryptoprevent tool. It basically does the same thing as my local security policy fix on my file server (although it's better for Windows 7 Home Premium systems, as they don't have a Local Security Policy Editor)

                        I think that the infected email contains a link to a website where the users is told to enter a CAPTCHA and download a file. The user is told that the file is either an invoice or a photo or something along those lines, and they are fooled into downloading and opening it. I haven't personally had it, so I'm going by what customers tell me the last ting they did was, and the speeding fine email seems to be the most common story. There was even an article about it in the Sydney Morning Herald - http://www.smh.com.au/nsw/fake-speed...02-13sbxk.html
                        Last edited by c_hegge; 07-07-2015, 06:16 AM.
                        I love putting bad caps and flat batteries in fire and watching them explode!!

                        No wonder it doesn't work! You installed the jumper wires backwards

                        Main PC: Core i7 3770K 3.5GHz, Gigabyte GA-Z77M-D3H-MVP, 8GB Kingston HyperX DDR3 1600, 240GB Intel 335 Series SSD, 750GB WD HDD, Sony Optiarc DVD RW, Palit nVidia GTX660 Ti, CoolerMaster N200 Case, Delta DPS-600MB 600W PSU, Hauppauge TV Tuner, Windows 7 Home Premium

                        Office PC: HP ProLiant ML150 G3, 2x Xeon E5335 2GHz, 4GB DDR2 RAM, 120GB Intel 530 SSD, 2x 250GB HDD, 2x 450GB 15K SAS HDD in RAID 1, 1x 2TB HDD, nVidia 8400GS, Delta DPS-650BB 650W PSU, Windows 7 Pro

                        Comment


                          #13
                          Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                          Originally posted by diif View Post
                          They are attacking the West, not Russia etc, Putin has no interest in people not attacking his country or peoples. that is why they are not being hunted, they are not criminals in their own country.

                          Ukraine is not that bad. I have a customer who goes over regularly and is setting up a business there.
                          putin is inteested in stability and trust, russia is an emerging business hub - he does not want russia seen as the next nigeria/israel where scammers go untouched.

                          as for ukraine, i wouldnt go near the place, it's unstable and that's not good for any financial investment.
                          you have a government that took over with a coup and throws reporters out of windows,
                          right wing "nazi's" as they have been labeled who seem to be operating independantly of any other group,
                          western mercenary's,
                          freedom fighters / terrorists - depending on your view who want independance from the stuff i just listed,
                          the CIA have infested the kiev police headquarters, and nothing good ever followed them,
                          and NATO would be pretty happy to help the place get nuked if they could blame it on russia afterwards!!

                          not only would i NOT have anything to do with ukraine, i would avoid country's that border it too!!!
                          Last edited by stj; 07-07-2015, 07:04 AM.

                          Comment


                            #14
                            Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                            I've only had one instance of Crypto** in the shop since the turn of the year as most of the good AVs now block it.

                            Virtually impossible to decrypt but if you are lucky you might be able to recover data from the shadow copies.

                            Comment


                              #15
                              Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                              Originally posted by stj View Post
                              putin is inteested in stability and trust, russia is an emerging business hub - he does not want russia seen as the next nigeria/israel where scammers go untouched.

                              as for ukraine, i wouldnt go near the place, it's unstable and that's not good for any financial investment.
                              you have a government that took over with a coup and throws reporters out of windows,
                              right wing "nazi's" as they have been labeled who seem to be operating independantly of any other group,
                              western mercenary's,
                              freedom fighters / terrorists - depending on your view who want independance from the stuff i just listed,
                              the CIA have infested the kiev police headquarters, and nothing good ever followed them,
                              and NATO would be pretty happy to help the place get nuked if they could blame it on russia afterwards!!

                              not only would i NOT have anything to do with ukraine, i would avoid country's that border it too!!!
                              Stability and trust ?! that's why the Ukranian border is shrinking.
                              They are going untouched because they are not attacking Russia.
                              There is plenty of good things going on in the Ukraine and the business my client is going into seems to be making plenty of money for his competitors.
                              If it was as bad as you claim i don't think he'd be visiting or setting up a business there.
                              There is a mafia presence same as in Russia but business practices and prices are adjusted accordingly.

                              I have no intention of visiting, there is no need as i am handling his website for him and i don't like flying.
                              Last edited by diif; 07-07-2015, 07:47 AM.

                              Comment


                                #16
                                Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                                If some E-mails come with an embedded file with a photo file name extension that isn't a photo and instead malware, then it looks like Microsoft may not have learned from the Internet Explorer 6 era! (or shortly before)

                                Microsoft allegedly had an exploit where the malware file looks like a GIF, JPG or PNG and possibly receives malware as soon as you even read the E-mail.
                                Last edited by RJARRRPCGP; 07-07-2015, 08:19 AM.
                                ASRock B550 PG Velocita

                                Ryzen 9 "Vermeer" 5900X

                                32 GB G.Skill RipJaws V F4-3200C16D-32GVR

                                Arc A770 16 GB

                                eVGA Supernova G3 750W

                                Western Digital Black SN850 1TB NVMe SSD

                                Alienware AW3423DWF OLED




                                "¡Me encanta "Me Encanta o Enlistarlo con Hilary Farr!" -Mí mismo

                                "There's nothing more unattractive than a chick smoking a cigarette" -Topcat

                                "Today's lesson in pissivity comes in the form of a ziplock baggie full of GPU extension brackets & hardware that for the last ~3 years have been on my bench, always in my way, getting moved around constantly....and yesterday I found myself in need of them....and the bastards are now nowhere to be found! Motherfracker!!" -Topcat

                                "did I see a chair fly? I think I did! Time for popcorn!" -ratdude747

                                Comment


                                  #17
                                  Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                                  Originally posted by c_hegge View Post
                                  Yeah. I know about the cryptoprevent tool. It basically does the same thing as my local security policy fix on my file server (although it's better for Windows 7 Home Premium systems, as they don't have a Local Security Policy Editor)

                                  I think that the infected email contains a link to a website where the users is told to enter a CAPTCHA and download a file. The user is told that the file is either an invoice or a photo or something along those lines, and they are fooled into downloading and opening it. I haven't personally had it, so I'm going by what customers tell me the last ting they did was, and the speeding fine email seems to be the most common story. There was even an article about it in the Sydney Morning Herald - http://www.smh.com.au/nsw/fake-speed...02-13sbxk.html
                                  Reminds me of a scam email one of the teachers received at my last school. Accused her of downloading copyrighted material. "I was that enraged as i've never downloaded anything illegal i clicked on the link" ....shortly followed by a call to us "my laptop is running funny". All the teachers had local admin rights. (Not my doing).

                                  Comment


                                    #18
                                    Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                                    Originally posted by diif View Post
                                    Reminds me of a scam email one of the teachers received at my last school. Accused her of downloading copyrighted material. "I was that enraged as i've never downloaded anything illegal i clicked on the link" ....shortly followed by a call to us "my laptop is running funny". All the teachers had local admin rights. (Not my doing).
                                    With my Yahoo E-mail account, I keep getting spam E-mails about a problem with my PayPal account.
                                    IIRC, they're phishing E-mails.
                                    Last edited by RJARRRPCGP; 07-07-2015, 01:55 PM.
                                    ASRock B550 PG Velocita

                                    Ryzen 9 "Vermeer" 5900X

                                    32 GB G.Skill RipJaws V F4-3200C16D-32GVR

                                    Arc A770 16 GB

                                    eVGA Supernova G3 750W

                                    Western Digital Black SN850 1TB NVMe SSD

                                    Alienware AW3423DWF OLED




                                    "¡Me encanta "Me Encanta o Enlistarlo con Hilary Farr!" -Mí mismo

                                    "There's nothing more unattractive than a chick smoking a cigarette" -Topcat

                                    "Today's lesson in pissivity comes in the form of a ziplock baggie full of GPU extension brackets & hardware that for the last ~3 years have been on my bench, always in my way, getting moved around constantly....and yesterday I found myself in need of them....and the bastards are now nowhere to be found! Motherfracker!!" -Topcat

                                    "did I see a chair fly? I think I did! Time for popcorn!" -ratdude747

                                    Comment


                                      #19
                                      Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                                      I used to get the Paypal emails. I just asked Paypal the first time and then forwarded the emails to them after that.
                                      sigpicThe Sky Is Falling

                                      Comment


                                        #20
                                        Re: Anyone noticed an outbreak of Cryptolocker malware lately?

                                        I noticed a large surge of Crypto in November/December here on the west coast of the US. Right before Christmas I had 5 come in in one day. They seemed to slow down a lot after the new year. A few customers cried when they heard they couldn't get their data back.

                                        Comment

                                        Working...
                                        X