Showing posts with label CryptoLocker. Show all posts
Showing posts with label CryptoLocker. Show all posts

Thursday, 10 September 2015

Microsoft Checks On Millions Of Computers Ransomware


Since yesterday evening, Microsoft has millions of Windows computers on the presence of an active ransomware family-controlled. It involves the Teerac-ransomware, which has been active since early 2014. In recent months, hundreds of thousands of computers with ransomware in touch.

These are essentially computers in Australia, Germany and Turkey. Teerac spreads via email attachments. When a user opens the attachment kinds of files are encrypted and there should be a fee of $ 500 in bitcoin paid to recover the files.According to Microsoft appear every day new instances of ransomware to avoid being detected by anti-virus software.

Due to the increasing activity of Teerac decided the Microsoft Malicious Software Removal Tool (MSRT) update in Windows so that the program can recognize and remove ransomware. The MSRT is a removal tool which is updated every month with new virus definitions and then scan the computer. In the case of an infection, the malware found is then removed. According to Microsoft, prevention is better than cure. Users also are advised to make backups, to keep software up to date, use a pop-up blocker and not to open attachments from strangers.

Thursday, 28 May 2015

Android Ransomware Not Give Paying User Penalty


Last week, more than 15,000 e-mails are sent with Android ransomware that occurs when a security update for Adobe Flash Player. The messages contain little text, except that the enclosed APK file, "Check Updates.apk" is an update to Flash Player.

In reality, it is ransomware that locks the device and a warning from the FBI shows. According to the warning, the user would have viewed pornographic websites. To unlock the device must be an amount of $ 500 to be paid. If the user attempts to unlock the device, the amount is increased to $ 1,500, reports the Romanian antivirus company BitDefender .

According to the Spanish security company S21sec ransomware makers find new ways to spread their creations. Currently used mainly social engineering, but new capabilities are added continuously, according to the IT security officer. Users also are advised to install APK files from untrusted sources and email filtering with MOT attachments.

Tuesday, 10 March 2015

Crypto Locker Infected 200 Computers From VU University


The Crypto Locker ransomware has 200 computers of the VU University Amsterdam (VU) infected as a spokeswoman for the university. "The Crypto Locker Virus haunts on our network," said Aukje Scoop. Twitter posted Rickey Gevers a screenshot of the warning was distributed among staff and students. The damage was due to a good backup strategy, however, are minimal. The malware spreads via email attachments and encrypt files on computers for ransom. To put the impact of ransomware to counteract the VU network decided this weekend to "read-only".

Scans performed at the IT department were discovered last week several infected workstations. Once there was an infection detected, the computer and the corresponding account temporarily blocked. The malware was removed and a backup of the evening returned it, then the computer and the account were released. Because the VU backing up the harm or risk of data loss are minimal. There were no students or employees have come forward that have been lost by the ransomware files.

Last weekend decided the technical department to put the network on read-only, so that the virus could not do his job. "The IT department had more clout to clean everything," Scoop notes. At the VU is a lot of work with group drives, where students store their documents. "Now it's wait and see how it is spread. The virus mutates continuously. Our IT department is aware that it can emerge in other places." At 200 computers Crypto Locker was eventually found.

Emails

"The complicated is that the virus ever mutates. In the beginning was warned mails from unknown senders or stranger left. But it now seems also that it can attach to emails from colleagues. Why is continuously scanned . It is therefore not sufficient to keep only foreign mails outside, because it seems to be mutated itself. "

It is currently unclear whether the students or employees who were initially opened the infected emails. When the first infections through Crypto Locker emerged the university decided to warn in different ways for the ransomware. "It is very much shut out by the security systems. In an organization such as a university, it is impossible to rule out anything. So there is a balance to be searched."

Virus Scanner

The network has now picked up again in read-only. In addition, the university is also looking forward a new type of virus that may in addition have to go, but the details are not yet known. According Spoon would not get the first time that make VU ransomware. A few months ago would have been some isolated cases. "But when that had no effect and that was resolved pretty quickly."

Friday, 16 January 2015

Cryptowall 3.0 - "Microsoft Sees Hundreds Of New Infections By CryptoWall"


After two months of silence, there is a new version of the CryptoWall-ransomware appeared that managed to infect one day 288 Windows computers, says Microsoft. CryptoWall 3.0 spreads the same way as previous versions, namely via drive-by downloads and installation by malware already present on computers. Once active encrypts CryptoWall kinds of files and then asks for an amount of 500 euros in bitcoin. Victims receive 167 hours to pay, and the price is increased. In previous versions it was then a sum of 1,000 euros.

Cryptowall Decrypt Service.

Communicated the older versions of CryptoWall still using the Tor network, CryptoWall 3.0 uses I2P, which stands for Invisible Internet Project (I2P), says researcher JuK of the blog Malware Do not Need Coffee . I2P is a network layer allowing application messages safely and pseudo-anonymous can exchange. 

Cryptowall 3.0 communications with C&C

The earlier versions of CryptoWall would be more than 830,000 computers have been infected, making it the most "successful" ransomware until now.

VirusTotal Report Zip File: c77a463c5f6481efee38bba2bc8bf085

VirusTotal Report: 6c3e6143ab699d6b78551d417c0a1a45

VirusTotal Report: 47363b94cee907e2b8926c1be61150c7