Showing posts with label Cryptowall. Show all posts
Showing posts with label Cryptowall. Show all posts

Saturday, 7 November 2015

CryptoWall-Ransomware Ransom Increases To 700 Euro


There is a new version of CryptoWall-surfaced ransomware that encrypts file names, victims speaks in a derogatory way and the ransom amount has increased to 700 euro, so researchers at the forum Bleeping Computer discovered.

CryptoWall is a form of ransomware which kinds of files on the computer encrypts. For decrypting victims must then pay. The first variant was last May discovered. This release early victims still 500 for decryption. If victims do not paid this amount was increased to 1,000 euros a time. With CryptoWall 4.0 that figure has now 1400 euros.

The new version also stands out because not only the contents of files are encrypted, but the file names. This is probably done to frustrate victims and make it difficult to determine which files need to be restored, says Lawrence Abrams Bleeping Computer. Like previous versions, removes all CryptoWall 4.0 Volume Shadow copies, turn off System Restore and Windows Startup Repair. Also makes use of the computer, on the basis of operating system and processor, a unique identification number.

Another change in Crypto 4.0 is the text to see victims of an encrypted computer get. Namely, that it has acquired a derogatory tone. So victims are addressed as "Congratulations !!! You have become part of the great CryptoWall community."It is also assumed that victims do not understand the explanations about encryption. Next, the creators which CryptoWall is not malicious and that together with the victims make the Internet safe. How the new version spreads exactly is unknown, but previous versions used mainly e-mail attachments and unpatched software.

Wednesday, 23 September 2015

Ransomware: US County Pays Ransom



The IT department of Miami County in the US state of Ohio has on the advice of a security $ 700 paid to the creators of CryptoWall-ransomware so the county encrypted files recovered. Early September was faced by the county with an infection.

The administrative computer system of the communication was via e-mail gets infected by the ransomware said Troy Daily News. This center is also responsible for the 911 emergency service in the county, but the network of these became infected. The ransomware early $ 700 in bitcoins, which Miami County on the board finally paid advised by a security expert. According to the expert would be the retrieval of the encrypted document in this way be cheaper and faster, reports Dayton Daily News.

Saturday, 19 September 2015

Thousands Of Hacked WordPress Sites Spread Malware


Attackers have managed to hack thousands of WordPress sites and use them for distributing malware, including the website of a US security. Before that warns security firm Sucuri. It would now go to 6,000 contaminated sites.

The attacks on the WordPress websites began two weeks ago. The hacked sites placed code that visitors unnoticed a page with the Nuclear-exploitkit late charge. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. Among the hacked WordPress sites are among other Coverity's website, a company dealing with security software.

How the attackers access to the WordPress sites managed to get has not been determined yet, but the attackers seem to create vulnerabilities in WordPress plugins use. Not just forget owners of WordPress flocking to update the software on their website, including updates to installed plug-ins will be forgotten. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use.

Friday, 18 September 2015

Increase In Brute Force Attacks Against WordPress Sites


WordPress sites get more and more to do with brute force attacks, in which it tries to log in using common passwords on the website. According to figures from security firm Sucuri that brute force attacks keep on WordPress websites.

According to Daniel Cid Sucuri his brute force attacks is still one of the main reasons why websites are hacked. "If you have you have to do with brute force attempts to make an unsecure login page", he tells. Administrators of a WordPress website can according to Cid take various measures against these types of attacks, such as setting captchas, only allowing certain IP addresses (IP whitelisting) and two-factor authentication.

Other WordPress administrators say that the attacks can be prevented simply by changing the URL of the login page and block in the .htaccess / IIS configuration. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use. Regular security reports about large numbers of WordPress sites that have been hacked and used to spread malware.

Monday, 7 September 2015

Millions Of WordPress Websites Vulnerable To Hackers


WordPress is by far the most popular content management system (CMS) on the Internet, but many administrators forget to update the software or use vulnerable plug-ins, allowing millions of websites are at risk of being taken over. The Danish security Heimdal Security warns that the looks of hacked WordPress websites that distribute ransomware on the rise.

The websites are malicious code placed that visitors unnoticed to a page with the Neutrino-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player, Adobe Reader and Internet Explorer users have not patched. In case the attack is successful, the Tesla Crypt-ransomware placed on the computer, mainly computer games-related data encrypted. Next, there to decrypt the files to be paid.

According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use. The latest WordPress version 4. This version is used by 79.9% of WordPress sites. 20.1% running on WordPress version 3 or older. The latest version of WordPress 3 appeared on November 20, 2014 and fixed it several security vulnerabilities. Also, version 4 have been different versions appeared, in part because of vulnerabilities.

In the 79.9% which WordPress uses 4 can therefore which users are still running a vulnerable version. Each month WordPress websites are 409 million people read. According Heimdal Security is therefore important that WordPress administrators to install available updates, both for their own website as the safety of their visitors.

Sunday, 23 August 2015

Thousands Of Hacked WordPress Sites Spread Ransomware


In recent weeks attackers have hacked more than 2600 unique WordPress sites and provide malicious code that attempt to infect visitors with ransomware. The hacked WordPress sites are all running version 4.2 of the software or older, says security firm Zscaler.

The attack on the WordPress sites consists of several steps. First, the site is accepted in full. So the attackers add a Webshell, and steal the credentials of the administrator. Is then added an iframe to the website that visitors to the WordPress site unnoticed a page with the Neutrino-exploitkit late charge. The iframe code only to users of Internet Explorer is shown. A cookie will prevent victims of the iframe code are offered several times.

To infect users makes the Neutrino-exploitkit using a malicious Flash file. In case Flash Player not installed on the computer, the user is offered an old Flash installation file, and the malicious file is loaded. Do not know how the installer will install exactly Zscaler allows the analysis of the attack.

In case the attack is successful, the ransomware CryptoWall-installed on the computer. This ransomware encrypts files on the computer and asks users a certain amount for decrypting. According to analyst John Mancuso WordPress remains an attractive target for cyber criminals. WordPress is a very popular free content management system used by more than 60 million websites, including about 23% of the Top 10 million websites on the internet.

Wednesday, 12 August 2015

IE Vulnerability Used To Distribute Ransomware


A vulnerability in Internet Explorer that Microsoft only three weeks ago patched is now actively used to infect computers with ransomware. The vulnerability exists in IE6 to IE11. Visiting a malicious or hacked website or see getting an infected ad is enough for an attacker to install malware on the computer for example.

The exploit that uses the vulnerability has been developed by the creators of the Angler Exploitkit. According to security researcher ' JuK 'of the blog Malware do not need Coffee makers could possibly since July 24 with the development of the exploit have been busy, two days after the release of the update. The makers of Angler developed previously often very quickly just exploits for unpatched vulnerabilities in Adobe Flash Player. Many Internet users are slow to patch. Even though there are security updates available, there are still computers are not up-to-date and can be attacked.

Adobe

According to security firm FireEye is noteworthy that the creators of the Angler Exploitkit now suddenly focus on an IE vulnerability. In recent months, were in fact only developed exploits for Flash Player vulnerabilities, with an exploit for Microsoft Silverlight as an exception. One possible explanation, according to the security at the security measures Adobe has taken to prevent abuse of vulnerabilities.

Depending on the software installed Internet, try the Angler Exploitkit attacks through vulnerabilities in Flash Player, Silverlight and Internet Explorer. In case the attack is successful CryptoWall-ransomware is installed. This ransomware encrypts files on the computer and then asks for a fee to decrypt them.

Tuesday, 4 August 2015

American Town Pays Twice Ransom To Ransomware



A town in the US state of New York last year twice in a short time become a victim of ransomware. And twice it was decided to pay the ransom. It went together to the tune of $ 800. The infections were carried out in Ilion, which consists of 8,000 inhabitants.

The malware was spreading in both cases via e-mail attachments and encrypted both payroll and accounting systems, as the mayor opposite let NBC know. The infections, which occurred in January and May, were reported ( pdf ) by the Office of the State Comptroller. "These incidents are a wake-up call for local governments in the state," as late Comptroller Thomas DiNapoli know. "Although the amount of money was low and no vital information was leaked, this attack does show that lack of standard IT security taxpayers expense can hunt and functioning of cities and school districts can disrupt."

Canada

The problem of ransomware plays not only in the United States. Recently, also various systems of two Canadian towns hit by ransomware. When the infection in Mahone Bay were encrypted files back to 2007. An officer received an email supposedly a resume. The enclosed zip file appeared to be the CryptoWall-ransomware. Since the malware no important data encrypted was not proceeded to pay.

In the case of the infection in the Canadian Bridgewater would even talk of two ransomware specimens have been, namely CryptoWall and Crypto Locker, let the Chief Administrative Officer of the city across from CBC News to know. Also in this case would no important files are encrypted there and the ransom was not paid. To prevent a new infection is now controlled security against ransomware and henceforth be made ​​offline backups.

Thursday, 16 July 2015

Microsoft Windows Computers Check On Ransomware



Microsoft this month controlled hundreds of millions of Windows computers on the presence of ransomware. The audit took place over the Malicious Software Removal Tool (MSRT), the standard Windows virus removal tool which can detect the most prevalent families of malware and remove it.

The tool will be updated every month, so a number of new active malware families can be recognized. Simultaneously, the MSRT scans the computer also in these families. This month Microsoft released an update released so CryptoWall- and-Reveton ransomware on computers can be recognized. CryptoWall spread via email attachments, can be bundled with other malware, or downloaded by exploit kits. In May and June, Microsoft saw 300,000 computers that were infected with Crypto Wall. Once active, the ransomware encrypts all kinds of files and then demands amount to decrypt them. The infections were mainly in the United States and Brazil have been observed.

Microsoft warns users therefore not to open suspicious e-mail attachments. Also, according to the software giant does not guarantee that users after paying the ransom regain access to their files, or that the PC is again restored to its original state.Microsoft recommends paying the ransom than not also. In addition, users of an infected computer via File History recover their files.

The second ransomware family where Microsoft is focused on using the MSRT is Reveton. This family has often been the target of the virus removal tool. The ransomware locks computers and then shows a message that appears to come from the FBI or local police. According to the report, the user has committed a crime and should be a penalty to be paid. In this case, it only involves a warning. Users' files are not encrypted by Reveton.

Wednesday, 24 June 2015

FBI Warns CryptoWall-Ransomware



Both consumers and businesses in the last year lost millions because they were victims of CryptoWall-ransomware, reason for the FBI to issue a warning. CryptoWall a ransomware variant that encrypts files for ransom.

According to the US, it is the most active investigation service ransomware threat in the United States. In addition, the damage is often greater than the demanded ransom, which is between $ 200 and $ 10,000. Many victims would be faced with additional costs due to network security, taking countermeasures, productivity loss, legal fees, IT assistance and arranging credit monitoring for employees and customers.

Between April 2014 and June 2015, the FBI received 992 complaints about CryptoWall, in which victims indicated that they had lost more than $ 18 million. To avoid infection by ransomware advises the FBI to use a virus scanner and firewall, install pop-up blockers, making backups and to be skeptical. "Do not click on e-mails or attachments you do not recognize and avoid suspicious websites." The latter recommendation, however, does not account for the large number of hacked websites and infected ads on legitimate websites that cyber criminals use ransomware to spread.

Thursday, 18 June 2015

Adobe Flash Player Popular With Cyber Criminals


Despite an automatic update function Adobe Flash Player continues to be very popular with cyber criminals, who last week patched vulnerability now use the browser plug-in for the spread of ransomware. Reported that the Japanese anti-virus company Trend Micro .

Although the patch is available and can be installed automatically by Flash Player, shows that particularly American, British and Canadian users who did not. In Belgium and Germany are perceived attacks via the vulnerability. It has become a trend in which after the appearance of a Flash Player update cyber criminals develop an exploit to attack users who have not installed the update.

"Many people are still running the previous version, meaning that a large number of users at risk," said analyst Peter Pi. The exploit that uses the vulnerability in Flash Player has been added to the Magnitude Exploitkit. Once unpatched users land on a malicious or hacked page or see an ad that points to this exploitkit, they may become infected with undetected malware.

In this case CryptoWall 3.0-ransomware is installed. These kinds of ransomware encrypts files on the computer and then asks for a certain amount to decrypt the files. Recently warned ( pdf ) also anti-virus company McAfee mean it had observed a sharp increase in the number of attacks in the first quarter of this year via Flash Player vulnerabilities. Adobe Flash Player users would now be using version 18.0.0.160, which through this page can be checked.

Tuesday, 9 June 2015

Cv Ransomware Spreading Through Double Zip File

How It Works
The use of CVs and zip files to distribute ransomware has long been distributing a successful method for cyber criminals to ransomware and other malware, but researchers from Cisco recently discovered an attack in which two zip files were used.

The attack begins with an email claiming to be a response to a previous mail contains an attached zip file. The zip file contains no resume, but an HTML file. This HTML file refers to a hacked WordPress page with an iframe. This iframe pointing back to Google Drive where the second zip file is downloaded. The contents of the zip file is a .scr file that actually CryptoWall is 3.0 ransomware.

This ransomware encrypts then all kinds of files on your computer and requires a certain amount to decrypt them. According to Cisco cyber criminals with this kind of tricks, and the use of macros and password-protected zip files, very successful in bypassing various security solutions.



Hashes:

Zip Files:

6be76dcc877ac42d5af53807b4be92172dea245142e948dba1367c274ab6a508
36da04ec68a9e0031f89d12065317f8a64ca3598ad0349991fb684e323435a62
10fbbeb985f18de13a145f05314a4ab2aaf42fcc276c3e24c6491b6482fe1d5f
2a7b9016bb8004d101dba337c5d1e679c4b88bea198e425a42081ec4186e5b45
b53b58df6445bc4c754f178af66f0b3a5ddf1e93971439d05be61ad9f0bc0997
5fead4017f0770fd0dd8a99b97b514730f46c30ecd61857b1359701b2d73caa7
0c066baf5153cd8e522b74316fed24c075020ff59c52361f253918fa2d66c7ad
3889d489f3905164b2c5731b8fb9c9bbe95ead175c7070f0aa77efe040a18b35
5bf3471231a4b0a5ad0685c9ee36e9f1f21df3f6c8fcbcb83d60fd64cc513582
f6ad2ad1fceb98f6a61360afd17d02dab4c0d2919fa6ddfd978582cf044a9655
81af832b81e034dfe742698104a90c1ff6bd490e1c289a49968a15036a268a6b
2c03f7497ea8cfc4e8633f0ced8d28e65d8505f94e8d28297c7096f42d8bf2a2
2dd699613d9b6b709e4667457acefc3009db57684a85f488396c4e8f4c2d9521

Cryptowall 3.0:

Saturday, 23 May 2015

CryptoWall-Ransomware Spreading Through SVG Files


Cyber ​​criminals have found a new way to distribute ransomware, namely the use of SVG files, so says security firm AppRiver. Scalable Vector Graphics (SVG) is a graphics format that supports interactive features and animations.

Thus, it is possible to add scripts to an SVG image. The now discovered attack starts with an e-mail claiming to contain a resume. It is a ZIP file that contains an SVG file again. At the SVG is a piece of JavaScript added again downloads a ZIP file. This .zip file contains CryptoWall-ransomware. It is an EXE file that the user has to extract and open. Once opened encrypts CryptoWall kinds of files and then ask hundreds of dollars ransom to decrypt them.

Friday, 8 May 2015

Australia Warns Of CVs Ransomware

The Australian government has warned companies to resumes that are currently scattered through e-mail and try to infect computers with ransomware. The e-mail suggests someone and says that he has attached his job. It is a zip file that contains a JavaScript file again. Once this .js file is opened, the computer becomes CryptoWall-ransomware infected.

It is the same attack in the April 21 news came. The Stay Smart Online campaign by the Australian government suggests that the attack focuses on Australian companies and a new campaign is active since last week. CryptoWall encrypts files on the computer and then asks for a ransom here. The Australian government warns that many victims recover their files if they pay the ransom, but there is no guarantee, since users have to deal with criminals. "Prevention is therefore the best medicine for ransomware and other malware attacks," the campaign.

Tuesday, 21 April 2015

JavaScript Annex Spreads CryptoWall-Ransomware


In many email attacks are used executables and Office documents, but there are spammers that use JavaScript attachments. Before warns Trustwave. The security company recently discovered a spam campaign where emails were sent that contain supposedly a resume laity.

There was a zip file as an attachment sent with it a Javascript file, ending .js. Once the recipient opened the file the script tried to download an executable, which turned out to be a variant of the CryptoWall-ransomware. This ransomware encrypts all kinds of files on the computer and then asks hundreds of dollars for decrypting it.

On another spam campaign Trustwave discovered a phishing attack that also made ​​use of JavaScript. In this case, an HTML file was sent to JavaScript which recipients must enter their account details. "If an e-mail telling you to enable JavaScript that you should not really do," says analyst Brian Bebeau. "Despite the use of executable files and other exploits you can not ignore JavaScript attachments in your e-mail traffic. They can both your users and yourself cause problems."

Saturday, 21 March 2015

Ransomware Steals For The First Time Passwords


Researchers have for the first time discovered a ransomware variant installs simultaneously spyware to steal all kinds of passwords from the system. According to the Japanese anti-virus company Trend Micro is the first time that ransomware is bundled with spyware. However, the infection method of "CryptoWall 3.0" is equivalent to previous versions and other crypto ransomware.

Users receive an e-mail with a zip annex, which would contain a so-called CV. In reality it is a Javascript file. Once the user opens this file are downloaded two "JPG files." However, the extension is only intended to circumvent security systems.Once the files are downloaded performed by JavaScript. It is a variant of CryptoWall and Fareit spyware. CryptoWall encrypts all kinds of data on the computer and then asks for a sum of 500 euros to decrypt it.

Is not paid on time, then the user must pay 1,000 euros. While the user is thus inferred Fare it steal all types of passwords from FTP programs, browsers, email clients and bitcoin wallets says analyst Anthony Joe Melgarejo. He argues that there are several reasons why the spyware is bundled with ransomware, perhaps because people refuse to pay the ransom and thereby steal passwords is a backup plan. "

Even if the user refuses to pay would be the cyber criminals, for example via the passwords of the bitcoin wallets, still can steal money. To infections with these and other species to prevent ransomware, users advised to not open attachments from unknown senders. "In fact, they should ignore or delete e-mail from unknown senders," says Melgarejo.

Sunday, 8 February 2015

Renewed Ransomware Shows KLPD Warning


The makers of the Reveton ransomware-have after two years provide their creation of a new design, but at the latest "make over" Dutch users still get a warning that supposedly of the National Police Agency (KLPD) is derived. The KLPD However since January 1, 2013 passed in the National Police. According to the warning, the user has been guilty of storing and distributing child pornography.

Because of this crime is the computer locked and requires an amount of 100 euros paid to regain access, the report said.These so-called fine can be paid via Ukash and PaySafeCard. The ransomware also gives instructions where these vouchers to purchase. The police started in 2013 a campaign to warn shopkeepers as people came to buy this kind of vouchers.

According to researcher JuK of the blog Malware Do not Need Coffee spreads the ransomware via ads on porn sites that use a recent vulnerability in Adobe Flash Player. This vulnerability was on January 24 via an emergency patch Adobe poem. Due to the use of police logos and names Reveton is also called the "police virus."

Unlike crypto ransomware as CryptoWall and Crypto Locker users files are not encrypted by Reveton. The impact is therefore smaller for victims, partly because there are all kinds of tools and manuals are available online to remove Reveton similar ransomware. The past year also saw a particular rise in ransomware crypto while Reveton just came less in the news.

Friday, 16 January 2015

Cryptowall 3.0 - "Microsoft Sees Hundreds Of New Infections By CryptoWall"


After two months of silence, there is a new version of the CryptoWall-ransomware appeared that managed to infect one day 288 Windows computers, says Microsoft. CryptoWall 3.0 spreads the same way as previous versions, namely via drive-by downloads and installation by malware already present on computers. Once active encrypts CryptoWall kinds of files and then asks for an amount of 500 euros in bitcoin. Victims receive 167 hours to pay, and the price is increased. In previous versions it was then a sum of 1,000 euros.

Cryptowall Decrypt Service.

Communicated the older versions of CryptoWall still using the Tor network, CryptoWall 3.0 uses I2P, which stands for Invisible Internet Project (I2P), says researcher JuK of the blog Malware Do not Need Coffee . I2P is a network layer allowing application messages safely and pseudo-anonymous can exchange. 

Cryptowall 3.0 communications with C&C

The earlier versions of CryptoWall would be more than 830,000 computers have been infected, making it the most "successful" ransomware until now.

VirusTotal Report Zip File: c77a463c5f6481efee38bba2bc8bf085

VirusTotal Report: 6c3e6143ab699d6b78551d417c0a1a45

VirusTotal Report: 47363b94cee907e2b8926c1be61150c7