Ransomware issue

Any idea how you got it in the first place? Downloaded something? :)
 
Any idea how you got it in the first place? Downloaded something? :)

Thats the part Iv'e been trying to figure out. Im usually careful with things of this nature. The only thing that I use on that server are IM related programs and most of those programs that I use are trusted programs. The one thing that I did recently was use a service called "SEOTOOLKIT" about a month ago. I was taking the cheap way of using a few services (Moz,MAjestic, etc) that I didnt have membership to. I eventually signed up to those sites so I let the SEOTOOLKit membership expire yesterday and today, voila, ransomware. In order to use the service you have to install a chrome plugin. This may not be the issue but its the only thing Iv'e done on that machine that I wouldn't dare do on my other machines.
 
@alwaysinvisible thats what I am going to have to do. Its a virtual server so its no big issue. My main concern was my dropbox account. I wasnt sure if there was a way for them to infect those files and then infect all of my other servers.

Here is the message that was left when I logged into the server...
Ahh yes, good old cryptolocker. This has got to be 3.0 or 4.0 already, because this is the third or fourth time I've seen them change up that message. Got infected with this a year or so ago, not fun

To be safe, make sure you completely wipe your server, no exceptions. Dropbox is trickier, however in that you likely won't have backups of that.

It's a calculated risk, if you feel like your Dropbox wasn't infected then you can do your own due diligence to cleanse it, and then hope that you're right. I would recommend throwing away the files, even though it sucks to have to do that.

In the future, keep constant backups of servers and drives like you're probably already doing, but make sure to do the same thing for cloud storage too. I like to take a backup of my Google Drive every month or so, and a hard-and-fast backup rule like that is probably a good thing for everybody to implement eventually.
 
Pause syncing of dropbox on the infected vps or better still uninstall it. You should stop it spreading to other connected pc's.

There are decrypters available for some strains of malware if you're lucky. I posted some links recently but not got time to find them now sorry.

After that if its a vps then quickest its re-install and then setup dropbox again.

Before reinstalling or setting up dropbox check your file modification dates. everything modified after the problem should be reverted to a previous version if possible (especially watch .exe, .js etc files)
 
These viruses are normally relatively easy to remove, just run your av and also malware bytes.

Worst thing is the damage they do - normally they leave a text file in each location along with encrypting all of your files.

To clean up I normally search across the entire computer for that text file then you know all the locations that have been infected.

There are some sites I'm sure that offer decryption keys for some strains of the virus but other than that your only options for decrypting files are paying the ransom or restoring from backup.

Dropbox and most other file sharing programs have a serious flaw that makes them weak against these type of viruses - with Dropbox you can restore your files to previous versions (if you have the paid addon up to 12 months worth) but you can only do so one file at a time. So if crypto infects Dropbox and then syncs across your devices you lose everything.

As for actually spreading the virus, I've never seen that happen. But of course you do need to identify the source - normally an email, a word doc, a PDF or a price of cracked software. And it normally infects a few days after you bring in the malicious code.

If you need any more help let me know.
 
You clearly don't know what u are talking about. If it's a self hosted server u should wipe it if it's in a data center ask for a rollback.

These viruses are normally relatively easy to remove, just run your av and also malware bytes.

Worst thing is the damage they do - normally they leave a text file in each location along with encrypting all of your files.

To clean up I normally search across the entire computer for that text file then you know all the locations that have been infected.

There are some sites I'm sure that offer decryption keys for some strains of the virus but other than that your only options for decrypting files are paying the ransom or restoring from backup.

Dropbox and most other file sharing programs have a serious flaw that makes them weak against these type of viruses - with Dropbox you can restore your files to previous versions (if you have the paid addon up to 12 months worth) but you can only do so one file at a time. So if crypto as infects Dropbox and then syncs across your devices you lose everything.

As for actually spreading the virus, I've never seen that happen. But of course you do need to identify the source - normally an email, a word doc, a PDF or a price of cracked software. And it normally infects a few days after you bring in the malicious code.

If you need any more help let me know.
 
Personally I'd never go anywhere near this. Ransomware is literally the shittest thing one can do, but boy are they making some serious green.

@tymillz If you are concerned about the Dropbox files I wouldn't worry too much, as I doubt the virus would be that advanced, but to be in the safeside you could always download the files and put them onto a VM or fresh VPS and see what they do. Also, try change the pw for dropbox and log out from everywhere for a while


That's nothing... I've heard one where they put ransomware on a Hospital system....


You can guess yourself what the level of urgency was like to pay up
 
You clearly don't know what u are talking about. If it's a self hosted server u should wipe it if it's in a data center ask for a rollback.

Clearly. I've only be in the IT industry for 20 years. And I have probably only dealt with crypto-ware a couple of hundred times in corporate environments including data centers. So yea, I am a bit of a novice on the subject :-)
 
That's nothing... I've heard one where they put ransomware on a Hospital system....


You can guess yourself what the level of urgency was like to pay up
i was about to comment about this one, they paid up $15k for the ransom, the files were decrypted and all was fine but the ransomers weren't caught. rumour has it most hospitals have terrible security when it comes to hacking and viruses leaving a lot of vulnerable targets.
 
@Asif WILSON Khan thanks. Thats pretty much what Ive been doing all night. A friend of mine knows alot more about this type of stuff so I had him take a look. He found the name of the ransomware and used one of the decryptors to get everything back. Right now Malwarebytes and HitmanPro is running.

Even though I have everything back I still plan on rolling the system back.
 
I once got all devices infected (almost) and it was spreading through modem on all devices in our home. I will now explain why I say "almost" and how I solved the problem.

The thing is, while I was trying to find a cure for this problem I had on all devices there was constantly some site poping out as only solution. But I didnt want to download their "free" program to remove this ransomware since this "site" looked semi-dodgy. Actually, this free program was what they wanted me to download . So, annoying thing that was spreading through devices didn't block the PCs, their goal was just to bother me as much as they can so I start searching for solution (antivirus programs didn't manage to delete this annoyance. I tried all the possible softwares ) .

Later, when I found out (reading on forums) that my problem is actually lurking in my modem and acting from there I restarted modem to factory settings and this cleared all devices.
 
RSA 4096 is hardcore encryption. These guys ain't foolin around.

Dropbox has file versioning. If they encrypt your files today, you simply take it down on the infected box, go to Dropbox via the web and return all files to their previous version. Also Dropbox has undelete, so you can recover the files the encryption program has deleted.

Last year a disgruntled former co-worker deleted the corporate Dropbox folder. We were working on a team project and when we got to a meeting 9AM there were no files on Dropbox. We panicked for about 10 minutes until a coworker said Dropbox keeps backups of everything even if you delete it. 2 minutes later and all our clients are downloading a fresh version of the files again, nothing lost.

Lately I've been looking into these shared SEO tools accounts. $20 for a bunch of tools that'd cost over $1000 sounds too good to be true. These tools come with a special version of Firefox. This Firefox could be boobietrapped where if you try to open its password file where it keeps the passwords of the tools, it locks your computer via ransomware. If you get the passwords hidden in Firefox, you can use the tools without paying the next month and without their Firefox. But if they included ransomware as part of their protection, then it's gonna be a case for the FBI pretty soon. I'm not saying any of these shared SEO tools did it, but by OP's description this is definitely possible.
 
@Asif WILSON Khan thanks. Thats pretty much what Ive been doing all night. A friend of mine knows alot more about this type of stuff so I had him take a look. He found the name of the ransomware and used one of the decryptors to get everything back. Right now Malwarebytes and HitmanPro is running.

Even though I have everything back I still plan on rolling the system back.

That's good to hear!
Hitman pro = great tool.

Would be good to put backup in place going forward - especially for your Dropbox. You can run a scripted backup with something like duplicati on windows, or you can connect Dropbox to a Linux box and back up using rsync or something similar.

RSA 4096 is hardcore encryption. These guys ain't foolin around.

Dropbox has file versioning. If they encrypt your files today, you simply take it down on the infected box, go to Dropbox via the web and return all files to their previous version. Also Dropbox has undelete, so you can recover the files the encryption program has deleted.

Last year a disgruntled former co-worker deleted the corporate Dropbox folder. We were working on a team project and when we got to a meeting 9AM there were no files on Dropbox. We panicked for about 10 minutes until a coworker said Dropbox keeps backups of everything even if you delete it. 2 minutes later and all our clients are downloading a fresh version of the files again, nothing lost.

Lately I've been looking into these shared SEO tools accounts. $20 for a bunch of tools that'd cost over $1000 sounds too good to be true. These tools come with a special version of Firefox. This Firefox could be boobietrapped where if you try to open its password file where it keeps the passwords of the tools, it locks your computer via ransomware. If you get the passwords hidden in Firefox, you can use the tools without paying the next month and without their Firefox. But if they included ransomware as part of their protection, then it's gonna be a case for the FBI pretty soon. I'm not saying any of these shared SEO tools did it, but by OP's description this is definitely possible.

That's right, but the bad thing is this - Dropbox only allows you to restore file by file on their revisions or download everything en-mass, so if crypto infects everything and it has a chance to sync you'd have to get the revision one by one for every file.

For my Dropbox I have it connected to a Linux box which I back up daily with veeam, and then I do a manual backup every quarter as well.
 
i was about to comment about this one, they paid up $15k for the ransom, the files were decrypted and all was fine but the ransomers weren't caught. rumour has it most hospitals have terrible security when it comes to hacking and viruses leaving a lot of vulnerable targets.


This aint even black hat anymore... Just straight up darknet sh!t. Hedge funds also have shaky security...

Probably is a market somewhere to prevent sh!t like this
 
This aint even black hat anymore... Just straight up darknet sh!t. Hedge funds also have shaky security...

Probably is a market somewhere to prevent sh!t like this
stuff like this i basically on par with bank robbery, locking down a hospital's system in my eyes is the same as taking hostages and putting a gun to their head, only easier for them to get away with it.
 
@Asif WILSON Khan thanks. Thats pretty much what Ive been doing all night. A friend of mine knows alot more about this type of stuff so I had him take a look. He found the name of the ransomware and used one of the decryptors to get everything back. Right now Malwarebytes and HitmanPro is running.

Even though I have everything back I still plan on rolling the system back.

@tymillz
Hi just ran into this ransom on a customer. Would be great if you can name the ransom and the decryptor, maybe i have a chance to recover the files. Important customer files, no backup :-/
 
@tymillz
Hi just ran into this ransom on a customer. Would be great if you can name the ransom and the decryptor, maybe i have a chance to recover the files. Important customer files, no backup :-/

I had a friend take care of it for me. Ill find out from him and will respond here once I get a response from him.
 
Back
Top