EMAN ransomware decryptor

Backups are absolutely critical indeed but the AV is the first line of defense. Policies are what makes or breaks security though.

The real beauty is when the backup system is setup in such a silly way that the ransomware gets access to it and encrypts the backups as well :D
And just imagine the moment if the ransomware fail and encrypts his own executable files too.
 
The real beauty is when the backup system is setup in such a silly way that the ransomware gets access to it and encrypts the backups as well :D

This is why I believe the backup needs to be a different physical device connected (or not connected anywhere lol) to a different network.

Edit, it should be at a different place too. in case of fire or water logging, the backup devices would be safe.
 
Backups are absolutely critical indeed but the AV is the first line of defense. Policies are what makes or breaks security though.

The real beauty is when the backup system is setup in such a silly way that the ransomware gets access to it and encrypts the backups as well :D

Yeah ahaha, holy shit I had to check this thing indeed, but the rans was blocked before getting into the backup. When the NAS ends the backup on his external hard disk, it automatically detaches it. If the previous IT didn't set this up, I swear I would have left the company right away
 
This is why I believe the backup needs to be a different physical device connected (or not connected anywhere lol) to a different network.

It definitely needs to be on a separate device for that purpose alone because otherwise you can't enforce the next step: proper permissions. Other devices should be able to append only (never have access to overwrite/delete). Deleting should only be allowable from the terminal of the backup device.
 
Thank god for you at least the company didn't suffer what could have been a terrible disaster! I am sorry I cannot help because I am nowhere near pro at programming stuff. Sorry!
 
It only needs to run once to do its thing :)
A restart while doing the 'job' will be deadly for it :D

While back when I was reading about this, someone had the BTC address traced and it had around 50-60 BTC on it if I am not wrong.
 
Talking about ransomeware, secured backups are much better than av.
Nope. Both are required. AV protects from infections and backups are there for different types of crisis.

You haven't been out in the world yet, have you? :D
Correct mate. I have not worked in an office or any kind of company yet. But yes I get what you are saying. If there was an actual synonym to describe most of the IT guys out there, it would be Noobs who don't have basic common sense.

The real beauty is when the backup system is setup in such a silly way that the ransomware gets access to it and encrypts the backups as well :D
Like I said, Silly = Majority of the IT guys in the world. :D
 
How would you know it's running and doing it's job? ;)
The sad story is: My ex-gf called me. She was really happy. I was like: "What's all the noise about?", "Babe, I think I became a millionaire!!". To make it short, she received a spam mail about winning a lottery.
She had the "ticket" downloaded where she was supposed to "sign". As I already knew what is going on, I was running like a f*cking maniac, not because she did that, but because the laptop was mine!
Everything was laggy and some .exe file with random generated name was using 25% of my CPU (it was using 1 core). When I opened my D: drive the files were literally getting renamed and encrypted in real time.

The good things out of this story are:
1. I didn't have anything important on my lap top, except for some college lectures
2. She is not my GF anymore.
 
A restart while doing the 'job' will be deadly for it :D

While back when I was reading about this, someone had the BTC address traced and it had around 50-60 BTC on it if I am not wrong.

How would you know it's running and doing it's job? ;)

Totally, the ransomeware can be activated remotely. Also, I was trying to trace some addresses, ransomeware was really a way to make huge money, hackers usually have few hundreds btc (mid of 2017).
 
If there was an actual synonym to describe most of the IT guys out there, it would be Noobs who don't have basic common sense.

Absolutely. And the reason for that is that people who understand security a) are few and far between and (as a result) b) cost a lot. What's worse is that security means discomfort for the users and someone has to take the decision to enforce the policies the IT person will come up with. Good luck with that. As a result, the average small company rarely has any other option other that pure luck.
 
Absolutely. And the reason for that is that people who understand security a) are few and far between and (as a result) b) cost a lot. What's worse is that security means discomfort for the users and someone has to take the decision to enforce the policies the IT person will come up with. Good luck with that. As a result, the average small company rarely has any other option other that pure luck.
Exactly.
 
Nope. Both are required. AV protects from infections and backups are there for different types of crisis.

There is no infection, just click the file, it runs. Hacker usually FUD the executable file before spreading, so av sometimes can't catch. Back in 2017, KAV let the file run :|, only ESET stops the file, but it don't delete it because of virus. It just stops the file because of setting to not change the system files.
 
Everything was laggy and some .exe file with random generated name was using 25% of my CPU (it was using 1 core).

It was good luck that this was a silly malware. A competent piece would have done the encryption on an NTFS alternate data stream using a small percentage of the CPU. In plain English, this means everything would appear and work normal (except file sizes) until the moment the malware would delete the data in the normal file stream.

Take a look here for an easy example of how alternate data streams work: https://blog.malwarebytes.com/101/2015/07/introduction-to-alternate-data-streams/
 
Hacker usually FUD the executable file before spreading, so av sometimes can't catch.

This is one of the things people don't want to wrap their heads around. AVs protect you from already detectable attacks and making a detectable executable into a (currently) undetectable isn't a big deal. As a result of not wanting to understand this, people idolize AVs.

In short, AVs are good to have but should be treated with the mentality of "it only goes so far, the rest is on me".
 
Hi my laptop infected with .FORMAT ransomware, i removed the ransomware but files are not able to open, anyone know how to recover my files.
 
Hi my laptop infected with .FORMAT ransomware, i removed the ransomware but files are not able to open, anyone know how to recover my files.
No decryption key = you are fked.
Try looking for decryption keys for that particular ransomwarr. Chances are, that it has already been decrypted (although thats a very slim chance, because hackers create keys for every victims these days).
 
Back
Top