Malware- Wana DecryptOr - Need some help

just checked my vps and it looks so bad :/ formatting that's what left for me ...
 
http://www.huffingtonpost.com/entry/britain-cyber-attack-national-health-service_us_5915e62ae4b00f308cf4fc86

Cyber Attack That Crippled British Hospitals Among ‘The Largest Ever Seen’
 
Sorry OP, your best bet is to pay the ransom if the stored information are important.

The way ransom software's work is that they are automated with sending you the legit unlock code after payment ( 80% of them are ).

Just for information, this was running in the wild for some time now, 99% of our hosted VPS`s got hit and luckily only mining software was installed and no lockers..

And dont blame the attackers, NSA developed these exploits in the first place and it was developed in 2015. God knows what they have now.
 
Is phishing emails the only way this thing is getting around? Or are there other means?

Spent 3 hours today finding the latest security update and manually updating all my devices.
 
Is phishing emails the only way this thing is getting around? Or are there other means?

Spent 3 hours today finding the latest security update and manually updating all my devices.


According to the huffpo article a couple posts above, it also spreads through a server network, not just emails.


Sorry OP, your best bet is to pay the ransom if the stored information are important.

The way ransom software's work is that they are automated with sending you the legit unlock code after payment ( 80% of them are ).

Just for information, this was running in the wild for some time now, 99% of our hosted VPS`s got hit and luckily only mining software was installed and no lockers..

And dont blame the attackers, NSA developed these exploits in the first place and it was developed in 2015. God knows what they have now.


I just rebuilt the servers. Its all good. Clients of mine are kinda pissed, but nothing we can do about it. Shite, huge Corporations got hit hard too.
 
I just rebuilt the servers. Its all good. Clients of mine are kinda pissed, but nothing we can do about it. Shite, huge Corporations got hit hard too.

Its just the tip of the iceberg since the tools and source codes i have seen leaked on some underground forums include some encrypted 0day`s for Apache and other web platforms beside the windows exploits, so i am guessing there will be havoc for some time now until everyone updates their systems and official patches are released for all affected platforms/systems.
 
One of my clients machines got hit by a malicious encryptor 'Wana DecryptOr 2.0 Anyone aware of or know a program to unlock these files?
I had to wipe my entire harddrive a few years back from that shit. Its a huge pain in the ass.
 
I had to reinstall 2 VPS's. Seems like they attack each and every server in the world.

The largest attack I ever saw.
 
Sorry OP, your best bet is to pay the ransom if the stored information are important.

Do you really think someone is going to manage milions requests of unlocking codes (since the source of the infection is the same in this case) ?
They just don't give a f***k if you pay

Sorry OP the only possibility to decrypt was to make a RAM dump while the encrypting process was still active and analyze it with a forensic tool like AesKeyFinder or Elcomsoft forensic disk decryptor, but also in this case you should know what you was doing and in my experience you successfully decrypt in less than 5% of the cases.

Have a healty backup is the only way
 
Last edited:
Do you really think someone is going to manage milions requests of unlocking codes (since the source of the infection is the same in this case) ?
They just don't give a f***k if you pay

Its an automated system, and yes they do give a F*ck about the unlock codes, because if there are no unlock codes than whats the point of paying the ransom ?

Think twice before posting professor.
 
One of my clients machines got hit by a malicious encryptor 'Wana DecryptOr 2.0 Anyone aware of or know a program to unlock these files?
nomoreransom.org This website was made by Europol's Cybercrime Center EC3, I hope it helps you out.
 
Holy shit this is a big one. Windows VPS are busted, gonna throw them out and wait and start new fresh instances when this thing ends. Lucky they're all disposable.
 
Its an automated system, and yes they do give a F*ck about the unlock codes, because if there are no unlock codes than whats the point of paying the ransom ?

Think twice before posting professor.

I know who paid already and got nothing. The "check payment" button shown is totally fake, no automated systems as you say as 99% of ransomware doesn't have.

I usually think more than twice when I post, thanks.
 
I know who paid already and got nothing. The "check payment" button shown is totally fake, no automated systems as you say as 99% of ransomware doesn't have.

I usually think more than twice when I post, thanks.

I said 80%, read carefully.

Yes for sure... it's the people that make the guns, not the ones that fire them that should get life in prison...

p.s. that's a metaphor, no political intent, ... intended!

Well in this case the people that "made the guns" were "using the guns" as well. The only difference is that the "guns" weren't sold publicly.

And look at it this way, the people that spread lockers before had an rough estimate of lets say 15% success rate per 1000 infections.

Now they have the tools to increase that rate to almost 100% thanks to the hard working people in the NSA.
 
I said 80%, read carefully.

I read carefully, you should do the same.
You said 80% are automated = not true at all. Most of the cases you must write to a given email communicating payment has been done.
If the ransom would have automation, would be a lot easier intercept network connections it would be trying to establish and to trace source/take down for authorities.

I talk by experience for doing forensic analysis on about 15 variants of ransom, I guess you talk by what you heard / read on the net which is often misleading and contribute to feed wrong beliefs like if you pay at 80% it will be sent to you unlocking code.
 
Back
Top