umerjutt00
Elite Member
- Oct 28, 2011
- 4,373
- 2,493
Any idea how you got it in the first place? Downloaded something? 
Any idea how you got it in the first place? Downloaded something?![]()
Ahh yes, good old cryptolocker. This has got to be 3.0 or 4.0 already, because this is the third or fourth time I've seen them change up that message. Got infected with this a year or so ago, not fun@alwaysinvisible thats what I am going to have to do. Its a virtual server so its no big issue. My main concern was my dropbox account. I wasnt sure if there was a way for them to infect those files and then infect all of my other servers.
Here is the message that was left when I logged into the server...
These viruses are normally relatively easy to remove, just run your av and also malware bytes.
Worst thing is the damage they do - normally they leave a text file in each location along with encrypting all of your files.
To clean up I normally search across the entire computer for that text file then you know all the locations that have been infected.
There are some sites I'm sure that offer decryption keys for some strains of the virus but other than that your only options for decrypting files are paying the ransom or restoring from backup.
Dropbox and most other file sharing programs have a serious flaw that makes them weak against these type of viruses - with Dropbox you can restore your files to previous versions (if you have the paid addon up to 12 months worth) but you can only do so one file at a time. So if crypto as infects Dropbox and then syncs across your devices you lose everything.
As for actually spreading the virus, I've never seen that happen. But of course you do need to identify the source - normally an email, a word doc, a PDF or a price of cracked software. And it normally infects a few days after you bring in the malicious code.
If you need any more help let me know.
Personally I'd never go anywhere near this. Ransomware is literally the shittest thing one can do, but boy are they making some serious green.
@tymillz If you are concerned about the Dropbox files I wouldn't worry too much, as I doubt the virus would be that advanced, but to be in the safeside you could always download the files and put them onto a VM or fresh VPS and see what they do. Also, try change the pw for dropbox and log out from everywhere for a while
You clearly don't know what u are talking about. If it's a self hosted server u should wipe it if it's in a data center ask for a rollback.
i was about to comment about this one, they paid up $15k for the ransom, the files were decrypted and all was fine but the ransomers weren't caught. rumour has it most hospitals have terrible security when it comes to hacking and viruses leaving a lot of vulnerable targets.That's nothing... I've heard one where they put ransomware on a Hospital system....
You can guess yourself what the level of urgency was like to pay up
@Asif WILSON Khan thanks. Thats pretty much what Ive been doing all night. A friend of mine knows alot more about this type of stuff so I had him take a look. He found the name of the ransomware and used one of the decryptors to get everything back. Right now Malwarebytes and HitmanPro is running.
Even though I have everything back I still plan on rolling the system back.
RSA 4096 is hardcore encryption. These guys ain't foolin around.
Dropbox has file versioning. If they encrypt your files today, you simply take it down on the infected box, go to Dropbox via the web and return all files to their previous version. Also Dropbox has undelete, so you can recover the files the encryption program has deleted.
Last year a disgruntled former co-worker deleted the corporate Dropbox folder. We were working on a team project and when we got to a meeting 9AM there were no files on Dropbox. We panicked for about 10 minutes until a coworker said Dropbox keeps backups of everything even if you delete it. 2 minutes later and all our clients are downloading a fresh version of the files again, nothing lost.
Lately I've been looking into these shared SEO tools accounts. $20 for a bunch of tools that'd cost over $1000 sounds too good to be true. These tools come with a special version of Firefox. This Firefox could be boobietrapped where if you try to open its password file where it keeps the passwords of the tools, it locks your computer via ransomware. If you get the passwords hidden in Firefox, you can use the tools without paying the next month and without their Firefox. But if they included ransomware as part of their protection, then it's gonna be a case for the FBI pretty soon. I'm not saying any of these shared SEO tools did it, but by OP's description this is definitely possible.
i was about to comment about this one, they paid up $15k for the ransom, the files were decrypted and all was fine but the ransomers weren't caught. rumour has it most hospitals have terrible security when it comes to hacking and viruses leaving a lot of vulnerable targets.
stuff like this i basically on par with bank robbery, locking down a hospital's system in my eyes is the same as taking hostages and putting a gun to their head, only easier for them to get away with it.This aint even black hat anymore... Just straight up darknet sh!t. Hedge funds also have shaky security...
Probably is a market somewhere to prevent sh!t like this
@Asif WILSON Khan thanks. Thats pretty much what Ive been doing all night. A friend of mine knows alot more about this type of stuff so I had him take a look. He found the name of the ransomware and used one of the decryptors to get everything back. Right now Malwarebytes and HitmanPro is running.
Even though I have everything back I still plan on rolling the system back.
@tymillz
Hi just ran into this ransom on a customer. Would be great if you can name the ransom and the decryptor, maybe i have a chance to recover the files. Important customer files, no backup :-/