A company I work with was hit when the employee opened a phishing email supposedly from another employee in the same company. It hit about 50 gb of data on the shared drive. We had Crashplan and restored from a few days previous. I then turned on DKIM and enabled quarantining non DKIM emails via DMARC.
I then turned on DKIM and enabled quarantining non DKIM emails via DMARC. Translation for techies who aren't familiar with email's many acronyms?
You’re infected—if you want to see your data again, pay us $300 in Bitcoins
21–30 of 295 posts
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#22Get a Mac.
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#23A company I work with was hit when the employee opened a phishing email supposedly from another employee in the same company. It hit about 50 gb of data on the shared drive. We had Crashplan and restored from a few days previous. I then turned on DKIM and enabled quarantining non DKIM emails via DMARC.
I then turned on DKIM and enabled quarantining non DKIM emails via DMARC. Translation for techies who aren't familiar with email's many acronyms?
DMARC means: http://en.wikipedia.org/wiki/DMARC
And the person below you doesn't understand how search engines work.
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#24Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#25And than the police shut down the ransomware servers and dooms data from many infected victims to garbage, brilliant!
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#26Earlier quoted context omitted.
I then turned on DKIM and enabled quarantining non DKIM emails via DMARC. Translation for techies who aren't familiar with email's many acronyms?
All those acronyms are easily googleable. Not being a techie does not mean you get to be lazy about looking things up.
Also, experts often have insights that introductory articles lack. Better to ask the source if they don't mind composing.
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#27Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#28Are there any recommendations of a simple way to at least enable automated backups of local documents to the cloud on a windows box?
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#29The only new thing about this ransomware is that the payment method is through Bitcoin, right?
1. Educating users to stop running random programs in zip files attached to emails, is apparently impossible. Maybe email-clients should scan the contents of any zipfile it receives and if it finds any kind of executable, put up all kinds of warning dialogs saying "You really don't want to run this. There's no reason to get a program in zipped email attachment nowadays. Please go consult your IT-admin or somebody who knows about computers for a 2nd-opinion"
Re: You’re infected—if you want to see your data again, pay us $300 in Bitcoins
#30You can work to prevent this by creating a group policy that disallows %AppData%\*.exe and %AppData%\*\*.exe A good discussion of this happened here: http://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care... sidenote: this virus actually scares me, and it sounds like it actually scares most people who work in IT. This is the shittiest thing anybody has ever seen, it sounds like.
Edit: It's the BTC aspect that's worrisome. Ransomeware is nothing new -- AIDS Information Trojan did it in 1989, but the (potentially) safe method of payments in crypto currency seem to be a new factor that will attract much more innovation in these type of attacks.