Ransomware, Extortionware, Malvertising Exploit Defensive Measures

zapp22

New member
Power User
VIP
Local time
2:49 AM
Messages
730
Location
Tejas, northern Mexico
I have not seen a persistent thread on this most important topic so wanted to begin.

Anyone that spends even a little time keeping up with IT Security knows how ugly this new world of Organized CyberCrime can be. Not only is invasive web-extortion becoming common, but the new battlefield has professional white hats reeling. IT bosses have few answers to their bosses and cients.
With ransomware on the rise, cryptographers take it personally | InfoWorld

Growth in extortion malware continues, finds F-Secure report - SC Magazine UK

Millions of WordPress sites at risk of hijack after zero-day released | ZDNet

https://threatpost.com/bypassing-os-x-security-tools-is-trivial-researcher-says/112410


Increasingly, victims are finding it more palatable to pay the Extortion Fee than to vainly hunt for affordable remedies, post-crime. That constitutes blood-in-the-water for the well-heeled cybercrime syndicates. Current $$ ransoms being paid range from mid-hundreds to several thousand $$$USD. Tragically, the price can also be "priceless" : Police ransomware scam drives UK teen to suicide

Those who make it our business to try to help people with IT issues hear the common question: "Is there ANY way to keep myself safe onine...?", and the only honest answer is "No - not safe, but yes a little less vulnerable". Situation depending, what ensues is a long difficult conversation to determine: "how hard are you willing to work to gain incremental, but breachable, defense?"

Please, you who are in the thick of the battle, post here your best resources, links, forums, alert mechanisms, twitter feeds, etc so that at the least, we who need to stay on top of the issue have more tools to work with. Part of the equation is for those who will to build a "rapid alert & response" methodology.
 

My Computer

Computer Manufacturer/Model Number
HP DC7600, HP DC7600[2], HP DC7100, Samsung NC10
OS
Windows XP Pro SP3, Windows 7 Pro 32-bit, Windows 7 Ultimate 64bit, Windows XP Home SP3
CPU
Pentium 4 3.2GHz, Pentium 4 3.4GHz 64bit, Atom,
Motherboard
Dunno
Memory
4GB matched, 1GB, 2.5GB, 4.0 GB
Graphics Card(s)
Geforce 8400 GS and others
Sound Card
RealteK ALC260 and others
Monitor(s) Displays
Asus HD
Screen Resolution
1920x1080
Hard Drives
WD Caviar 640gb SATA
Cooling
We Be Cool
Generally speaking, according to some sources -- a well-balanced, well-configured, well-maintained, multi-layered defense is best. I add: "battleship" or "carrier" booting [set up via bcdedit & msconfig] helps alert me very early if something has changed, ie, session looks & feels different from the norm. Firewall, anti-virus [1 w/real time shields; both w/non-overlapping scheduled scans]; anti-spyware, anti-malware [real time shields & scheduled scans]; a couple of systems & environs monitoring programs; bi-monthly OS & data partition backup onto external media; several rescue usb sticks & DVDs; safe & sane browsing; extra cooling fans; UPS -- all of which make computer usage by wifey and I, not iron-clad, rather a healthy balance of functionality [what we want to do with computer] and security.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Antec desktop; Acer Aspire laptops
OS
Windows 7 Professional 64-bit
CPU
Desktop i5; Acers i5 & i7
Memory
desktop 16GB; 1 Acer 8GB & 1 Acer 16GB
Hard Drives
1TB split into 2 equal partitions [OS and data] usable by RJS
Internet Speed
AT&T DSL
Browser
FF, GChrome, msIE
Other Info
Windows 7 Firewall, Emsisoft AM/AV, MSE [scan-only], SpywareBlaster, Ruiware/BillP combine

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
exactly what we need in this thread, Jacee.
i'm sending that one to my IT buddies.
A friend in the trade that has a multimillion$$ budget got hit several ways in recent months, one attack of which took an appliance and loaded a different FIRMWARE on the system, which rendered all the automated snapshots/backups of the data neuter. no recovery. it became a pawn/slave
in another instance more recent, workstation in the domain was simply used for ordinary browser work and was Ransomware-attacked, leaving all the local files locked with no decryption possible. fortunately, that one had a backup that could be immediately deployed so the loss was negligible in relation to the scope of this shop. an interesting feature was that every attached device for which the user had authentication was also encrypted.

Cloud-reliant backups are not safe. basically when the credentials are overcome, the sync'd/sync'ing resources become the property of the Criminal.

What's in your Twitter Following folder? Mine in no particular order:
- Threatpost
- Krebs
- Malwarebytes unpacked blog
- Andy Greenberg
- @kaspersky
 

My Computer

Computer Manufacturer/Model Number
HP DC7600, HP DC7600[2], HP DC7100, Samsung NC10
OS
Windows XP Pro SP3, Windows 7 Pro 32-bit, Windows 7 Ultimate 64bit, Windows XP Home SP3
CPU
Pentium 4 3.2GHz, Pentium 4 3.4GHz 64bit, Atom,
Motherboard
Dunno
Memory
4GB matched, 1GB, 2.5GB, 4.0 GB
Graphics Card(s)
Geforce 8400 GS and others
Sound Card
RealteK ALC260 and others
Monitor(s) Displays
Asus HD
Screen Resolution
1920x1080
Hard Drives
WD Caviar 640gb SATA
Cooling
We Be Cool
Does a garden-variety "AV" package protect against such? NO.
Well-meaning advisors will tell users: "just don't do anything dumb on the web and you'll avoid infection. Don't do this, don't go there".... Ever bumped into Doubleclick on the web? YES you have... every stinking day. Ever visit a website for news, or tech news, or tech support? You're exposed.

https://blog.malwarebytes.org/malve...l-time-bidding-and-malvertising-a-case-study/

Faked Flash-based ads on HuffPo, other sites downloaded extortionware | Ars Technica

Flash EK leveraged in potentially widespread malvertising attack - SC Magazine

IT friends: arrogance is not an effective defensive policy.
 

My Computer

Computer Manufacturer/Model Number
HP DC7600, HP DC7600[2], HP DC7100, Samsung NC10
OS
Windows XP Pro SP3, Windows 7 Pro 32-bit, Windows 7 Ultimate 64bit, Windows XP Home SP3
CPU
Pentium 4 3.2GHz, Pentium 4 3.4GHz 64bit, Atom,
Motherboard
Dunno
Memory
4GB matched, 1GB, 2.5GB, 4.0 GB
Graphics Card(s)
Geforce 8400 GS and others
Sound Card
RealteK ALC260 and others
Monitor(s) Displays
Asus HD
Screen Resolution
1920x1080
Hard Drives
WD Caviar 640gb SATA
Cooling
We Be Cool

Attachments

  • spywBlaster.jpg
    spywBlaster.jpg
    70.8 KB · Views: 0

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top