Ransomware එකක් ආවා කියපන්කෝ...

supunt21

Active member
  • Jun 8, 2014
    588
    91
    28
    31
    Ganemulla
    Ransomware එකක් ආවා කියපන්කෝ...

    අද අපේ ඔෆිස් එකේ ගොඩාක්ම mail වැඩකරන මැශින් එකට ransomware virus එකක් ආවා කියපන්කො...
    :shocked::shocked::shocked:
    මෙහෙම එකක් දැක්කමයි... තිබුනimage file සේරම encrypt වෙලා...
    :no::no::no::no::no:
    ඒ අස්සෙ තිබුනා text ඩොකියුමන්ට් එකක්...

    syasck.png


    මම ගියා tor browser එකෙන් මේ ලින්ක් වලට.
    rk9clt.png


    334sz2d.png


    මුන්ට සල්ලි ගෙවන්න ඕනේ බන් file decrypt කර ගන්න... ඔෆිස් එකේ දාලා තියෙන්නෙ kaspersky. ඒකෙන් ඇල්ලුවෙත් නෑ බන්.
    :(:(:(
    ටිකක් හොයලා බැලුව බන් මේ ගැන... word වගේ document වලින්ලු මේවා එවන්නෙ... තවම මේකට හරියන විසඳුමක් නම් හොයාගෙන නෑ වගෙ බන්... දන්න එකක් ඉන්නවනම් තව විස්තර කරපන්කො මේ ගැන... මේ වගේ දෙයක් වෙන්න කලින් නවත්ත ගන්න පුලුවන්ද? මෙහෙම දෙයක් උනොත් අපි මොකද කරන්න ඕනේ?
     

    Dinuka44

    Well-known member
  • Apr 8, 2008
    1,141
    47
    48
    Duka tama bro.. ape office ekatath awa, machines 2kata infect una user apu mail eka extract karala exe erka run karala, okkama docs iwarai computers 2ma,, recover karanna baha ayeth,user ta hitha hada ganna kiyanna, nothing to do.. api macafee use karanne.
     

    dath kimbula

    Well-known member
  • Jan 17, 2011
    35,838
    3,595
    113
    මහපොලව.....
    අදෝ සසරක් නොදනිමි....
    මට ඔය වගේ වුනොත් නැට්ට-සොරි බාව *කේ ගහං, *ක හපං මැරෙන්න වෙන්නේ....

    එනිසා බම්ප් කරමි..
    බම්ප් වේවා!!!
     

    Dinuka44

    Well-known member
  • Apr 8, 2008
    1,141
    47
    48
    This is the answer from, macafee support,

    Issue : "Cryptolocker Ransomware".

    We constantly try to make sure that our DATs have the latest definitions to make sure we have full coverage, but there are times when a new variant is released and we do not have the signature for that in artemis as well.

    At this juncture, I would recommend applying the access protection rule from the following document, if they have not been setup as yet:
    https://kc.mcafee.com/corporate/index?page=content&id=PD25203

    I would also recommend putting in a user defined access protection rule as per the following parameters to see which process is creating that file:

    File/Folder blocking rule

    Name of Rule:malware create block

    Processes to include: *

    Processes to exclude: leave blank

    File name to block:**\*.vvv(where vvv is the extension of the encrypted files)

    Action to block:Create, Write.

    I would also recommend setting up a block for the following Rule:

    Access Protection->Anti Virus Maxiumum Protection->prevent svchost from running non-windows executables.

    Please duplicate the current access protection policy, add these rules and assign to all machines.

    Please review the access protection log to determine which process is creating this file.

    If it is svchost, then a procmon capture during the file encryption will help us identify the offending dll.

    In addition to that, is there a chance you could submit the file as a sample to us based on the instructions in the following KB?:
    https://kc.mcafee.com/corporate/index?page=content&id=KB68030

    Once done, you will receive an analysis ID.

    Please share that with me for faster processing.

    I would also recommend scanning the source machine with the following tool and submitting the collected samples to us:
    www.mcafee.com/in/downloads/free-tools/getsusp.aspx

    Regarding the recovery of the files, please accept my apologies, but that will not be possible.

    The files were encrypted with 256 bit AES encryption which is unbreakable.

    Also the key to decrypt the files itself is encrypted with 2048 bit RSA encryption, which again, is uncrackable.

    I would recommend deleting the files to save disk space and if you have a backup available, restore them from there.

    I would also recommend advising the firewall team to block the domain name and originating IP of the link that was clicked by the user.

    I would recommend leveraging Host IPS to prevent the modification of the important files in your environment.

    Regarding the detections you are seeing, these are in all probability ransomware remnants, typically the png, txt and html files left behind with instructions to pay the malware author.

    Host IPS can be used to control how files with different extensions may be modified and used.For more information on Host IPS, please refer to the videos below and the documents attached:

    https://kc.mcafee.com/corporate/index?page=content&id=PD25203, page 3 and 4.

    https://www.youtube.com/watch?v=_R8M-OmMBBI

    https://www.youtube.com/watch?v=q_fgPbXZOBM

    https://www.youtube.com/watch?v=_TsPhtFa7AM

    We look forward to your reply.

    Best Regards,
    Kranthi Kiran M
    Support Engineer
    Intel Security Business Support
    How am I doing today? Share your feedback with my manager at [email protected].
    Kindly reply to all while responding at this communication
     
    • Like
    Reactions: supunt21

    dinchad

    Well-known member
  • Jul 31, 2007
    6,974
    643
    113
    අප්පට සිරි මචන් මට ඔහොම කේස් වෙලා මමත් හෙව්වා බන් හම්බුනේ නෑ සොලූශන් එකක් මට නම් උනේ උන් ඔක්කොම ෆ්යිල් බැක් අප් ෆ්යිල් කරලා .ඒක අපහු ඩික්‍රිප්ට් කරන්න උන්ට ගෙවන්න ඕනිලු.ඒකත් උන් දෙන දවස් ටික ඇතුලෙ කරන්න ඕනි නැත්තන් ආපහු මුකුත් කරන්න බෑ .මගේ තිබ්බ එකේ නම් මේල්ස් තමා තිබ්බෙ ඒක හින්දා අවුලක් උනේ නෑ ආපහු ඕස් එක දැම්මා .
    ඕකට විසදුමක් නම් හම්බුනේ නෑ මචන්
    :(:(:(:(:(
     
    Last edited:
    • Like
    Reactions: supunt21

    supun_sg

    Well-known member
  • Sep 5, 2010
    16,170
    24,809
    113
    tracing Geo-location.. ... ...
    ඕක ගැන අහල තිබ්බා.. එත් දැක්කමයි වෙච්චි එකෙක්.. මම කියන්නේ ලංකාවේ.. ඕක word file එකක් open කරපු ගමන් ගිය එකක් ද නැත්නම් exe, bat වගේ එකක් run කරලා, run වෙලා ද? බයේ බෑ බන්.. machine එකේ තියන ඔක්කොම ෆයිල් ඕනි බන්.. මේකෙන් බේරෙන්න විදියක් දන්නවා නම් කියපල්ලකෝ.. මේකේ hacking ගැන එහෙම දන්නා උන් ඉන්නවනේ.. මේ වගේ එකකින් බේරෙන්න අපි මොනාද කරන්න ඕනි?
     

    ramitha1987

    Active member
  • Jun 11, 2007
    462
    77
    28
    file restore karanna try ekak denna puluwan.. meka remove karanna baha lesiyen...

    Symantec might have some answers..

    only way to prevent is backing up your files frequently..
     
    • Like
    Reactions: supunt21

    ctooi

    Banned
  • Jul 19, 2008
    7,280
    498
    83
    මකබාවේ
    Cryptolocker nam sorry thama. Key eka ganna pay karanna wenna a. Wena podi ewun hadapu ransoware wala encryption awul thiyenawa nam file recover karanna tool ekak hadala thibuna kaspersky hari sophos eken hari.

    :yes::yes: KIS eka galavagena yanava oya vage virus valata, ESET and Avira Free thamayi Hoda
     

    zCexVe

    Active member
  • Sep 12, 2006
    8,550
    22
    38
    Where I'm now
    hitman pro dala oka ayin kranna. Ube file ovayin encrypt karanna 1 hour valin bae. Oya RSA-2048 valin encrypt karanava nam PC eka slow vela thiyenava godak vela hehe..Echcharata resource oni. Salli gevanna ehema oni nae.

    Remove ransomware with hitman pro kiyala google karala oka fix kara ganna.
    eta passe combofix hari MBAM hari duvala root kit check karanna. root kit ekka hariyata remove karanna bari nam aniva ai OS eka danna.
     
    • Like
    Reactions: supunt21