11% increase in ransomware within a year

https://securelist.com/ksn-report-ransomware-in-2016-2017/78824/

My only surprise would be ‘only an 11% increase’ in a year. It seems to have been massive recently.

Not if you used Avast:
https://blog.avast.com/avast-and-avg-only-free-antivirus-score-100-av-comparatives-real-world-test

Doesn’t matter what you use(d), there still is a 11% increase in (new) ransomware.
It is not about how many things are blocked, but detected.

Massive Petya Ransomware Attack (GoldenEye)

http://screencast-o-matic.com/screenshots/u/Lh/1498589006645-46653.png

More information here and here

Hi bob3160,

Breaking news here indeed, at a grand scale.

Well someone should finally uphold the American constitution against these NSA spooks, thinking they are above the law, letting this out into cyberspace, now causing global havoc & damage through their EternalBlue zero-day proliferation, also giving Microsoft a bad name. Ransomeware-worms in the making and causing havoc around the globe.

Globally firms are devastated by Peyta in Ukraine and in Russia and now also in the port of Rotterdam, the Netherlands, e.g. Maersk Logistics, http://www.apmterminals.com/500.html?aspxerrorpath=/ → https://asafaweb.com/Scan?Url=www.apmterminals.com%2F500.html%3Faspxerrorpath%3D Read: http://www.nnit.com/OfferingsAndArticles/Pages/COWI-Upgrades-its-IT-Security.aspx (there were threats from cybercriminals). See also: http://toolbar.netcraft.com/site_report?url=http%3A%2F%2Fwww.apmterminals.com%2F500.html%3Faspxerrorpath%3D%2F

The malware, what they now think is a worm, spreading like wildfire, encrypts the MFT on the hard disk (master file table).

CERT’s in all sort of countries now up in arms. Victims have no more than 30 minutes to take their systems off of the grid and shut them down. Thank you, foks, for making this crap possible (ironic mode on).

polonus

P.S. Great avast is out in the trenches against this, keeping a finger on the pulse through the Wifi-Inspector. 39 million servers vulnerable and haven’t been patched. Read: https://blog.avast.com/petya-based-ransomware-using-eternalblue-to-infect-computers-around-the-world

Damian

Local Killswitch for Peyta.

Seems there is a killswitch now, creating c:\windows\perfc as the ransomeware checks that file and then stops.
Info credits: Amit Serper. AppLocker-feature to block the execution of “perfc.dat” should also do the trick according to Kaspersky Lab’s.

pol

P.S. For what it is worth: https://www.bleepingcomputer.com/news/security/petya-ransomwares-encryption-defeated-and-password-generator-released/

https://blog.kaspersky.com/new-ransomware-epidemics/17314/
https://securelist.com/schroedingers-petya/78870/

Vaccine, not Killswitch, Found for Petya (NotPetya) Ransomware Outbreak
https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/

Microsoft Security Advisory 4033453
Vulnerability in Azure AD Connect Could Allow Elevation of Privilege
https://technet.microsoft.com/library/security/4033453.aspx

SLocker Mobile Ransomware Starts Mimicking WannaCry
https://blog.trendmicro.com/trendlabs-security-intelligence/slocker-mobile-ransomware-starts-mimicking-wannacry/

New Azer CryptoMix Ransomware Variant Released
https://www.bleepingcomputer.com/news/security/new-azer-cryptomix-ransomware-variant-released/
V.T-https://www.virustotal.com/en/file/6f5f3bd509c22f0aec4a55fd4d08b7527be4708145b760bc3bd955c6e7538064/analysis/

Decryptor Released for the Mole02 CryptoMix Ransomware Variant
https://www.bleepingcomputer.com/news/security/decryptor-released-for-the-mole02-cryptomix-ransomware-variant/

New BTCWare Ransomware Decrypter Released for the Master Variant
https://www.bleepingcomputer.com/news/security/new-btcware-ransomware-decrypter-released-for-the-master-variant/

https://security.googleblog.com/2016/10/distrusting-wosign-and-startcom.html

While not sticking to the rules, these certifiers have endangered website visitors and are not trusted any longer by Google.

Background read: https://www.lowendtalk.com/discussion/95618/google-chrome-distrusting-wosign-and-startcom-certificates

Comics can tell more than a thousand words: -http://dilbert.com/search_results?terms=Vast+Power+Of+Certification

pol

Most providers and CDNs in cahoots with Big GubbermentRead: https://www.eff.org/who-has-your-back-2017

This not about protecting your personal data through security technology, best practices etc, this just touches transparency,
policy towards end-users, Amazon and Whatsapp has a bad reputation for the total lack of protecting your data against snoopers.

Adobe, Amazon, Apple, Facebook, Google, LinkedIn, Microsoft, T-Mobile, Twitter, WhatsApp, WordPress en Yahoo. Providers Verizon, T-Mobile, Comcast en AT&T just scored one star in protecting your data from Government requests.

polonus

Big Campaign in USA for Netneutrality:

https://www.battleforthenet.com/july12/

polonus

Knowing the political climate here in the good ol’ U.S. of A. this looks like a losing cause. :cry:
We can always hope. :wink:

Data of 14 Million Verizon Customers Exposed in Server Snafu

https://www.bleepingcomputer.com/news/security/data-of-14-million-verizon-customers-exposed-in-server-snafu/

Don’t Open SPAM Containing Password Protected Word Docs
(Should be obvious at this point.)

https://www.bleepingcomputer.com/news/security/psa-dont-open-spam-containing-password-protected-word-docs/