Skip to main content

Posts

Showing posts with the label ransomware

Preventie van ransomware

Preventie van ransomware This blog post will be fully in Dutch. If youd like to read English material, be sure to check out my Q&A on ransomware. A translation will also be available in one of the next days. Ransomware heeft in principe geen introductie meer nodig, maar kortgezegd zal deze specifieke soort malware (bijna) al je bestanden encrypteren en een bepaald bedrag vragen (tegenwoordig vaak in Bitcoin) om terug toegang tot al je bestanden te verkrijgen. Andere benamingen: CryptoLocker, cryptoware, encrypting ransomware. Deze blog post is opgesplitst in twee luiken: 1 voor thuisgebruikers, 1 voor bedrijven. De meeste tips zijn echter ook uitwisselbaar en kunnen naar believen worden toegepast. Tot slot worden ook enkele tools ter beschikking gesteld als aanvulling alsook extra resources. Thuisgebruikers Gebruik, afhankelijk van de mailclient, een degelijke anti-spam filter. In zo goed als alle online diensten (bv. Outlook.com, Gmail, ...) wordt deze reeds standaard aangeboden. ...

Ransomware fala sério!

Ransomware fala sério! Recently, a user contacted me in regards to what looks like a new, Brazilian ransomware. In this blog post, were taking a quick look at the ransom and how to unlock or decrypt your files. TL;DR : to unlock your files, you can use the key or password: 123 Para desbloquear seus arquivos, voc� pode usar a chave ou a senha: 123 The title of this blog loosely translates to: ransomware, no way! (excuse my Portuguese) The ransomware appears to call itself Sem Solu��o; which translates to Hopeless or No Solution. I propose we call it Hopeless ransomware: Figure 1 - Seus arquivos foram criptografados Sua ID N�o a formas de recuperar sem comprar a senha, ser tenta eu apago tudo! O m�todo de pagamento � via Bitcoins.  O pre�o �: 600,00 REAIS =  Bitcoins N�o tem Bitcoins?, pesquise no google e aprenda comprar ou clique em Compra Bitcoins envie os bitcoins para: 1LULpQbdvoAWqKzhe8fuMiPQ8iGdW36pk1 Para receber a senha, voce precisa criar uma e-mail em https://mail.pro...

The purpose of ransomware

The purpose of ransomware Ransomware, a phenomenon now very well known, serves one ultimate and obvious purpose: Monetary gain for the cybercriminal(s). However, multiple scenarios are, in fact, possible. Consider any and all of the following: Deployed as ransomware, extortion; Deployed as smokescreen; Deployed to cause frustration; Deployed out of frustration; Deployed as a cover-up; Deployed as a penetration test or user awareness training; Deployed as a means of disruption and/or destruction. Lets go over all of these briefly: Deployed as ransomware, extortion This has been the traditional approach - ransomware is installed on the victims machine, and its only purpose is to create income for the cybercriminal(s). In fact, ransomware is simple extortion, but via digital means. I could give 100s, if not 1000s of links as example, but this search query should suffice and show the current boom or trend in the cybercriminal landscape: https://www.bleepingcomputer.com/search/?q=ransomware...

Ransomware prevention

Ransomware prevention Very short blog post to let you know I now also have an English version of my article preventie van ransomware, on how to prevent ransomware. You can find it as a page (see top of my blog) or here: Ransomware Prevention Translations are available in Dutch (Nederlands) and French (fran�ais). Thanks to @WawaSeb for the French translation. If you would like to translate this page in your own language, feel free to do so and send me the link so it can be added. download  file  now

Ransomware Baru GoldenEye Petya Ransomeware Evolusi WannaCry

Ransomware Baru GoldenEye Petya Ransomeware Evolusi WannaCry Virus ransomware kembali menyerang komputer-komputer di seluruh dunia pada Selasa (27/6). Serangan ini berhasil mengambil alih server di perusahaan minyak terbesar Rusia, mengganggu operasional bank-bank di Ukraina, serta mematikan komputer di perusahaan perkapalan dan periklanan multinasional. Pakar keamanan siber mengatakan serangan tersebut tampaknya menggunakan sejenis alat peretas yang sama yang digunakan dalam serangan ransomware WannaCry. "Ini seperti WannaCry lagi," kata Mikko Hypponen, kepala peneliti firma keamanan siber F-Secure yang berbasis di Helsinki, dilansir dari Reuters, Rabu (28/6) Ransomware WannaCry pada bulan Mei 2017 lalu menggegerkan dunia karena telah menginfeksi ratusan ribu komputer, sebelum seorang peneliti Inggris membuat sebuah kill-switch. Hypponen memperkirakan virus tersebut bisa menyebar di Amerika saat para pekerja menghidupkan mesin yang rentan, yang memungkinkan virus tersebut me...