MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 17 posts ] 
Author Message
 Post subject: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 9th, 2014, 11:01 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
Hi Gurus!

Are you see any similar case.
I have here a drive that have been hacked by malware similar to CryptoBit.
Malware has deleted all important info from Drive and created a file called "BACKUP" 40GBs.
Virus has created a File into destop folders too that says:



Hello,
I crypted all your important data
I stored the crypted data in your hard disk.
If you want to become your data back, send me an email containing your ip adress.
Your ip xxx.xxx.xxx.xxx
e-mail : serverlock@yandex.com


Have you see this problem?
any way to resolve it?


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 9th, 2014, 11:25 
Offline

Joined: August 5th, 2014, 16:46
Posts: 55
Location: Slovakia
imagine that you have dynamic IP .... not very smart malware :?


EDIT: Oh I am idiot i just saw it saves current IP :lol:


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 9th, 2014, 11:29 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
No, not very smart you are on true

but big problem


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 9th, 2014, 11:33 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
i atach an extract about 7mb form 40GB BACKUP crypted file.


Attachments:
TestBACKUP1.rar [6.76 MiB]
Downloaded 481 times
Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 9th, 2014, 12:27 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2821
Location: Kuwait
This is the new Generation of viruses/malware

(ctb-locker)

Still new, no cure

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 9th, 2014, 12:37 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2821
Location: Kuwait
Forgot to mention that this new malware uses TOR network communication
which makes it DIFFICULT to trace not like the other OLDER Bitcoin Locker

so for everybody, Monitor your TOR network activity.

good luck

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 10th, 2014, 3:47 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
woult you pay extortion?

you think malwareboy will restore crypted info?


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 10th, 2014, 9:45 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
Have not dealt with that version... yet. Did you try SHADOWEXPLORER? Some of the latest crypto viruses have not eliminated the shadow copies.


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 10th, 2014, 10:08 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
is win2003 no shadow avaliable


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 10th, 2014, 11:19 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3903
Location: Adelaide, Australia
How much is the extortion?
Depending on the value of data, and problems it causes for the length of time there is n o solution.. maybe some would pay it for the chance of the criminals decrypting.

But there are less malware groups actually decrypting or sending key because it is more contact (unnecessary for them) to get tracked.

Not enough is being done about this. But on the same token, what CAN be done about it? The current internet ecology favours them. We cant even shut down a C&C Server if we find it because it could easily be the local MRI XP PC at a hospital, as it could be in some scumbags basement.


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 10th, 2014, 12:22 
Offline

Joined: December 5th, 2011, 5:38
Posts: 1740
Location: Verona, Italy
I hate those hackers bastards :evil:

_________________
My firmware database:
https://mega.nz/folder/O01DkBRI


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 11th, 2014, 11:30 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
HaQue wrote:
How much is the extortion?


Extorsión is about 3000 sur

I think cstoer will acccet the extorsión


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 11th, 2014, 11:49 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
since they copied it to a new folder any chance at all deleted copies recoverable on this version of malware?


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 11th, 2014, 11:55 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 811
Location: World
Look like secure deletion of files after cryt data


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 11th, 2014, 16:37 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
Brutal!!! They are getting better and better. Hopefully client can be patient until this version is solved. Paying a crook is certain to cause this type of crime to grow and to be discouraged.


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 11th, 2014, 21:14 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 16955
Location: Australia
Would this be a job for the NSA? :P Imagine the public relations coup if they could actually do something useful and catch a real criminal instead of spying on Faecebook traffic.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Virus Encrypt all your data into a BACKUP caled file
PostPosted: October 11th, 2014, 22:21 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3903
Location: Adelaide, Australia
I am thinking We need an elite taskforce. Make a Lair somewhere 2Km deep under the Utah Data Center ( http://en.wikipedia.org/wiki/Utah_Data_Center ) so they can run a huge pipe up to evry living souls DATA. them make a Crack team with Super Hero outfits that make Thunderbirds, X-Men or Batman envious, with members like:

Brian Krebs http://krebsonsecurity.com/ Seek and Identify
Ugene Kaspersky http://www.kaspersky.com/about/management_team Analysis and captivating scary superhero vocals
H.D. Moore - https://twitter.com/hdmoore - mass scanning and categorisation
Greg Hoglund - http://en.wikipedia.org/wiki/Greg_Hoglund - Ninja coding, Reverse Engineering, techspertise
Mikko Hypponen - http://mikko.hypponen.com/ - Experince, Coding, Public relations
Ed Skoudis - http://www.sans.org/instructors/ed-skoudis - Malware System Defense, Reverse Engineering
Lenny Zeltser - http://zeltser.com/ - Reverse engineering, cool hackery tricks
th3j35t3r (The Jester) - http://jesterscourt.cc/ - SecOps (for now) and Media Releases
Bill Gates - http://www.microsoft.co - Evil Genius type leather chair, speakerphone boss/ cashflow
Jason Bourne.. yes I know he aint real, but we need someone to actually take these slimeballs out IRL


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 17 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 35 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group