Pages:
Author

Topic: Bitcoin ransomware covered by CCTV (Read 1478 times)

sr. member
Activity: 462
Merit: 250
May 15, 2015, 02:03:45 AM
#28
Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?


Much viruses and malware need the user of the computer, aka victim, to run an unsuspected file to be infected. Email is only one of the main source of these malwares. Others ways include plugging in a usb flash disks, downloading and viewing a pdf document.

PDF documents?
How does that work?
I have never heard of that before.
This is the first time I heard that.

Check out this link from malwarebytes: https://blog.malwarebytes.org/intelligence/2013/08/the-malware-archives-pdf-files/

and from AppleInsider about Macs:

http://appleinsider.com/articles/11/09/23/researchers_discover_pdf_malware_that_targets_apples_mac_os_x

Thanks for the links.
I doubt that I would ever go through that process, so I have just downloaded Malwarebytes  Cheesy
full member
Activity: 219
Merit: 100
May 15, 2015, 01:32:59 AM
#27
Mining gets less profitable they will do anything for there BTC
full member
Activity: 350
Merit: 118
May 15, 2015, 01:23:36 AM
#26
lol i can't translate those text in the image, is there any text version available?  Roll Eyes

Try this.

Strange. That link just takes me to a login page in Chinese...

Do not use proxy. Proxies are being re-directed to login. This is the link...

http://weibo.com/3552119670/Cg6HS4D9W

...and here is the translation...

Quote
@ CCTV News
[Mo open strange e-mail in English spread! ] New Trojan virus struck, the most vulnerable foreign workers caught! It is spread through corporate and personal mail, e-mail in English, the Trojans were generally means "order" "Product Details" and so on, can be deceptive. Once caught, the computer 114 kinds of file formats will all be the Trojan encrypted and can not be opened. Want to restore a file, the only way is to pay a ransom to the Bitcoin Trojan author. (CCTV reporter Sun Yang)

I wasn't using a proxy. I think there might be some sort of geographical restriction which is redirecting non-Chinese IPs to a login page.

This is the page I get:

http://www.weibo.com/login.php

Anyway, thanks for the translation. It sounds like a variant of the CryptoLocker virus.

So if I understand correctly, a user needs to run this file first?
Which is sent to them via email?

If it's anything like the CryptoLocker trojan, then yes, it would need to be run.

Another ransomware case, are antiviruses able to identify it still or not? I think it's designed for windows only right? Or can it spread in Linux and Mac too?

Again, I'm only familiar with CryptoLocker but if it's anything similar then it should be Windows-specific. Malware which can infect OS X and Linux are quite rare.

It's going to be difficult to stop Ransomware. Once the Trojan is triggered all files targeted will be encrypted and then you are stuffed.

Without the key, your files are gone...

The only way to reduce the damage, will be to do regular offline backups. If you are hit, you could just restore the files and only lose the files that was not being backed up.

Most office workers do not make backups regularly.  Sad 

Businesses will probably start forcing backups soon if they haven't already been doing so. If everyone had backups, these ransom hackers would be out of business.

to be honest backup should be mandatory regardless of virus or other things, what if your hdd fail or other random crap like that? i've always an entire backup of my ssd in a usb pen drive

in this situation the victim could have just restored everything in no time without paying that crazy amount

It's also recommended to have backups of your backups.

And even that isn't necessarily going to be 100% successful. Stefan Thomas who is a Bitcoin core developer once lost a substantial amount of BTC because both his backups managed to fail simultaneously:

Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?


Much viruses and malware need the user of the computer, aka victim, to run an unsuspected file to be infected. Email is only one of the main source of these malwares. Others ways include plugging in a usb flash disks, downloading and viewing a pdf document.

PDF documents?
How does that work?
I have never heard of that before.
This is the first time I heard that.



There is a way called extension spoofing. Using the appropriate tool anyone can do it and it can be used to trick users download and run malicious files as well as files with malicious code attached to them. You can use extension spoofing on a huge variety of extensions but besides PDF is an especially vulnerable extension.

Basically this is correct. The Wikipedia article goes into more detail about the issue with extensions:

Quote from: Wikipedia
CryptoLocker typically propagated as an attachment to a seemingly innocuous e-mail message, which appears to have been sent by a legitimate company. A ZIP file attached to an email message contains an executable file with the filename and the icon disguised as a PDF file, taking advantage of Windows' default behaviour of hiding the extension from file names to disguise the real .EXE extension. CryptoLocker was also propagated using the Gameover ZeuS trojan and botnet.

Not to mention Acrobat Reader can also have vulnerabilities of its own which can be exploited if left unpatched:

http://www.cvedetails.com/vulnerability-list/vendor_id-53/product_id-497/Adobe-Acrobat-Reader.html
hero member
Activity: 1204
Merit: 531
Metaverse 👾 Cyberweapons
May 04, 2015, 01:33:26 PM
#25
Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?


Much viruses and malware need the user of the computer, aka victim, to run an unsuspected file to be infected. Email is only one of the main source of these malwares. Others ways include plugging in a usb flash disks, downloading and viewing a pdf document.

PDF documents?
How does that work?
I have never heard of that before.
This is the first time I heard that.



There is a way called extension spoofing. Using the appropriate tool anyone can do it and it can be used to trick users download and run malicious files as well as files with malicious code attached to them. You can use extension spoofing on a huge variety of extensions but besides PDF is an especially vulnerable extension.
hero member
Activity: 504
Merit: 500
May 04, 2015, 10:53:27 AM
#24
Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?


Much viruses and malware need the user of the computer, aka victim, to run an unsuspected file to be infected. Email is only one of the main source of these malwares. Others ways include plugging in a usb flash disks, downloading and viewing a pdf document.

PDF documents?
How does that work?
I have never heard of that before.
This is the first time I heard that.

Check out this link from malwarebytes: https://blog.malwarebytes.org/intelligence/2013/08/the-malware-archives-pdf-files/

and from AppleInsider about Macs:

http://appleinsider.com/articles/11/09/23/researchers_discover_pdf_malware_that_targets_apples_mac_os_x
sr. member
Activity: 462
Merit: 250
May 04, 2015, 02:01:46 AM
#23
Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?


Much viruses and malware need the user of the computer, aka victim, to run an unsuspected file to be infected. Email is only one of the main source of these malwares. Others ways include plugging in a usb flash disks, downloading and viewing a pdf document.

PDF documents?
How does that work?
I have never heard of that before.
This is the first time I heard that.

legendary
Activity: 1621
Merit: 1000
news.8btc.com
May 03, 2015, 11:12:28 PM
#22
The weibo has been reposted over 2000 times

And on TV
hero member
Activity: 1204
Merit: 531
Metaverse 👾 Cyberweapons
May 03, 2015, 05:26:13 PM
#21
It's important to save backup frequently. These days there are many easy to use and reliable cloud based and physical storage to store your data so in most cases it's up to you to take care of it.

Many of the ransomware cases were done with insider help. Profit is shared half half with the Russian coder.

This. Someone had been infected with a ransomware that detected the user's nation and asked for ransom in his language and in BTC. It even offered an exchange service to use to convert the national currency into BTC lol This person had important files on his HDD so he decided to pay the ransom in the way the program asked for it and in the end his computer got unlocked.
hero member
Activity: 672
Merit: 500
May 03, 2015, 04:46:13 PM
#20
Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?


Much viruses and malware need the user of the computer, aka victim, to run an unsuspected file to be infected. Email is only one of the main source of these malwares. Others ways include plugging in a usb flash disks, downloading and viewing a pdf document.
sr. member
Activity: 462
Merit: 250
May 03, 2015, 12:37:39 PM
#19
Guys, nobody has answered my question so far:

This trojan has to be ran by the victim right?
And it's send through email?
hero member
Activity: 504
Merit: 500
May 03, 2015, 10:52:07 AM
#18
It's going to be difficult to stop Ransomware. Once the Trojan is triggered all files targeted will be encrypted and then you are stuffed.

Without the key, your files are gone...

The only way to reduce the damage, will be to do regular offline backups. If you are hit, you could just restore the files and only lose the files that was not being backed up.

Most office workers do not make backups regularly.  Sad  

Businesses will probably start forcing backups soon if they haven't already been doing so. If everyone had backups, these ransom hackers would be out of business.

to be honest backup should be mandatory regardless of virus or other things, what if your hdd fail or other random crap like that? i've always an entire backup of my ssd in a usb pen drive

in this situation the victim could have just restored everything in no time without paying that crazy amount

I totally agree.

But way too many people (people probably reading this too) will think "I'll do it tomorrow or another day." But you never know when the computer could crash, could be tonight. Whoops.
legendary
Activity: 3248
Merit: 1070
May 03, 2015, 10:49:32 AM
#17
It's going to be difficult to stop Ransomware. Once the Trojan is triggered all files targeted will be encrypted and then you are stuffed.

Without the key, your files are gone...

The only way to reduce the damage, will be to do regular offline backups. If you are hit, you could just restore the files and only lose the files that was not being backed up.

Most office workers do not make backups regularly.  Sad  

Businesses will probably start forcing backups soon if they haven't already been doing so. If everyone had backups, these ransom hackers would be out of business.

to be honest backup should be mandatory regardless of virus or other things, what if your hdd fail or other random crap like that? i've always an entire backup of my ssd in a usb pen drive

in this situation the victim could have just restored everything in no time without paying that crazy amount
hero member
Activity: 504
Merit: 500
May 03, 2015, 10:44:01 AM
#16
It's going to be difficult to stop Ransomware. Once the Trojan is triggered all files targeted will be encrypted and then you are stuffed.

Without the key, your files are gone...

The only way to reduce the damage, will be to do regular offline backups. If you are hit, you could just restore the files and only lose the files that was not being backed up.

Most office workers do not make backups regularly.  Sad  

Businesses will probably start forcing backups soon if they haven't already been doing so. If everyone had backups, these ransom hackers would be out of business.
legendary
Activity: 1904
Merit: 1074
May 03, 2015, 09:55:48 AM
#15
It's going to be difficult to stop Ransomware. Once the Trojan is triggered all files targeted will be encrypted and then you are stuffed.

Without the key, your files are gone...

The only way to reduce the damage, will be to do regular offline backups. If you are hit, you could just restore the files and only lose the files that was not being backed up.

Most office workers do not make backups regularly.  Sad  
hero member
Activity: 672
Merit: 502
May 03, 2015, 09:46:58 AM
#14
Quote
@ CCTV News
[Mo open strange e-mail in English spread! ] New Trojan virus struck, the most vulnerable foreign workers caught! It is spread through corporate and personal mail, e-mail in English, the Trojans were generally means "order" "Product Details" and so on, can be deceptive. Once caught, the computer 114 kinds of file formats will all be the Trojan encrypted and can not be opened. Want to restore a file, the only way is to pay a ransom to the Bitcoin Trojan author. (CCTV reporter Sun Yang)

I think there should be quick action to stop this Trojan virus, that does not spread to the rest of the world.

Another ransomware case, are antiviruses able to identify it still or not? I think it's designed for windows only right? Or can it spread in Linux and Mac too?

lol i can't translate those text in the image, is there any text version available?  Roll Eyes

It say "Welcome to China club.  A ching chang chong chong!"

 Cheesy Never knew you speak chinese so well.
full member
Activity: 179
Merit: 100
May 03, 2015, 08:36:52 AM
#13
Many of the ransomware cases were done with insider help. Profit is shared half half with the Russian coder.
sr. member
Activity: 462
Merit: 250
May 03, 2015, 05:42:47 AM
#12
lol i can't translate those text in the image, is there any text version available?  Roll Eyes

Try this.

Strange. That link just takes me to a login page in Chinese...

Do not use proxy. Proxies are being re-directed to login. This is the link...

http://weibo.com/3552119670/Cg6HS4D9W

...and here is the translation...

Quote
@ CCTV News
[Mo open strange e-mail in English spread! ] New Trojan virus struck, the most vulnerable foreign workers caught! It is spread through corporate and personal mail, e-mail in English, the Trojans were generally means "order" "Product Details" and so on, can be deceptive. Once caught, the computer 114 kinds of file formats will all be the Trojan encrypted and can not be opened. Want to restore a file, the only way is to pay a ransom to the Bitcoin Trojan author. (CCTV reporter Sun Yang)

So if I understand correctly, a user needs to run this file first?
Which is sent to them via email?
sr. member
Activity: 252
Merit: 250
May 03, 2015, 05:20:29 AM
#11
Quote
@ CCTV News
[Mo open strange e-mail in English spread! ] New Trojan virus struck, the most vulnerable foreign workers caught! It is spread through corporate and personal mail, e-mail in English, the Trojans were generally means "order" "Product Details" and so on, can be deceptive. Once caught, the computer 114 kinds of file formats will all be the Trojan encrypted and can not be opened. Want to restore a file, the only way is to pay a ransom to the Bitcoin Trojan author. (CCTV reporter Sun Yang)

I think there should be quick action to stop this Trojan virus, that does not spread to the rest of the world.
sr. member
Activity: 728
Merit: 256
May 03, 2015, 05:08:37 AM
#10
lol i can't translate those text in the image, is there any text version available?  Roll Eyes

Try this.

Strange. That link just takes me to a login page in Chinese...

Do not use proxy. Proxies are being re-directed to login. This is the link...

http://weibo.com/3552119670/Cg6HS4D9W

...and here is the translation...

Quote
@ CCTV News
[Mo open strange e-mail in English spread! ] New Trojan virus struck, the most vulnerable foreign workers caught! It is spread through corporate and personal mail, e-mail in English, the Trojans were generally means "order" "Product Details" and so on, can be deceptive. Once caught, the computer 114 kinds of file formats will all be the Trojan encrypted and can not be opened. Want to restore a file, the only way is to pay a ransom to the Bitcoin Trojan author. (CCTV reporter Sun Yang)
full member
Activity: 350
Merit: 118
May 03, 2015, 04:01:04 AM
#9
lol i can't translate those text in the image, is there any text version available?  Roll Eyes

Try this.

Strange. That link just takes me to a login page in Chinese...

we can't translate text images can we? (unless we speak that language lol)

I don't know if they have OCR programs written for the Chinese language but I did once translate a German book into English by scanning it and processing it through an OCR program before translating it. The results were actually better than I expected although Asian languages don't tend to translate well.

Probably best to wait for someone who understands Chinese to find this thread and chime in.
Pages:
Jump to: