Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Watch out! New ransomware attack spreading from Russia
Komando.com ^ | October 25, 2017 | By Francis Navarro, Komando.com

Posted on 10/25/2017 10:07:09 AM PDT by Swordmaker

This year's global outbreaks of the WannaCry and Petya/GoldenEye ransomware variants shook the tech and business world. Traditionally designed as a for-profit malware scheme, ransomware encrypts important files on computers and demands a ransom to give you access to them again.

These cyberattacks mainly targeted outdated and unpatched Windows machines, which are vulnerable to a variety of NSA hacking tools leaked earlier this year. Since the flaws are wormable, the attacks even prompted Microsoft to make an unusual move - it released a patch for the now obsolete and unsupported operating systems to protect the apparent millions of users still using this outdated software.

Now, it appears that a new variant of the Petya ransomware is once again spreading rapidly, crippling key government offices, transportation services and corporations around the globe. But is it what it seems?

Bad Rabbit This new ransomware attack has spread across Russia, Ukraine, Turkey and Bulgaria, crippling multiple news organizations and transportation systems in its wake. There are also reports that the attack has reached targets in the U.S.

The new ransomware strain, named "Bad Rabbit" by its authors, is suspected to be a new variant of Petya and it operates quite similarly - it encrypts the files of a target computer then demands a ransom to restore the files.

In Bad Rabbit's case, its authors are demanding a ransom of 0.05 Bitcoin, equivalent to around $282. The ransom note also displays a 41-hour countdown timer that threatens the victim to pay up before it hits zero or else, the ransom goes up.

(Excerpt) Read more at komando.com ...


TOPICS: Business/Economy; Computers/Internet; Conspiracy
KEYWORDS: ransomwareattack; windows; windowspinglist

1 posted on 10/25/2017 10:07:09 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: dayglored
pinging for your list... another ransomware attack spreading due to a false FLASH download that hits only Windows computers. Not good.



2 posted on 10/25/2017 10:10:36 AM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; ShadowAce

Ping!....................


3 posted on 10/25/2017 10:10:46 AM PDT by Red Badger (Road Rage lasts 5 minutes. Road Rash lasts 5 months!.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger
I just downloaded Zonealarm for the first time.

I wonder what made me DO that ?

4 posted on 10/25/2017 10:23:35 AM PDT by knarf (I say things that are true, I have no proof, but they're true.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker

You should only browse the web and use email as a normal user, not an administrator. Better yet, create a virtual box to do it.


5 posted on 10/25/2017 10:26:18 AM PDT by AppyPappy (Don't mistake your dorm political discussions with the desires of the nation)
[ Post Reply | Private Reply | To 1 | View Replies]

To: knarf

What did you download? Anti-ransomeware, firewall, etc?


6 posted on 10/25/2017 10:34:04 AM PDT by PistolPaknMama
[ Post Reply | Private Reply | To 4 | View Replies]

To: Red Badger
Thanks for the ping, but I posted the article. In any case, this attack only works on Windows computers being a variant of the Petya ransomware, which only runs on Windows computers.

It is also a Trojan horse attack, in that it requires the complicity of the user to download and install a spurious Adobe Flash update to get infected. Apple Macs block the downloading, installation, and first run of any of that family of trojans.

7 posted on 10/25/2017 10:35:36 AM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: AppyPappy

I’d say a Linux live disc.

Chop power at the first sign of weirdness.


8 posted on 10/25/2017 10:54:19 AM PDT by wally_bert (I didn't get where I am today by selling ice cream tasting of bookends, pumice stone & West Germany)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

I would just pop a DVD in and reinstall Windows because I have no important info on my computer ,but most important I use Linux


9 posted on 10/25/2017 10:59:22 AM PDT by butlerweave (it's the children are)
[ Post Reply | Private Reply | To 1 | View Replies]

To: PistolPaknMama

They have a free trial of all of that.


10 posted on 10/25/2017 11:02:26 AM PDT by knarf (I say things that are true, I have no proof, but they're true.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker
Watch out! New ransomware attack spreading from Russia Hillary's friends.
11 posted on 10/25/2017 11:11:54 AM PDT by bmwcyle (People who do not study history are destine to believe really ignorant statements.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

Putin needs money for his rearming and his espionage.


12 posted on 10/25/2017 11:52:32 AM PDT by TBP (Progressives lack compassion and tolerance. Their self-aggrandizement is all that matters.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
Ransomware / Flash Warning! ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Swordmaker for the ping!!

13 posted on 10/25/2017 11:56:30 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

a section titled “Umbrage” that details the CIA’s ability to impersonate cyber-attack techniques used by Russia and other nation states. In theory, that means the agency could have faked digital forensic fingerprints to make the Russians look guilty of hacking the Democratic National Committee.

https://www.wired.com/2017/03/wikileaks-cia-dump-gives-russian-hacking-deniers-perfect-ammo/

Things that make you hmm...


14 posted on 10/25/2017 12:03:07 PM PDT by McGruff (Lock Her Up! In a Padded Cell!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; Whenifhow; null and void; aragorn; EnigmaticAnomaly; kalee; Kale; White Bear; ...

heads up!


15 posted on 10/25/2017 5:43:36 PM PDT by bitt (press takes him literally, but not seriously; his supporters take him seriously, but not literally)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

prevention suggestions....I’ve read the thread so far, and don’t understand whether I’m “administrator” ...I THINK I am....and how to run using a “virtual” something or other...help


16 posted on 10/25/2017 5:53:22 PM PDT by goodnesswins (There are only TWO Races. The Decent Race, and the Indecent Race. (Frankl))
[ Post Reply | Private Reply | To 13 | View Replies]

To: goodnesswins
> I’ve read the thread so far, and don’t understand whether I’m “administrator” ...I THINK I am....and how to run using a “virtual” something or other...help

In Windows, you're an administrator if either of the following are true:

The steps for finding out the above are a little different in each version of Windows. What version are you running?

A "Virtual Machine" is sort of a computer inside another computer. That's a BIG topic, which I'd encourage you to read up on at your own pace, to see if it's something you want to try out. It can get very technical.

Layman's description: https://www.howtogeek.com/196060/beginner-geek-how-to-create-and-use-virtual-machines/

Detailed description: https://en.wikipedia.org/wiki/Virtual_machine

17 posted on 10/25/2017 7:01:02 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 16 | View Replies]

To: dayglored

Just got Windows 10 a few months ago...thank you. I think I am the administrator, since this is my home laptop, and no one else has had access to it...lol.


18 posted on 10/25/2017 8:16:41 PM PDT by goodnesswins (There are only TWO Races. The Decent Race, and the Indecent Race. (Frankl))
[ Post Reply | Private Reply | To 17 | View Replies]

To: Swordmaker; All

what is going to end up happening is more and more people are going to run windows in a virtual machine on their linux systems- then these ransomwares can’t infect (I think?) because nothing is saved unless you choose to save your session-

Another viable option is for everyone to install rollbackRX- it is system restore on steroids- and will allow you to roll back you system to a known good virus free time before you got the virus- and it does so on boot- before ransomware can start I believe- as rollbackRX protects the master boot record

Here’s a link discussing the issue for anyone itnerested:

http://community.horizondatasys.com/forum/rollback-rx/3873-will-rollback-rx-protect-against-petya-ransomware


19 posted on 10/25/2017 8:46:02 PM PDT by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson