Jump to content

ALERT: This New Ransomware Steals Passwords Before Encrypting Files

Source: http://thehackernews.com/2015/12/ransomware-hacking-password_3.html

 

You should be very careful while visiting websites on the Internet because you could be hit by a new upgrade to the World's worst Exploit Kit - Angler, which lets hackers develop and conduct their own drive-by-attacks on visitor's computers with relative ease.

 

 

Once the Angler exploit kit finds a vulnerable application, such as Adobe Flash, in visitor's computer, the kit delivers its malicious payloads, according to a blog post published by Heimdal Security.

The First Payload infects the victim's PC with a widely used data thief exploit known as Pony that systematically harvests all login usernames and passwords stored on the infected system and then sends them to servers controlled by hackers.

This allows attackers to obtain working logins for a number of websites, e-commerce sites, and even corporate applications, from which the hackers could steal more data.

The Second Payload drops the widely-used CryptoWall 4.0 Ransomware that locks user files until a ransom amount is paid.

4ynwfHK.png

Link to comment
Share on other sites

Link to post
Share on other sites

Holly fuck. I have now officially uninstalled flash from my computer. That and adblock isnow nlocking everything! Why are some websitrs still using flash anyways?

Main rig: Shockwave - MSI Z170 Gaming 7 MOBO, i7-6700k, 16GB DDR4 3000 MHz RAM, KFA2 GTX 980ti HOF, Corsair RM1000 PSU, Samsung 850 EVO 250GB SSD, WD 7200RPM 3TB, Corsair Air 540 White, ASUS P278Q 1440p 144Hz display.

 

Laptop: Lenovo Y510p, i7-4700HQ, 12 GB (8+4) 1600MHz DDR3 RAM, GT755 2GB SLI graphis card, 1366x768 display.

Link to comment
Share on other sites

Link to post
Share on other sites

So we can learn 3 things from this:

 

1. Stop giving yourself root privileges all the time in Windows. Setup a limited account for gaming, email, and browsing the web. Then use the administrative account for installing properly-vetted software and occasionally modifying system settings.

2. Do weekly backups of your important data. The amount of people who don't backup anything is...astounding.

3. Stop using Flash and Java? Definitely wouldn't hurt and your overall-computing impact would be minimal.

γνῶθι σεαυτόν

Link to comment
Share on other sites

Link to post
Share on other sites

Holly fuck. I have now officially uninstalled flash from my computer. That and adblock isnow nlocking everything! Why are some websitrs still using flash anyways?

 

3. Stop using Flash and Java? Definitely wouldn't hurt and your overall-computing impact would be minimal.

Actually, this only apply to people that HAVE OUTDATED VERSION, but if you have up-to-date version of Flash and Java then you're fine. In addition, Malwarebytes Anti Exploit Free will help protect against ransomware and exploit with no major slow down. 

Link to comment
Share on other sites

Link to post
Share on other sites

I have malwarebytes. Is that an extension to it? I had been planing on uninstalling flash for a while now. I guess this just made me do it sooner rather than latter.

Main rig: Shockwave - MSI Z170 Gaming 7 MOBO, i7-6700k, 16GB DDR4 3000 MHz RAM, KFA2 GTX 980ti HOF, Corsair RM1000 PSU, Samsung 850 EVO 250GB SSD, WD 7200RPM 3TB, Corsair Air 540 White, ASUS P278Q 1440p 144Hz display.

 

Laptop: Lenovo Y510p, i7-4700HQ, 12 GB (8+4) 1600MHz DDR3 RAM, GT755 2GB SLI graphis card, 1366x768 display.

Link to comment
Share on other sites

Link to post
Share on other sites

I have malwarebytes. Is that an extension to it? I had been planing on uninstalling flash for a while now. I guess this just made me do it sooner rather than latter.

Malwarebytes Anti Malware - Fighting against internet threats.

 

Malwarebytes Anti Exploit - Shield your applications to prevent ransomware and exploit.

Link to comment
Share on other sites

Link to post
Share on other sites

Actually, this only apply to people that HAVE OUTDATED VERSION, but if you have up-to-date version of Flash and Java then you're fine. In addition, Malwarebytes Anti Exploit Free will help protect against ransomware and exploit with no major slow down. 

 

0-day exploits are found all the time. Remember all the java-hate perpetuated by a Mozilla blacklist a couple years ago that essentially forced Pogo to convert their java-based games to flash? Only tranfered the problem from one vehicle to another. (And the new vehicle is just as bad.)

γνῶθι σεαυτόν

Link to comment
Share on other sites

Link to post
Share on other sites

Malwarebytes Anti Malware - Fighting against internet threats.

Malwarebytes Anti Exploit - Shield your applications to prevent ransomware and exploit.

Thanks. I was unaware of the anti exploit version. Good to know. Cheers...

Main rig: Shockwave - MSI Z170 Gaming 7 MOBO, i7-6700k, 16GB DDR4 3000 MHz RAM, KFA2 GTX 980ti HOF, Corsair RM1000 PSU, Samsung 850 EVO 250GB SSD, WD 7200RPM 3TB, Corsair Air 540 White, ASUS P278Q 1440p 144Hz display.

 

Laptop: Lenovo Y510p, i7-4700HQ, 12 GB (8+4) 1600MHz DDR3 RAM, GT755 2GB SLI graphis card, 1366x768 display.

Link to comment
Share on other sites

Link to post
Share on other sites

0-day exploits are found all the time. Remember all the java-hate perpetuated by a Mozilla blacklist a couple years ago that essentially forced Pogo to convert their java-based games to flash? Only tranfered the problem from one vehicle to another. (And the new vehicle is just as bad.)

Malwarebytes Anti Exploit require no signature at all like tradition antivirus does to catch 0-day exploit. It just another layers to shield your applications, if the exploit try to exploit your applications, Malwarebytes Anti Exploit will jump in to prevent it. That like say, Malwarebytes Anti Exploit REQUIRE NO SIGNATURE TO CATCH ZERO DAY EXPLOIT. 

Link to comment
Share on other sites

Link to post
Share on other sites

snip

well you shouldnt be on those sites anyways

Link to comment
Share on other sites

Link to post
Share on other sites

well you shouldnt be on those sites anyways

MSNBC, a popular cable news network has malicious ads. They are not restricted to Kickass or 4chan.

I run my browser through NSA ports to make their illegal jobs easier. :P
If it's not broken, take it apart and fix it.
http://pcpartpicker.com/b/fGM8TW

Link to comment
Share on other sites

Link to post
Share on other sites

MSNBC, a popular cable news network has malicious ads. They are not restricted to Kickass or 4chan.

well shit we are all fucked  :mellow:

Link to comment
Share on other sites

Link to post
Share on other sites

So you get fucked both sides.

 

Also, who still uses Flash and Java these days? 

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

2NgcHAj.gif

3 words-

Anti adblock killer

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×