ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Analysis of Locky ransomware

    IT Discussion
    19
    178
    49.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • coliverC
      coliver @Deleted74295
      last edited by

      @Breffni-Potter said:

      Remember, in the BackBlaze client, it throttles the upload speed by default. So dive into the settings and you can set it to upload more.

      I backed up 50GB in a couple of hours from the UK.

      Yep... my parents are on a crappy DSL connection.

      1 Reply Last reply Reply Quote 0
      • NicN
        Nic @BRRABill
        last edited by

        @BRRABill said:

        @coliver said:

        Backblaze keeps a ton of versions of files. I don't remember how many but it is a lot. Backblaze also isn't a sync client. It is a true backup client.

        I'm just imagining the process of restoring 150GB of data as individual files. Ugh.

        They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download.
        https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/

        BRRABillB 1 Reply Last reply Reply Quote 1
        • BRRABillB
          BRRABill @Nic
          last edited by

          @Nic said:

          They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download.
          https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/

          $189 isn't actually a bad deal AND you get to keep the drive.

          I wonder how that works, though. I mean, you obviously don't want the actual backup, as the encrypted files have probably been uploaded. So can you get the previous version of every file?

          You know what I mean? That seems messy.

          coliverC 1 Reply Last reply Reply Quote 0
          • coliverC
            coliver @BRRABill
            last edited by

            @BRRABill said:

            @Nic said:

            They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download.
            https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/

            $189 isn't actually a bad deal AND you get to keep the drive.

            I wonder how that works, though. I mean, you obviously don't want the actual backup, as the encrypted files have probably been uploaded. So can you get the previous version of every file?

            You know what I mean? That seems messy.

            How is it messy? I need the backups from 11/1/2015. They send you a drive with those backups on there. You plug it in and restore. Not sure where the issue is?

            1 Reply Last reply Reply Quote 1
            • NicN
              Nic
              last edited by

              Well you can go into the console and look at and download individual files. I imagine if you needed a restore from only before the infection date then they'd be able to do that. Let me ping @aaron for more details, since he works for them.

              BRRABillB 1 Reply Last reply Reply Quote 0
              • BRRABillB
                BRRABill @Nic
                last edited by

                @Nic said:

                Well you can go into the console and look at and download individual files. I imagine if you needed a restore from only before the infection date then they'd be able to do that. Let me ping @aaron for more details, since he works for them.

                Haha ... I was doing the same thing. He might not get the ping though since it's later in the day. I sent him a PM.

                1 Reply Last reply Reply Quote 0
                • aaron-closed accountA
                  aaron-closed account Banned
                  last edited by

                  This post is deleted!
                  aaron-closed accountA 1 Reply Last reply Reply Quote 2
                  • BRRABillB
                    BRRABill
                    last edited by

                    @aaron

                    Awesome info. That might just be the solution.

                    1 Reply Last reply Reply Quote 1
                    • JaredBuschJ
                      JaredBusch
                      last edited by gjacobse

                      Look what hit my quarantine.

                      0_1456344178164_upload-a4829315-ca73-49f1-a057-17cabcf76d36

                      So I delivered it.

                      0_1456344226793_upload-8cdfc0c8-d2fb-44e0-9e55-4f88cfad5095

                      OMG! I owe them $298,39

                      Wait what? comma 39 cents? What the f[moderated] is that.

                      This is an admin email account at a client. If the admin account has it, it is only time before someone does all the things.

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender
                        last edited by

                        this is why I turned off Doc and DOCX files via the spam filter.

                        BRRABillB 1 Reply Last reply Reply Quote 0
                        • BRRABillB
                          BRRABill @Dashrender
                          last edited by BRRABill

                          @Dashrender said:

                          this is why I turned off Doc and DOCX files via the spam filter.

                          What if your users legitimately need those files?

                          wirestyle22W DashrenderD 2 Replies Last reply Reply Quote 0
                          • wirestyle22W
                            wirestyle22 @BRRABill
                            last edited by

                            @BRRABill said:

                            @Dashrender said:

                            this is why I turned off Doc and DOCX files via the spam filter.

                            What if your users legitimately need those files?

                            Much better ways to share documents than through email

                            BRRABillB 1 Reply Last reply Reply Quote 0
                            • BRRABillB
                              BRRABill @wirestyle22
                              last edited by

                              @wirestyle22 said:

                              Much better ways to share documents than through email

                              Good point.

                              DashrenderD 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @JaredBusch
                                last edited by

                                @JaredBusch weird mix of USD and European notation there.

                                1 Reply Last reply Reply Quote 1
                                • DashrenderD
                                  Dashrender @BRRABill
                                  last edited by

                                  @BRRABill said:

                                  @Dashrender said:

                                  this is why I turned off Doc and DOCX files via the spam filter.

                                  What if your users legitimately need those files?

                                  Then I can white list them. Luckily - we rarely need those sent through email.

                                  1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender @BRRABill
                                    last edited by

                                    @BRRABill said:

                                    @wirestyle22 said:

                                    Much better ways to share documents than through email

                                    Good point.

                                    Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                    Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                    It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                    BRRABillB stacksofplatesS 2 Replies Last reply Reply Quote 0
                                    • BRRABillB
                                      BRRABill @Dashrender
                                      last edited by

                                      @Dashrender said:

                                      Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                      Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                      It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                      It was more a ML concession. I just assumed there was an easy was in ODfB everyone was using I was unaware of.

                                      For the most part file sharing like that is a PITA, especially for most users who have no idea. I have to get the file, and share it out, etc..

                                      1 Reply Last reply Reply Quote 0
                                      • stacksofplatesS
                                        stacksofplates @Dashrender
                                        last edited by stacksofplates

                                        @Dashrender said:

                                        @BRRABill said:

                                        @wirestyle22 said:

                                        Much better ways to share documents than through email

                                        Good point.

                                        Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                        Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                        It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                        I don't really do any local editing any more. Since I have Zoho I use Zoho Docs (doesn't really matter what service you use), but I use their online software. If I get it in an email, I can open it directly with their Docs apps and edit.

                                        DashrenderD 1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender @stacksofplates
                                          last edited by

                                          @johnhooks said:

                                          @Dashrender said:

                                          @BRRABill said:

                                          @wirestyle22 said:

                                          Much better ways to share documents than through email

                                          Good point.

                                          Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                          Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                          It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                          I don't really do any local editing any more. Since I have Zoho I use Zoho Docs, but I use their online software. If I get it in an email, I can open it directly with their Docs apps and edit.

                                          This is something awesome about O365 and Google Apps as well.

                                          stacksofplatesS 1 Reply Last reply Reply Quote 1
                                          • stacksofplatesS
                                            stacksofplates @Dashrender
                                            last edited by

                                            @Dashrender said:

                                            @johnhooks said:

                                            @Dashrender said:

                                            @BRRABill said:

                                            @wirestyle22 said:

                                            Much better ways to share documents than through email

                                            Good point.

                                            Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                            Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                            It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                            I don't really do any local editing any more. Since I have Zoho I use Zoho Docs, but I use their online software. If I get it in an email, I can open it directly with their Docs apps and edit.

                                            This is something awesome about O365 and Google Apps as well.

                                            Ya I've used both. I have a Microsoft account and an Office 365 account. The Office online stuff is nice, and same with Google Docs. I just use Zoho for mail so that makes sense for me.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 9
                                            • 4 / 9
                                            • First post
                                              Last post