ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    a2 hosting - looks like a potential ransomware attack

    Scheduled Pinned Locked Moved IT Discussion
    17 Posts 6 Posters 690 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      frodooftheshire
      last edited by frodooftheshire

      Actually I don't know why they're on IIS - their website, if my memory serves me, is quite basic. Their previous IT team placed them there and it's been on our list to move them to new hosting services - this is just unfortunate timing.

      JaredBuschJ 1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch
        last edited by

        Their email stated it was a hack.

        Could be a zero day or unpatch something with IIS hosting. /shrug.

        They are restoring server by server from backups.

        1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @scottalanmiller
          last edited by

          @scottalanmiller said in a2 hosting - looks like a potential ransomware attack:

          @JaredBusch has had a customer down for several days on there, too.

          They are still down.

          1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch
            last edited by

            My original thread.
            https://mangolassi.it/topic/19394/a2-hosting-windows-server-outage

            1 Reply Last reply Reply Quote 1
            • JaredBuschJ
              JaredBusch @frodooftheshire
              last edited by

              @frodooftheshire This was the email the client received.

              Thank you for your continued patience as we work through this difficult issue. We realize how important our services are to you and your clients. Our team has been working around the clock to resolve this issue and will not rest until the task has been completed.

              Our preliminary investigation has determined that during the early hours on Monday the 22nd, our Windows platform was the victim of a malware attack. Once we detected the presence of malware, in order to prevent further spread, we shut down the entire Windows fleet and began our mitigation. To protect client data, our fleet has remained offline while we conducted our investigation.

              Based on our initial investigation, we have no reason to believe that personal information or data was downloaded due to this malware. It is important to note that A2's Billing systems and internal infrastructure were not compromised in any way. This attack only targeted our Windows platform.

              Our Engineering team determined that the safest course of action is to restore all servers from backup. This will ensure that no malware remains on any A2 systems. Around the clock work has resulted in several affected websites and servers coming back online. We are optimistic that at the current pace, the majority of the impacted services will be back online before the weekend. Individual servers will be listed on our status page as they become fully available again.

              We are not taking this issue lightly. While our current main focus is to restore services, a thorough investigation will be performed and a more detailed report released later once our investigation is complete and services are back online.

              Your continued patience and support is greatly appreciated.

              1 Reply Last reply Reply Quote 0
              • CloudKnightC
                CloudKnight
                last edited by

                Ouch...be interesting to know how the malware got in.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @CloudKnight
                  last edited by

                  @StuartJordan said in a2 hosting - looks like a potential ransomware attack:

                  Ouch...be interesting to know how the malware got in.

                  Windows 😉

                  CloudKnightC ObsolesceO 2 Replies Last reply Reply Quote 0
                  • CloudKnightC
                    CloudKnight @scottalanmiller
                    last edited by CloudKnight

                    @scottalanmiller haha very true...why people want to use IIS these days for their platform is beyond me.

                    dbeatoD 1 Reply Last reply Reply Quote 0
                    • ObsolesceO
                      Obsolesce @scottalanmiller
                      last edited by

                      @scottalanmiller said in a2 hosting - looks like a potential ransomware attack:

                      @StuartJordan said in a2 hosting - looks like a potential ransomware attack:

                      Ouch...be interesting to know how the malware got in.

                      Windows 😉

                      No, Linux.

                      Because I'm sure it was written on there!

                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                      • scottalanmillerS
                        scottalanmiller @Obsolesce
                        last edited by

                        @Obsolesce said in a2 hosting - looks like a potential ransomware attack:

                        @scottalanmiller said in a2 hosting - looks like a potential ransomware attack:

                        @StuartJordan said in a2 hosting - looks like a potential ransomware attack:

                        Ouch...be interesting to know how the malware got in.

                        Windows 😉

                        No, Linux.

                        Because I'm sure it was written on there!

                        A2 is a Windows platform. Thats its purpose. Yheir focus is IIS hosting.

                        JaredBuschJ 1 Reply Last reply Reply Quote 0
                        • dbeatoD
                          dbeato @CloudKnight
                          last edited by

                          @StuartJordan said in a2 hosting - looks like a potential ransomware attack:

                          @scottalanmiller haha very true...why people want to use IIS these days for their platform is beyond me.

                          It is interesting though, the hype right now is about Site Core which also happens to run on IIS.
                          https://www.sitecore.com/

                          1 Reply Last reply Reply Quote 0
                          • JaredBuschJ
                            JaredBusch @scottalanmiller
                            last edited by

                            @scottalanmiller said in a2 hosting - looks like a potential ransomware attack:

                            @Obsolesce said in a2 hosting - looks like a potential ransomware attack:

                            @scottalanmiller said in a2 hosting - looks like a potential ransomware attack:

                            @StuartJordan said in a2 hosting - looks like a potential ransomware attack:

                            Ouch...be interesting to know how the malware got in.

                            Windows 😉

                            No, Linux.

                            Because I'm sure it was written on there!

                            A2 is a Windows platform. Thats its purpose. Yheir focus is IIS hosting.

                            Absolutely false.

                            DFFFCF52-D03C-4A66-A38D-ABDE012B8F41.png

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @JaredBusch
                              last edited by

                              @JaredBusch no one said that hey didn't OFFER something else, but what makes them a viable product is their unique Windows offering.

                              1 Reply Last reply Reply Quote 0
                              • 1 / 1
                              • First post
                                Last post