ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Analysis of Locky ransomware

    IT Discussion
    19
    178
    50.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Deleted74295D
      Deleted74295 Banned
      last edited by

      Remember, in the BackBlaze client, it throttles the upload speed by default. So dive into the settings and you can set it to upload more.

      I backed up 50GB in a couple of hours from the UK.

      coliverC 1 Reply Last reply Reply Quote 0
      • coliverC
        coliver @Deleted74295
        last edited by

        @Breffni-Potter said:

        Remember, in the BackBlaze client, it throttles the upload speed by default. So dive into the settings and you can set it to upload more.

        I backed up 50GB in a couple of hours from the UK.

        Yep... my parents are on a crappy DSL connection.

        1 Reply Last reply Reply Quote 0
        • NicN
          Nic @BRRABill
          last edited by

          @BRRABill said:

          @coliver said:

          Backblaze keeps a ton of versions of files. I don't remember how many but it is a lot. Backblaze also isn't a sync client. It is a true backup client.

          I'm just imagining the process of restoring 150GB of data as individual files. Ugh.

          They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download.
          https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/

          BRRABillB 1 Reply Last reply Reply Quote 1
          • BRRABillB
            BRRABill @Nic
            last edited by

            @Nic said:

            They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download.
            https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/

            $189 isn't actually a bad deal AND you get to keep the drive.

            I wonder how that works, though. I mean, you obviously don't want the actual backup, as the encrypted files have probably been uploaded. So can you get the previous version of every file?

            You know what I mean? That seems messy.

            coliverC 1 Reply Last reply Reply Quote 0
            • coliverC
              coliver @BRRABill
              last edited by

              @BRRABill said:

              @Nic said:

              They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download.
              https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/

              $189 isn't actually a bad deal AND you get to keep the drive.

              I wonder how that works, though. I mean, you obviously don't want the actual backup, as the encrypted files have probably been uploaded. So can you get the previous version of every file?

              You know what I mean? That seems messy.

              How is it messy? I need the backups from 11/1/2015. They send you a drive with those backups on there. You plug it in and restore. Not sure where the issue is?

              1 Reply Last reply Reply Quote 1
              • NicN
                Nic
                last edited by

                Well you can go into the console and look at and download individual files. I imagine if you needed a restore from only before the infection date then they'd be able to do that. Let me ping @aaron for more details, since he works for them.

                BRRABillB 1 Reply Last reply Reply Quote 0
                • BRRABillB
                  BRRABill @Nic
                  last edited by

                  @Nic said:

                  Well you can go into the console and look at and download individual files. I imagine if you needed a restore from only before the infection date then they'd be able to do that. Let me ping @aaron for more details, since he works for them.

                  Haha ... I was doing the same thing. He might not get the ping though since it's later in the day. I sent him a PM.

                  1 Reply Last reply Reply Quote 0
                  • aaron-closed accountA
                    aaron-closed account Banned
                    last edited by

                    This post is deleted!
                    aaron-closed accountA 1 Reply Last reply Reply Quote 2
                    • BRRABillB
                      BRRABill
                      last edited by

                      @aaron

                      Awesome info. That might just be the solution.

                      1 Reply Last reply Reply Quote 1
                      • JaredBuschJ
                        JaredBusch
                        last edited by gjacobse

                        Look what hit my quarantine.

                        0_1456344178164_upload-a4829315-ca73-49f1-a057-17cabcf76d36

                        So I delivered it.

                        0_1456344226793_upload-8cdfc0c8-d2fb-44e0-9e55-4f88cfad5095

                        OMG! I owe them $298,39

                        Wait what? comma 39 cents? What the f[moderated] is that.

                        This is an admin email account at a client. If the admin account has it, it is only time before someone does all the things.

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender
                          last edited by

                          this is why I turned off Doc and DOCX files via the spam filter.

                          BRRABillB 1 Reply Last reply Reply Quote 0
                          • BRRABillB
                            BRRABill @Dashrender
                            last edited by BRRABill

                            @Dashrender said:

                            this is why I turned off Doc and DOCX files via the spam filter.

                            What if your users legitimately need those files?

                            wirestyle22W DashrenderD 2 Replies Last reply Reply Quote 0
                            • wirestyle22W
                              wirestyle22 @BRRABill
                              last edited by

                              @BRRABill said:

                              @Dashrender said:

                              this is why I turned off Doc and DOCX files via the spam filter.

                              What if your users legitimately need those files?

                              Much better ways to share documents than through email

                              BRRABillB 1 Reply Last reply Reply Quote 0
                              • BRRABillB
                                BRRABill @wirestyle22
                                last edited by

                                @wirestyle22 said:

                                Much better ways to share documents than through email

                                Good point.

                                DashrenderD 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @JaredBusch
                                  last edited by

                                  @JaredBusch weird mix of USD and European notation there.

                                  1 Reply Last reply Reply Quote 1
                                  • DashrenderD
                                    Dashrender @BRRABill
                                    last edited by

                                    @BRRABill said:

                                    @Dashrender said:

                                    this is why I turned off Doc and DOCX files via the spam filter.

                                    What if your users legitimately need those files?

                                    Then I can white list them. Luckily - we rarely need those sent through email.

                                    1 Reply Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender @BRRABill
                                      last edited by

                                      @BRRABill said:

                                      @wirestyle22 said:

                                      Much better ways to share documents than through email

                                      Good point.

                                      Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                      Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                      It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                      BRRABillB stacksofplatesS 2 Replies Last reply Reply Quote 0
                                      • BRRABillB
                                        BRRABill @Dashrender
                                        last edited by

                                        @Dashrender said:

                                        Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                        Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                        It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                        It was more a ML concession. I just assumed there was an easy was in ODfB everyone was using I was unaware of.

                                        For the most part file sharing like that is a PITA, especially for most users who have no idea. I have to get the file, and share it out, etc..

                                        1 Reply Last reply Reply Quote 0
                                        • stacksofplatesS
                                          stacksofplates @Dashrender
                                          last edited by stacksofplates

                                          @Dashrender said:

                                          @BRRABill said:

                                          @wirestyle22 said:

                                          Much better ways to share documents than through email

                                          Good point.

                                          Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                          Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                          It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                          I don't really do any local editing any more. Since I have Zoho I use Zoho Docs (doesn't really matter what service you use), but I use their online software. If I get it in an email, I can open it directly with their Docs apps and edit.

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @stacksofplates
                                            last edited by

                                            @johnhooks said:

                                            @Dashrender said:

                                            @BRRABill said:

                                            @wirestyle22 said:

                                            Much better ways to share documents than through email

                                            Good point.

                                            Actually - I would say not good point. What ways are you thinking? Drop Box? Google Drive? OneDrive, ODfB? etc - those are all horrible ways to share files because it's just as easy to get infected by them as it is by email.

                                            Heck, the one person I know who got hit by Locky got it through DropBox. He got a notice it had been uploaded - he went and looked - he though HUH, it's odd that it's a word file, because normally it's a PDF - meh, whatever - click - infected!
                                            It didn't help that the company used GPOs to remove the prompting about macros, so he didn't even have that protection.

                                            I don't really do any local editing any more. Since I have Zoho I use Zoho Docs, but I use their online software. If I get it in an email, I can open it directly with their Docs apps and edit.

                                            This is something awesome about O365 and Google Apps as well.

                                            stacksofplatesS 1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 8
                                            • 9
                                            • 3 / 9
                                            • First post
                                              Last post