So I was heading to bed, about 11:40pm, figured I'd check my mail. Alarming message there from a colleague about being unable to access a file. Long story short, ransomware on the work network.

For some daft reason, one of my predecessors left a generic account in the group that gives terminal server access. Limited folders but still. Locked everything the fuck down and doing a restore now.

Not that I needed sleep anyway. :/

(no giveaways, just venting)

(also: no, I'd never consider paying the ransom)

7 years ago*

Comment has been collapsed.

I hope you can get it all sorted out. Business ransomware and ransomware disguised as bank or police mails are such a spreading plague here that they are talked about in the local and National television news. And still people sometimes fall for it because of several reasons like curiosity and not knowing about ransomware.

7 years ago
Permalink

Comment has been collapsed.

Yeah this wasn't someone stupidly clicking something they shouldn't have (unless someone gave login details to a phishing site, still possible) but I've certainly tried to tell people what to watch out for.

7 years ago
Permalink

Comment has been collapsed.

Make sure to keep every machine quarantined and scorch them clean before letting them back onto the network. Otherwise you'll be doing the same again within 2 days.

7 years ago
Permalink

Comment has been collapsed.

Thankfully it was contained to one terminal server. Only shared folders affected. Still haven't isolated the encrypting exe though, so that box is off limits for now.

7 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

7 years ago
Permalink

Comment has been collapsed.

Nah, the range of IP addresses implied botnets or compromised PCs in eastern europe somewhere.

7 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.