SophosLabs has just published a new report on a ransomware strain known as ProLock, which is interesting not so much for its implementation as for its evolution.
Lets start at the very top of the ransomware dilemma.
Should you ever pay blackmail money to ransomware crooks?
As you can imagine, law enforcement and government bodies around the world reguarly say, No! Please dont, because its the regular payments that make the whole ransomware ecosystem work in the first place.
Sure, in the 1990s, before anyone figured out how to make any real money out of malware, there were plenty of deeply destructive computer viruses that circulated widely and did huge amounts of damage.
It was often hard to figure out why anyone would write and deliberately disseminate malware back then, because those who were caught very often ended up serving prison sentences.
There were lots of possible reasons, of course: because virus writers had some sort of axe to grind with the world; because they wanted to make some sort of social or political statement; or simply because they could, and wanted to show off to their buddies in the cyberunderground.
Money didnt really come into it at all back then, not least because there wasnt a reliable way to extort money online and remain anonymous.
But malware in general, and ransomware in particular, doesnt much follow that anger at the world path any more.
Its almost all about money now and as you are no doubt aware in the case of ransomware, the money demanded can be several million dollars per network attack.
So, if no one ever paid up, contemporary theory says that crooks would be much less inclined to bother attacking networks with ransomware in the first place.
Thats because most attacks require quite a lot of time and effort on the part of the crooks this isnt an after-hours hobby where hackers compare notes with underground chums, but a competitive cybercrime arena.
Ransomware gangs may take days or weeks to get their attack ready, for example by:
Our own threat response team has even dealt with a ransomware victim where the criminals appear to have dug around in the IT departments own email to find out what cyberinsurance arrangements the company had in place, and to gauge how high to pitch their ransom demand.
These crooks also downloaded personal contact data for key members in the IT team, and then placed a voice call (using a voice changer) to the IT manager to threaten him directly, reading out some of his personally identifiable information (PII) as proof that they had already exfiltrated corporate data.
Weve also seen ransomware attacks where the criminals have emailed staff across the company to warn them that their own PII would be exposed to the world if the company didnt pay up, urging the staff to contact their IT team to demand that payment be made basically, turning the organisation against itself.
As you can see, the reaction of the crooks to the ever-louder advice, Dont pay! has been to adjust their approach to make their demands more compelling, even against companies that feel sure theyd never pay up.
As a result, weve always taken a conciliatory approach that says, We urge you to avoid paying up if there is any way you can. But if its legal to pay in your country, and you end up doing so, were not going to judge you for it, because its not the future of our business thats looking into the barrel of a ransomware criminals gun.
After all, if you genuinely have been caught out with inadequate backup, if every single computer in your company is essentially frozen and useless, if your business is almost certain to go down the tubes if you dont pay up, and if paying up is likely to save the company
then it would be rather self-indulgent for anyone to insist, You still shouldnt pay up, even if it means that everyone loses their job.
But what if paying up wont work, no matter how stuck you are, and might even make your position worse?
Thats a problem that faced the ProLock ransomware gang earlier this year.
Last year, as far as we can tell, these crooks were behind ransomware called PwndLocker that fortunately for the rest of us could sometimes be decrypted without paying.
The crooks had apparently made a cryptographic blunder that sometimes allowed victims to recover the decryption key even after the encryption was finished.
Next came the ProLock ransomware strain, which ended up provoking a more-urgent-than-ever warning from the FBI that said:
The decryption key or decryptor provided by the attackers upon paying the ransom has not routinely executed correctly. The decryptor can potentially corrupt files that are larger than 64MB and may result in file integrity loss of approximately 1 byte per 1KB over 100MB. Added coding may be necessary for the decryptor to function.
Interestingly, ProLock doesnt actually scramble every byte of every file it attacks.
In the ProLock sample analysed by SophosLabs, the first 8KB (8192 bytes, or 0x2000 in hex) of every file are left untouched.
As a result, files of 8KB or below are unmodified, while files bigger than 8192 bytes are encrypted but with the first 8KB intact.
ProLock isnt the first ransomware to use this trick leaving the start of files alone and there are three likely reasons why ransomware crooks do it:
We checked our own home directory and found that about two-thirds of our files were smaller than 8KB, which led us to think that a ProLock attack might not be that bad after all
except that the one-third of files that would get scrambled included almost everything of real importance, including all audio and podcast files and every video file, as well as most images, PDFs, documents, databases and presentations.
Only in the case of our Naked Security article archive would we have been lucky enough to retain just over half of our files, for the simple reason that we save the originals as plain text files, half of which are just under 8KB. (If saved as DOC or DOCX files, they would all come out well over 8192 bytes.)
ProLock also has some other interesting tricks to learn about, including obscuring the ransomware executable itself by hiding it inside a BMP (bitmap image) file that displays as an almost-uniform and apparently uninteresting black rectangle if you open it for inspection.
In a real-life ProLock attack, however, a PowerShell script that does not itself contain any ransomware code is used to unravel the EXE from the innocent-looking BMP file in order to launch it.
ProLock also contains a list of more than 150 different software products that it tries to spot in memory and kill off automatically, including enterprise applications (which typically keep files such as databases locked open, with the result that ransomware cant get write access to those files), security software and backup tools.
For the full and fascinating details of the ProLock ransomware, please visit the SophosLabs report.
You will learn:
Visit link:
ProLock ransomware new report reveals the evolution of a threat - Naked Security
- History of Evolution | Internet Encyclopedia of Philosophy [Last Updated On: December 9th, 2016] [Originally Added On: December 9th, 2016]
- Evolution - Bulbapedia, the community-driven Pokmon encyclopedia [Last Updated On: December 12th, 2016] [Originally Added On: December 12th, 2016]
- What is Evolution - explanation and definitions [Last Updated On: December 21st, 2016] [Originally Added On: December 21st, 2016]
- Evolution (2001 film) - Wikipedia [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- EvolutionM.net - Mitsubishi Lancer Evolution | Reviews, News ... [Last Updated On: February 1st, 2017] [Originally Added On: February 1st, 2017]
- YMCA evolution continues at lake - Gaston Gazette [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Ivanka Trump's Beauty Evolution, From 1998 to Today Watch - Us Weekly [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Lumpy, hairy, toe-like fossil could reveal the evolution of molluscs - The Guardian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How Evolution Alters Biological Invasions - ScienceBlog.com (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Cultural evolution and the mutilation of women - The Economist [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Late-night hosts on the evolution of Trump: 'Dickish to dictatorish' - The Guardian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Gold's Gym Regina rebrands to become Evolution Fitness - Regina Leader-Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Incremental Versus Radical Innovation: A Response to Josh Swamidass on Evolution and Cancer - Discovery Institute [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Blockchain: Investment (R)Evolution For Developing Markets - Forbes [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- See the Evolution of the Famed Porsche 911 in 7 Photos - WIRED [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Exhibition charts 500 years of evolution of robots - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How evolution turned ordinary plants into ravenous meat-eaters - Wired.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Are Evolution Fresh Drinks 'Poison'? - snopes.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Non-Chromosomal DNA Drives Tumor Evolution - The Scientist [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Chimpanzee feet allow scientists a new grasp on human foot evolution - Phys.Org [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- 'Goldilocks' genes that tell the tale of human evolution hold clues to variety of diseases - Science Daily [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Pac-Man is Coming to 'The Sandbox Evolution' Next Week - Touch Arcade [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Chimpanzee feet allow scientists a new grasp on human foot ... - Science Daily [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Bacteria sleep, then rapidly evolve, to survive antibiotic treatments - Phys.Org [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orangutan squeaks reveal language evolution, says study - BBC ... - BBC News [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Evolution gives rhyme its reason - Aurora News Register [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Deeper origin of gill evolution suggests 'active lifestyle' link in early vertebrates - Science Daily [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- From Tara Palmer-Tomkinson to Cara Delevingne: the evolution of the It girl - The Guardian [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Banned TED Talk: Rupert Sheldrake The Science Delusion - Collective Evolution [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- VOTD: Watch the Evolution of Keanu Reeves' Acting Career - /FILM [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Pokmon Go Eevee evolution: How to evolve Eevee into Vaporeon, Jolteon and Flareon with new names - Eurogamer.net [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Horse evolution bucks evolutionary theory - Science News [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Samsung's Chromebook Pro highlights the category's continued evolution - TechCrunch [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Scientists solve fish evolution mystery - Phys.Org [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Wildfire evolution forces Forest Service into new thinking - The Daily Progress [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- How the horse can help us answer one of evolution's biggest questions - Raw Story [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- A primer on Darwin Day: Some religious groups embrace 'Theistic evolution' - LancasterOnline [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Apple: Evolution of in-car audio tech moving at 'speed of sound ... - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Mariska Hargitay's Evolution from '80s Glam to Law & Order: Special Victims Unit - TVOvermind [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Evolution of baseball from power to speed has left SBs behind ... - Chicago Sun-Times [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- More order with less judgment: An optimal theory of the evolution of cooperation - Science Daily [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- J. Albert C. Uy speaks on evolution, biodiversity in bellied flycatcher population - The College Reporter [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- See the Evolution of Movie Magic With Every Oscar Winner for Visual Effects in History - Gizmodo [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Numerology: Here's What Your Name Says About You - Collective Evolution [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- The Evolution of Valentine's Day - Inside Science News Service [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Why evolution may be tech billionaires' biggest enemy - The Week Magazine [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Community Viewpoint: Evolution, like gravity, is much more than theory it is a fact - Kdminer [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How the horse can help us answer one of evolution's biggest questions - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How evolution alters biological invasions - Science Daily [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Cockeyed squid shines light on deep sea evolution - Christian Science Monitor [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Eye Evolution: A Closer Look - Discovery Institute [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Evolution always wins: University of Idaho video game uses mutating aliens to teach science concepts - The Spokesman-Review [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Geneticists track the evolution of parenting - Phys.Org [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How this cockeyed squid shines a light on deep sea evolution - Christian Science Monitor [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- 4 Possible Roadmaps For macOS and iOS Evolution - The Mac Observer (blog) [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- The Evolution of the Energy Capital of the World - Texas Monthly [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Humons presents an atypical dance evolution - Detroit Metro Times [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Pokemon Go Adds 80 Generation 2 Pokemon, New Evolution Items This Week - IGN [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Fossil discovery rewrites understanding of reproductive evolution ... - Science Daily [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- 'X-Men: Evolution' Is the Gateway Drug of Comic Book Shows - Geek [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- A cultural catch: Evolution of wooden halibut hooks carved by native ... - Science Daily [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Bremerton's Fitness Evolution now Planet Fitness - Kitsap Sun (blog) [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Eye Evolution: The Waiting Is the Hardest Part - Discovery Institute [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Evolution Of The Yeezy: 2009-2017 - HotNewHipHop [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Prebiotic evolution: Hairpins help each other out - Science Daily [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- This 'Live Birth' Fossil Could Change Humanity's Understanding Of Evolution - Daily Caller [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Mysterious Ancient Stonehenge-Like Circles Found in Amazon Rainforest - Collective Evolution [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- 'Pokemon Go': How to Evolve Poliwhirl Into Politoed - Heavy.com [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- 'Pokemon Go': How to Evolve Slowpoke Into Slowbro or Slowking - Heavy.com [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- 'Pokemon Go': How to Evolve Gloom Into Bellossom - Heavy.com [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Pokmon Go Dragon Scale - how to evolve Seadra into Kingdra and how to get the Dragon Scale - Eurogamer.net [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Pokmon Go Eevee evolution: How to evolve Eevee into Umbreon, Espeon, Vaporeon, Jolteon and Flareon with new ... - Eurogamer.net [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- University of Pittsburgh guest speaker discloses evolution findings - UTA The Shorthorn [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- 'Pokemon Go' Special Items: Drop Rates for Evolution Items & Berries at Pokestops - Heavy.com [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- How Vedic Philosophy Influenced Nikola Tesla's Idea of 'Free Energy' - Collective Evolution [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Migration to America took long enough for evolution to happen on the way - Ars Technica [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- How To Choose Your Eevee Evolution In 'Pokmon GO:' Umbreon And Espeon Edition - Forbes [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Evolution Items - IGN [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Congo River fish evolution shaped by intense rapids: Genomic study ... - Science Daily [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Pokmon Go - How to evolve, use Special Items, when to evolve or Power Up your Pokmon - Eurogamer.net [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]