Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le février 14, 2016, 09:41:32

Titre: [BC] UmbreCrypt Ransomware manually installed via Terminal Services
Posté par: chantal11 le février 14, 2016, 09:41:32
Bonjour,

Une fiche BleepingComputer sur le Ransomware UmbreCrypt

UmbreCrypt Ransomware manually installed via Terminal Services (http://www.bleepingcomputer.com/news/security/umbrecrypt-ransomware-manually-installed-via-terminal-services/)

Citer
A new CrypBoss ransomware variant has been released called UmbreCrypt.  This ransomware family encrypts a victim's data with AES encryption and then requires them to email the developers for payment instructions. At this time there is no way to decrypt these files for free, but Fabian Wosar of Emsisoft is looking into modifying his current CrypBoss decrypter to work with this variant.

I have been told by numerous victims that they feel UmbreCrypt was manually installed through hacked terminal services or remote desktop. If you are infected with this ransomware, it is advised that you check your Windows event logs for failed login attempts to try and determine the account that was compromised.