Auteur Sujet: [BC] UmbreCrypt Ransomware manually installed via Terminal Services  (Lu 6868 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25139
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Bonjour,

Une fiche BleepingComputer sur le Ransomware UmbreCrypt

UmbreCrypt Ransomware manually installed via Terminal Services

Citer
A new CrypBoss ransomware variant has been released called UmbreCrypt.  This ransomware family encrypts a victim's data with AES encryption and then requires them to email the developers for payment instructions. At this time there is no way to decrypt these files for free, but Fabian Wosar of Emsisoft is looking into modifying his current CrypBoss decrypter to work with this variant.

I have been told by numerous victims that they feel UmbreCrypt was manually installed through hacked terminal services or remote desktop. If you are infected with this ransomware, it is advised that you check your Windows event logs for failed login attempts to try and determine the account that was compromised.
« Modifié: février 14, 2016, 09:42:50 par chantal11 »
 

Tags: