got osiris hack .. 3bt to unlock.. any other way?

larciel

Diamond Member
May 23, 2001
4,590
8
81
employee clicked a zip file

his workstation and whole server files are now locked, redactedwants 3 bitcoin to unlock.. any other way?

*why did only his and server and not other workstations in LAN got locked?

Profanity is not allowed in the technical forums,
Markfw
Anandtech Moderator
 
Last edited by a moderator:

lxskllr

No Lifer
Nov 30, 2004
57,659
7,892
126
I'm guessing he didn't have permission to access the other machines, and the encryption ran with his permissions.
 

larciel

Diamond Member
May 23, 2001
4,590
8
81
it just scans for all drive letters and encrypt the files.. I had mapped server folder on the desktop and that's why it was infected.

major F&CK
 

Fardringle

Diamond Member
Oct 23, 2000
9,190
755
126
Wipe the encrypted drive(s) and restore from backup. You do have a backup for the server, right?
 

larciel

Diamond Member
May 23, 2001
4,590
8
81
Lol. If I had backup I wouldn't post be posting here. Anyways I decided to not pay. I'll just start new.

Sent from my LG-H918 using Tapatalk
 

Fardringle

Diamond Member
Oct 23, 2000
9,190
755
126
Plenty of places have insufficient disaster recovery plans (or none at all). Please use this as an incentive to put one together for your company! Something that can be taken off site (removable drives/tapes or online/remote backup) is my preferred option so you won't lose everything in case of fire or other loss of property. If possible, use two different options for business critical files since backups sometimes fail as well.
 

larciel

Diamond Member
May 23, 2001
4,590
8
81
hard drives are really cheap.

nas's are cheap too.

what's your excuse?
No excuse. I'll certainly stay up all night to start from scratch. That for my laziness to back up.

I'll be optimistic that lost files weren't that important. But then if it was, I'd have backed up sooner. Lol



Sent from my LG-H918 using Tapatalk
 

Elixer

Lifer
May 7, 2002
10,376
762
126
Even if you did pay, 70% don't get their data back from a recent survey.
I would revoke that person's privileges until they understand that they could have fubared the whole company's servers.

It isn't only about backups, it is about education. Heck, it is also possible that there was more to that program besides encryption, like installing backdoors, or using your machines as a DDoS bot.

I would strongly look at the firewall's logs for any out of the ordinary IPs, and see how much data has been transferred, and compare it to similar days.
I would also strongly think about reinstalling the OS as well, unless you are darn sure the infection only hit that one machine.

BTW, there are companies out there that have decryptors for free, depending on which malware it is.
 
Reactions: russ6150
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |