[opensuse] Linux threats from ransomware : Erebus
stuff seen : <http://blog.trendmicro.com/trendlabs-security-intelligence/erebus-resurfaces-as-linux-ransomware/> regards ... -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
On 2017-06-21 09:12, ellanios82 wrote:
stuff seen :
<http://blog.trendmicro.com/trendlabs-security-intelligence/erebus-resurfaces-as-linux-ransomware/>
«As for how this Linux ransomware arrives, we can only infer that Erebus may have possibly leveraged vulnerabilities or a local Linux exploit. For instance, based on open-source intelligence, NAYANA’s website runs on Linux kernel 2.6.24.2, which was compiled back in 2008.» «Additionally, NAYANA’s website uses Apache version 1.3.36 and PHP version 5.1.4, both of which were released back in 2006» [Groan] «In a notice posted on NAYANA’s website last June 12, the company shared that the attackers demanded an unprecedented ransom of 550 Bitcoins (BTC), or US$1.62 million, in order to decrypt the affected files from all its servers. In an update on June 14, NAYANA negotiated a payment of 397.6 BTC (around $1.01 million as of June 19, 2017) to be paid in installments.» Well, I hope that by now they learnt to update their machines. -- Cheers / Saludos, Carlos E. R. (from 42.2 x86_64 "Malachite" at Telcontar)
On Wed, Jun 21, 2017 at 1:54 PM, Carlos E. R. <robin.listas@telefonica.net> wrote:
Well, I hope that by now they learnt to update their machines.
And perhaps to backup their data? What would happen if the machine had simply died? Surely they could at least have restored from the backup before the encryption? Some loss. But still... -- Roger Oberholtzer -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
On 2017-06-22 10:41, Roger Oberholtzer wrote:
On Wed, Jun 21, 2017 at 1:54 PM, Carlos E. R. <> wrote:
Well, I hope that by now they learnt to update their machines.
And perhaps to backup their data? What would happen if the machine had simply died? Surely they could at least have restored from the backup before the encryption? Some loss. But still...
Indeed. If I had something hosted there I would consider go elsewhere fast. -- Cheers / Saludos, Carlos E. R. (from 42.2 x86_64 "Malachite" at Telcontar)
participants (3)
-
Carlos E. R.
-
ellanios82
-
Roger Oberholtzer