W32/DistTrack is detection for a worm malware that has extremely destructive behaviour. Machines infected by it are rendered useless because most of the files, the Master Boot Record (MBR), and the partition tables are overwritten with random data. The overwritten data is lost and is not recoverable. The system is rendered unbootable.
Random ramblings and findings whilst maintaining and supporting MS Active Directory and interfacing
Showing posts with label Threat Advisory. Show all posts
Showing posts with label Threat Advisory. Show all posts
Thursday, 16 February 2017
McAfee Labs Threat Advisory for W32/DistTrack
Labels:
Intel Security,
McAfee,
SNS Notice,
Threat Advisory
Location:
Brixham TQ5, UK
McAfee Labs Threat Advisory for Ransomware-SAMAS
Ransomware-SAMAS is a detection for a family of ransomware that on execution encrypts certain file types present in the user’s system. The compromised user has to pay the attacker with a ransom to get the files decrypted.
Ransomware-SAMAS has been known to be used in targeted ransomware attacks on Organisations.
Ransomware-SAMAS has been known to be used in targeted ransomware attacks on Organisations.
Labels:
Intel Security,
McAfee,
SNS Notice,
Threat Advisory
Location:
Brixham TQ5, UK
Tuesday, 8 March 2016
KeRanger - OSX Ransomeware
March 4th Palo Alto Networks Research Center detected the first known fully functional Ransomware on OSX.
Ransomware is a type of Malware that restricts access to the affected computer system in some way, typically by encrypting the User files on a computer using an Asymmetric Encryption algorithm where the Private Key required to decrypt the files is not stored on the infected machine, and to get access to the Private key the infected party would be required to pay the 'Ransom' to unlock their files. The transactions are normally conducted using digital currency such at BitCoin.
Ransomware is a type of Malware that restricts access to the affected computer system in some way, typically by encrypting the User files on a computer using an Asymmetric Encryption algorithm where the Private Key required to decrypt the files is not stored on the infected machine, and to get access to the Private key the infected party would be required to pay the 'Ransom' to unlock their files. The transactions are normally conducted using digital currency such at BitCoin.
Labels:
OSX,
OTX,
Ransomware,
Threat Advisory
Location:
St Neots, UK
Sunday, 28 February 2016
McAfee Labs has released an updated Threat Advisory for W97M/Downloader and X97M/Downloader.

Labels:
Intel Security,
McAfee,
McAfee Labs,
Threat Advisory
Location:
St Neots, UK
Saturday, 27 February 2016
McAfee Labs Threat Advisory for Ransomware-Locky

The compromised user has to pay the attacker to get the files decrypted.
Labels:
Intel Security,
McAfee,
McAfee Labs,
Threat Advisory
Location:
St Neots, UK
Tuesday, 9 February 2016
McAfee Labs has released an updated Threat Advisory for W32/Pinkslipbot.

Labels:
Intel Security,
McAfee,
McAfee Labs,
Threat Advisory
Location:
St Neots, UK
Saturday, 23 January 2016
McAfee Labs Threat Advisory for NanoLocker
NanoLocker is a ransomware that encrypts certain files on infected machines with public key cryptography. The compromised user has to pay a ransom to the attacker to receive the secret key allowing to decrypt the files.
McAfee detects this threat under the following detection name:
McAfee detects this threat under the following detection name:
- Ransomware-FCO!partialMD5
Detailed information about the threat, its propagation, characteristics and mitigation can be viewed in the Threat Advisory.
This notification was initially communicated through the McAfee SNS service, to receive Threat Advisories directly from Intel Security please visit the SNS Centre and sign up to "Malware and Threat Reports"
Labels:
Intel Security,
McAfee,
Threat Advisory
Location:
St Neots, Saint Neots, Cambridgeshire
Friday, 15 January 2016
McAfee Labs Threat Advisory for JS/Nemucod

Labels:
Intel Security,
McAfee,
McAfee Labs,
Threat Advisory
Subscribe to:
Posts (Atom)