ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Dharma ransomware

    Scheduled Pinned Locked Moved IT Discussion
    dharmaransomware
    15 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      Sounds like they have things well in hand. Are you wondering if there is anything to do now that the ransom is required?

      DanpD 1 Reply Last reply Reply Quote 1
      • RojoLocoR
        RojoLoco
        last edited by

        Lots of user training for the entire staff. The only way to prevent these infections is to keep Janet in accounting from clicking every damn thing she sees. Training and better backups... which they may actually have to pony up some $$$ to do properly.

        DanpD 1 Reply Last reply Reply Quote 3
        • DanpD
          Danp @scottalanmiller
          last edited by

          @scottalanmiller I learned of the encryption last night and just now received a copy of the critical incident report to review. They are proceeding with the understanding that the files can't be unencrypted without paying the ransom.

          I know that solutions have been to decrypt other ransomware. From my brief research, I haven't seen a solution for this one.

          1 Reply Last reply Reply Quote 0
          • DanpD
            Danp @RojoLoco
            last edited by

            @RojoLoco My understanding is that this wasn't an end-user issue. Rather, the prior IT guy left a router protected by a weak password.

            RojoLocoR 1 Reply Last reply Reply Quote 0
            • RojoLocoR
              RojoLoco @Danp
              last edited by

              @Danp said in Dharma ransomware:

              @RojoLoco My understanding is that this wasn't an end-user issue. Rather, the prior IT guy left a router protected by a weak password.

              Ouch. Then they will need to hire at least 1 competent IT person. Hopefully they won't become a target after being successfully attacked (not paying the ransom helps with this).

              1 Reply Last reply Reply Quote 1
              • DanpD
                Danp
                last edited by

                Found this post from earlier today on bleepingcomputer.com.

                It would be wonderful if these can be used to build a decryption tool.

                DashrenderD 1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @Danp
                  last edited by

                  @Danp said in Dharma ransomware:

                  Found this post from earlier today on bleepingcomputer.com.

                  It would be wonderful if these can be used to build a decryption tool.

                  yes and no.

                  yes because someone doesn't have to start over - no because the company not might really step up their IT game.

                  DanpD 1 Reply Last reply Reply Quote 0
                  • DanpD
                    Danp @Dashrender
                    last edited by

                    @Dashrender Oh.. they are definitely stepping up their IT game. New MSP is hired already. I'm reviewing their $26K proposal, which includes new security devices, new server, new backup appliance, etc.

                    Some of their recommendations call for solutions that I don't have experience with, so I'll start another thread to seek input on that.

                    DashrenderD 1 Reply Last reply Reply Quote 1
                    • DustinB3403D
                      DustinB3403
                      last edited by

                      OK so I just updated my lab copy of XO, and it worked without issue. I'm gonna snapshot, and try the update again and see if it breaks.

                      1 Reply Last reply Reply Quote 1
                      • DanpD
                        Danp
                        last edited by

                        In my best JB voice -- "FFS. WTF does this have to do with the current discussion?!"

                        <gd&r>

                        DustinB3403D 1 Reply Last reply Reply Quote 2
                        • DustinB3403D
                          DustinB3403 @Danp
                          last edited by

                          @Danp whoops wrong topic.

                          DanpD 1 Reply Last reply Reply Quote 0
                          • DanpD
                            Danp @DustinB3403
                            last edited by

                            @DustinB3403 👍 😆

                            1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @Danp
                              last edited by

                              @Danp said in Dharma ransomware:

                              @Dashrender Oh.. they are definitely stepping up their IT game. New MSP is hired already. I'm reviewing their $26K proposal, which includes new security devices, new server, new backup appliance, etc.

                              Some of their recommendations call for solutions that I don't have experience with, so I'll start another thread to seek input on that.

                              Now thing is to make sure they don't over spend....

                              DanpD 1 Reply Last reply Reply Quote 0
                              • DanpD
                                Danp @Dashrender
                                last edited by

                                @Dashrender Exactly see new thread here.

                                1 Reply Last reply Reply Quote 0
                                • 1 / 1
                                • First post
                                  Last post