GetDotted Domains

Viewing Thread:
"LOCKY ransomware virus via spoofed email address"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Fri 29/04/16 at 11:20
Moderator
"Are you sure?"
Posts: 5,000
*Heads Up*

I've just had a call from a client saying they stupidly opened an email that appeared to have been sent from themselves...

(See other forum threads for mentions of this.)

It contained a ZIP file attachment which they also opened (!) and before you know it they found they had been infected with LOCKY ransomware! :¬(

Reading about LOCKY it looks pretty serious and people are often caught out via an email that looks as if it has been sent from their own email account.

I saw a number of these spoofed dodgy emails myself yesterday but it's not only Freeola accounts being targeted it could be any provider.

I'm off to investigate later.
[s]Hmmm...[/s]
Fri 29/04/16 at 16:53
Moderator
"Are you sure?"
Posts: 5,000
Just to update my LOCKY infected client...


After investigation the spoofed email (from his own domain) arrived yesterday morning with the subject 'Doc575' with an attached ZIP file.

A few minutes after opening the attachment good old Microsoft Defender was on the case. It looks like 544 files were zapped in that few minutes.

Luckily my client has a Syncback backup solution in place so it's looking as if they may have got away with things!

NOTE: If LOCKY was allowed to run then there's a good chance that it would have gone on to mess with external drives and networked kit. I can see that causing all sorts of damage.

I don't leave my external backup drive permanently switched on - this saves me from a storm taking everything out (another client got hit with that last year!) and would also stop LOCKY reaching it.

[s]Hmmm...[/s]
Fri 29/04/16 at 12:10
Regular
"Feather edged ..."
Posts: 8,536
A bit more info here and here and here for the new variant

What intrigues me about this 'ransomware' is that payment for the decrypter is 0.5 Bitcoins! But how much is a Bitcoin? Well, on today's Market, 1 Bitcoin = £308.22!!!! An expensive mistake! However, if the infection is of the new variety, AutoLocky, then a free decyption tool is available as detailed in the 3rd link.
Fri 29/04/16 at 11:20
Moderator
"Are you sure?"
Posts: 5,000
*Heads Up*

I've just had a call from a client saying they stupidly opened an email that appeared to have been sent from themselves...

(See other forum threads for mentions of this.)

It contained a ZIP file attachment which they also opened (!) and before you know it they found they had been infected with LOCKY ransomware! :¬(

Reading about LOCKY it looks pretty serious and people are often caught out via an email that looks as if it has been sent from their own email account.

I saw a number of these spoofed dodgy emails myself yesterday but it's not only Freeola accounts being targeted it could be any provider.

I'm off to investigate later.
[s]Hmmm...[/s]

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Very pleased
Very pleased with the help given by your staff. They explained technical details in an easy way and were patient when providing information to a non expert like me.
Excellent
Excellent communication, polite and courteous staff - I was dealt with professionally. 10/10

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.