How to Identify Ransomware

If you are hit by Ransomware, you need to block off the attack by removing Internet access from your PCs and servers, stop any encryption processes in progress and any other processes running that shouldn’t be running.

Then the first stage of investigation is to identify what you’re facing and the website https://id-ransomware.malwarehunterteam.com/ is a good starting point.

You upload one encrypted file or the file that is the ransom message to this website and it will try to identify the variant of ransomware. Currently it can identify several hundred variants.

For each there is extra information which can tell you if there are decryption keys available on the Internet.

Some anti-hackers try to find the decryption keys and post them freely, but the blackmailers do know this and try to stay of ahead of them by using new variants for which there are no keys available except for the one held by the blackmailer.

The website is run purely as a free service to the public and does not decrypt files for you – you need an IT  professional for that (assuming it’s possible as many cannot be decrypted without a key from the blackmailer)

If you have a suspected virus rather than ransomware then there is a website that may help to identify it  at https://www.virustotal.com

As always, the advice is that it’s best to avoid being held to ransom – ensure you have adequate systems protection in place, staff that have been educated on the danger of cyber-attacks, regular backups (including off-site) and have a plan in place to deal with a ransomware attack.

Do Share this post on social media – click on the post title then scroll down to the social media share buttons.

Fightback Ninja Signature

Stop Remote Desktop Access

Remote desktop / remote control desktop / remote desktop protocol – this means to take control of one computer from another one.

This can be very useful if say you need to work at home but access some services from your workplace or files off your work computer etc.  It’s also used extensively by IT support staff when diagnosing and fixing problems.

Within a company network it can be safe but if you open your firewall to allow remote access through the firewall then this can be a problem.

Microsoft’s implementation of remote access has vulnerabilities that the hackers know about and they scan IP addresses looking for anyone that has left that door in their firewall available (typically RDP is on TCP port 3389).

Security experts believe that this vulnerability is extensively used by ransomware spreaders who can then bypass the password check and gain access to your systems.

If you use remote access through your firewall – make sure you’re safe or turn it off permanently.

Can There Be Safe Remote Access?

This depends on exactly what you want to achieve but the general advice from many security experts is to use a Virtual Private Network or just don’t allow remote access from outside of your firewall.

Do leave a comment on this post – click on the post title then scroll down to leave your comment.

Fightback Ninja Signature

Predictions on The Growth of Disinformation in 2022

These predictions are based on information on the Kinzen website at www.kinzen.com plus other information sources.

Disinformation is spread by governments, organisations and individuals for a wide variety of reasons.

They may want to damage a country, business or people or to take advantage in some other way or to spread their propaganda or hide their activities and it is becoming a more sophisticated battle every year for people to discern truth from disinformation.

QAnon

QAnon is a strange phenomena where a mysterious figure spread disinformation and made predictions which mostly have not come true and yet has a large very committed following. It is described as an American far-right political conspiracy theory and movement centred on false claims made by an anonymous individual or individuals, known by the name “Q”, that a cabal of Satanic people operate at high levels in the US government and other countries.

This does sound ridiculous but it has a significant following. Q knew how to press the buttons for some conspiracy theorists and others and it refuses to go away, at least for now.

It is likely that more such conspiracy groups will form over the coming years and use many of the same tactics and ideas as QAnon.

Politics

October 2022 is the time for the general election in Brazil and many expect to see fighting over the legitimacy of the electoral process

The French presidential contest is in April 2022 and there may be more sophisticated forms of misinformation used to push the results one way or another.

Hungary’s populist pioneer Viktor Orban is facing a tough challenge from a united opposition in April. Orban has used creeping state control of media to seed storylines that appeal to established prejudice and end with some “sort of discriminatory legislation against independent voices.” The Orban government is already warning that the US will attempt to influence the vote, creating the very prospect of a disinformation campaign about disinformation.

The Disinformation War

The Oxford Internet Institute believes that 81 countries have taken part in online propaganda and covert influence campaigns perhaps as part of their foreign policy.

“Disinformation for hire’ will continue to be a growth industry. The Oxford Internet Institute identified 48 countries in which the state had partnered with private ‘strategic communications’ firms to spread “computational propaganda” and use bots to create the impression of trending political messaging.

Russia and China are very likely to step-up up their disinformation activities on a larger scale then ever, using state actors and private companies.

Facebook

Facebook whistle-blower Frances Haugen gave the world a better view of the inside of Facebook and whether they ‘care’ about stopping misinformation from spreading on their platform.

However various governments are putting more pressure on Facebook to take their responsibilities more seriously and invest more money in blocking all kinds of misleading or illegal content.

If you have any experiences with these scams do let me know, by email.

Fightback Ninja Signature

Valentine’s Day Scams

Many scammers try to take advantage of holidays, events or anything in the news and Valentine’s Day is a big target for them.

Scam #1: Valentine’s Day E-Cards

There’s always lots of ads for electronic cards (e-cards) and especially around public holidays. If you want to try sending such cards – it’s better to find a website yourself rather than clicking on an advert.

If you receive what seems to be a Valentine’s e-card then be careful as many are created by scammers and sent out by the million. Rather than clicking the link to see the e-card – hover your cursor over the link and see if it does link to the website you expect. If it does then go to the website (do not click the link) and see if there is a card waiting for you. This doesn’t guarantee the e-card is safe but does exclude most forms of the scam.

Scam #2: Valentine’s Gift Cards

A Valentine’s gift card may seem a good idea and the adverts try to convince you they are the safest way to please someone.

But many are scams so beware inputting any confidential details and paying online. Make sure the site is a reputable one.

Scam #3: Buying Flowers Online

If you look on the Internet there are many choices of flower shop offering to deliver the perfect Valentine’s day surprise, but there are also pop up scam flower shops. Many offer beautiful bouquets at amazing prices (photos copied from a legitimate site of course) and some are taken in by this.

Always pick a reputable seller – preferably with well-known bricks and mortar branches around the country or at least one that has been around for some time and built a good reputation.

Scam #4. Online Dating

For some, this is a time to turn to online dating to look for the right partner. There is a huge array of websites and APPS offering to find your Mr Right or Miss Right, but there are also many new such sites and APPS appearing all of the time. Many of these are legitimate and do a good job but some are scam sites simply looking for confidential information and your credit card details.

Choose a site or APP that has a good reputation rather than a bargain offer.

Once in the world of online dating there are many scammers who post fake profiles and try to hook up with a number of people. They create very appealing profiles but their intention is to form a bond very quickly then start to get money from you – maybe a small gift or help to pay translation costs or money to visit you.

These people will likely research you online by looking at any profiles and posts on social media so they can see what you would like and use that to entice you further into a relationship.

If someone you have never met professes undying love for you then it’s going to be a scam.

Scam #5. Social Media Posts

Posting romantic moments on social media is very popular this time of year – but be careful before you click on any poems, letters , quizzes, surveys etc. directed to you on social media.

APPS on Facebook and other sites are not necessarily as safe as you expect, especially not just because they are about romance.

Stay safe.

Do Share this post on social media – click on the post title then scroll down to the social media share buttons.

Fightback Ninja Signature