
CryptoWall
Essential Information to Protect your Business
CryptoWall – You may have seen it on the news, on social media, or simply heard about it in passing. You may have also heard it mistakenly called CryptoLocker or CryptoDefense – but these are two similar, nearly extinct, forms of ransomware.
Ion Networking is strongly recommending, in addition to business-class endpoint protection software, the use of our CryptoWall prevention software.
Ion Networking has a partner pricing plan that allows us to offer you CryptoWall prevention, with lifetime updates, for $10 per PC plus installation time. Installation time may vary, but we estimate that we can install our CryptoWall prevention solution onto 10 PCs per hour.
This does not guarantee that you will be 100% protected, but we have seen a 95% reduction in CryptoWall infections when this software is used in conjunction with your business-class endpoint protection software (Ion Networking is recommending SOPHOS Cloud Endpoint Protection).
Please call your Ion Networking technician or our main number 207-318-7609 for more information.
So what is CryptoWall? Why should you be worried about it? And how does it affect your business?
This article will answer these questions and more. Read on to learn more about one of the most powerful and prolific computer viruses to ever be released.
What is CryptoWall?
Simply put, CryptoWall is a file-encrypting ransomware program that was originally released around the end of April 2014. It targets all versions of Windows including XP, Vista, 7, 8, and 10. It can also be carried by a Mac and infect other computers on a network, but there have, so far, been no confirmed cases of the virus successfully running on a Mac. Files and folders shared from a Mac to a mixed network, however, can be encrypted by the virus running on a Windows PC.
CryptoWall is currently distributed in version 4.0, but there are still lingering 2.0 and 3.0 infections spreading around the globe. Each version is essentially an enhanced version of the previous virus. This makes each successive release more powerful, harder to detect, and subsequently harder to prevent.
How Does CryptoWall Work?
Essentially, the main events that take place in the infection phase are as follows:
- The infection starts with an email received by the target of the attack. The email will contain either a link to a compromised web site or an email attachment directly containing the virus.
- When the potential victim clicks on the link or opens the attachment the following occurs:
- The link places an invisible downloader on the now infected system which connects to several different servers where it can then download the CryptoWall virus. Once downloaded, CryptoWall is invisibly installed on the victim’s PC
- The attachment is opened, which invisibly installs CryptoWall on the victim’s PC.
- CryptoWall sends an encrypted message to a different server where it obtains an encryption key.
- CryptoWall proceeds to encrypt files on the victim’s PC using the encryption key it obtained in the previous step.
- Once encrypted, files cannot be accessed.
- CryptoWall 4.0 encrypts both the file and the file name.
- Once all of the files are encrypted, a warning is presented on the screen with instructions on how to pay for the decryption key.
Why should I worry about CryptoWall, and how does it affect my business?
Once CryptoWall encrypts your data, there’s not much you can do. The encryption is very strong and most likely, unbreakable.
Network Security End-User Training
With everything from the Crypto Virus to Phishing attacks & credit card theft, critical data is very vulnerable: to theft & destruction. Most of these things can be prevented by 2 simple things: 1. End-user awareness training 2. Network system vulnerability testing and remediation.We offer both! We can launch a simulated phishing attack on the people in your company and see how well your users respond to phishing attempts. We offer education and training on how to detect these attacks and not fall victim to them.
Your data is at risk! 95% of all successful attacks involve human error…
Cost of Phishing Attacks?
The average 10,000 employee company spends $3.7 million a year dealing with phishing attacks, according to a new report from the Ponemon Institute.More Than You Think!
The report, which surveyed 377 IT professionals in companies ranging in size from less than 100 to over 75,000 employees, showed that about half of the costs were due to productivity losses.End-User Awareness Training: INCLUDES
Simulated Phishing Attack / Education and Training / Phishing ReassessmentCONTACT US TO SCHEDULE YOUR TRAINING
207-318-7609
The only options you have to access your data are:
- Remove all of the encrypted files from your system and restore the infected files from a recent backup
- Pay the ransom and get a decryption key.
- Please note that paying the ransom does not guarantee that you will get the decryption key or that an obtained decryption key will work.
- Ion Networking does not recommend paying the ransom.
If your business is infected with CryptoWall:
- The worst case scenario is that you will lose all data on mapped (server) drives and all data on the infected computer or computers.
- Without backups, you may need to pay the attackers to obtain a decryption key – this will cost up to $1500 to obtain the key and several days of lost productivity while payments are processed and the decrypt key is sent to you.
- The best case scenario is that you have recent backups and can restore all data from the backup, resulting in several hours of lost productivity, but no major loss of data.
- With a myriad of backup solutions on the market today, it’s hard to determine which is the best solution for your business. Ion Networking can help you determine the best solution and can provide full implementation support for the solutions we provide.
How can I prevent Infection and how can Ion Networking Help?
While there is no 100% solution to preventing a CryptoWall Infection, there are several things that can be done to mitigate your chances of infection.
The best method of prevention is user education:
- Don’t access links in e-mails from people you don’t know and don’t open attachments in emails you aren’t expecting. These are the main methods for spreading CryptoWall.
- Don’t click links in e-mails you receive from unknown e-mail addresses.
- Don’t allow access to personal email, social networking, and malicious sites on your network
- Ion Networking has a user education presentation specifically designed around the deployment methods most commonly used by CryptoWall.
Make sure your security solution detects and blocks CryptoWall.
- Verify you have a supported Firewall or UTM device with the most current firmware.
- Keep your anti-virus and anti-malware software up to date
- Ion Networking has several security solutions – from endpoint protection to Unified Threat Management devices – that are automatically updated to provide protection against CryptoWall.
Keep your Windows and vital software updated with the latest security patches.
- Download and install all security patches provided by Microsoft and your individual software vendors (Adobe, Autodesk, Sage, Oracle (Java), Google (Chrome), etc.)
Good backups are your best protection if you are infected
- Ion Networking has several backup solutions for your business – ask us to help you decide what the best backup solution is to protect you and your data.
