16 Senators and Staff In Pennsylvania Locked Out Of Their Systems By Ransomware

Ker-Splat!

This happened to the Pennsylvania Senate Democratic Caucus on Friday and the website is still down as of the time of this post on Monday morning. This can’t be a fun day over there. As of Friday, Pennsylvania Democrats spokeswoman Stacey Witalec said, “At this point we are working with Microsoft to see where we’re at.”

Odds are, it was a phishing email some poor unsuspecting staffer clicked on. This is a good time to take them from unsuspecting, to a healthy level of paranoia by training them about the threat.

 

 

Mystery Shopper Email Scams – Yeah, They Still Happen

It’s important that we help educate others that these scams do still happen. Lower income, unemployed and retired people are especially prone to this sort of scam. It sounds like easy money, and even appeals to the undercover 007 type in most of us, but it can do a number on your bank account.

Key thing to remember is, if someone sends you a check and asks you to send the change, it’s a scam. This doesn’t matter if it’s a car purchase on ebay or craigslist, or anything else, don’t do it. Checks can take a long time to clear, or be found to be fake, and you are held holding the bag.

Mystery shopping is the SCAM OF THE WEEK here at KnowBe4, and there is some good info on what to look for, and something you can copy/paste for friends and family. Check it out.

 

My 2016 Unemployment Diaries Recap – Day 12 to Day 14. More to follow

Please note, this is a reposting of some previous entries made in 2016 when my position was eliminated and I found myself unexpectedly unemployed. This is being reposted here simply for the purpose of preservation as I am not maintaining the old site much. In any case, enjoy if you feel like reading it:


Day 12 of unemployment – Arizona Football and Wal-Mart Bathrooms

Day 12 of unemployment – This is a small update, and for this, I’m going to have to take it back to the previous night. You see, there was this football game. This game you see, pitted my Arizona Cardinals against the Green Bay Packers and was for moving ahead in the post-season. This game started at 8:30pm Florida time, it ended late. I mean really late. On top of that, it was a great game. One of those “did you see the game?” games. This was full of crazy plays, including an almost impossible “hail mary” and a coin flip where the coin did not actually flip. Couple this is a night full of storms, and bammo, not much sleep.

On a plus note, we were able to spend some quality time with the chicken-dog when the thunder happened. Oh, yeah!

That made my 0800 call time at church where I was working as the Producer, a bit of a challenge. I don’t think I really woke up until halfway through the 2nd service. No one seemed to notice so all was well. I was happy to realize that at least I was wearing pants.

Other than that, I spent most of the day working a firearm trade and eating various things. Overall, a day well spent.

Oh, a message to my fellow male people. When you are using a public toilet, please lift the lid before you pee in (or on) the toilet. This was even low for Wal-Mart standards. Not cool. Seat, UP, Leave it if you must, I won’t complain.


 

 

 

Yukon Public Schools Hit With Data Breach

And again I find myself reporting on a W2 scam. This time, It’s Yukon Public Schools that fell for a phishing scam and emailed W2’s to scammers.  Superintendent Dr. Jason Simeroth said the email looked like it was sent from him, then later in the story it was mentioned that it was spoofed from an AOL email address. Really? AOL in this day and age? This is twice today I have heard of people using AOL email. I really thought it was dead.

Kids, today’s lesson is, if you are handling sensitive information or transferring money, you might want to pick up the phone BEFORE you hit send. Just sayin.

 

 

 

#MHN, #kippo and #Dionaea still cooking along. Now to capture binaries…

So, I’ve been playing with Kippo and Dionaea using the Modern Honey Network (MHN) tool and having some fun with it. At this point, I’m going to reload my Kippo box at home and deploy it with Dionaea as well rather than WordPot. I like being able to see the different types of attacks on FTP and HTTP, but I’m having some trouble with the config.

Currently, FTP will make a connection, but fails to send a directory listing. Likewise, I am not capturing any binaries right now. I tried making the folder wide open (777 & nobody:nogroup) but still no luck. If you have any ideas, let me know please. I want to start playing with captures. In the meantime, my pew pew map is about done collecting sources now. Few of the attacks come from a new place now.

 

Pew Pew Pew!

 

Mucho attacks, no binaries captured. I do have pcap’s, but I want some malware files! 🙂

 

TorrentLocker (aka Cryptolocker) is back and farming credentials as well.

After taking some time off, Cryptolocker appears to be back in a very aggressive campaign, and it has some new ‘features’. It’s sent via Word docs with a PowerShell script, infects and spreads via shared files, and it’s also grabbing credentials as well.

Right now it appears to be targeting Europe, especially Italy, but we need to keep our eyes open regardless of where we live.