Ransomware Masked as Rockwell Update

nhatsen

Member
Join Date
Oct 2010
Location
Argentina
Posts
686
A known rule is that you should never open an attachment which seems suspicious... especially if the attachment is Allenbradleyupdate.zip:

http://www.isssource.com/ransomware-masked-as-rockwell-update/

Rockwell Automation has learned about the existence of a malicious file called ‘Allenbradleyupdate.zip’ that is being distributed on the Internet. This file is NOT an official update from Rockwell Automation, and we have been informed that this file contains a type of ransomware malware...
 
Jeez, they are relentless with that stuff. I suppose it's an easy money maker, probably easier than trying to steal credit card or bank info.

I had a guy that I work with bring me his laptop which was infected with ransomware, a couple of years ago. I was able to fix it the first time without too much trouble. The 2nd time I couldn't. Lucky for him he was diligent about keeping backups. Now days it sounds like they are a lot more sophisticated.
 
My wife just got one on her email last night, telling her that Google was going to delete all of her photos unless she installed a new "Google.zip" file attached to the email. LUCKILY she asked me about it first! However the only reason she bothered asking me was because she remembered that we use Amazon's photo service, not Google's. I had to re-emphasize to her about NEVER opening attachments to emails unless you specifically ASKED for them from someone.
 
My wife just got one on her email last night, telling her that Google was going to delete all of her photos unless she installed a new "Google.zip" file attached to the email. LUCKILY she asked me about it first! However the only reason she bothered asking me was because she remembered that we use Amazon's photo service, not Google's. I had to re-emphasize to her about NEVER opening attachments to emails unless you specifically ASKED for them from someone.

I ended up switching my folks over to Linux due to their willingness to open anything in an email. Time and time again I would tell them assume that anything in an email is bad, but they don't always get it. "But it said that I had a virus so I had to click it".
 
I ended up switching my folks over to Linux due to their willingness to open anything in an email. Time and time again I would tell them assume that anything in an email is bad, but they don't always get it. "But it said that I had a virus so I had to click it".
This is what my father does. Parents shouldn't be trusted with anything more complicated than a Chrome Book or iPad. Something that can't be screwed up.
 
I got one today that spoofed my company's own domain server....It was from "[email protected]"...It spoofed the return address, header, hop path...hard to discern that it wasn't from me, other than I know I have no email called accounting. It had the message "Just received this from the IRS" and a IRS.DOC attachment.

Fortunately, I use mailwasher, so emails don't even get pulled into outlook without me approving them. I blasted that one right off network solutions server.
 
I ended up switching my folks over to Linux due to their willingness to open anything in an email. Time and time again I would tell them assume that anything in an email is bad, but they don't always get it. "But it said that I had a virus so I had to click it".

Lol, like my mom. Every few months these is an issue and my free tech support line gets a call and there is a bunch of whining on the other line. 🔨 *sigh*
 

Similar Topics

Hello, I am using a UDT to track status from two different indexing lines that merge into one. Essentially, one indexing line is the part, and...
Replies
17
Views
3,709
Hi guys I'm struggling to understand this function. I have an RFID reader that reads in LH and RH of a variant. The variant is set from the HMI...
Replies
13
Views
2,746
Hey I'm new to rs logic 5000 I have the basics but I'm getting confused with this mvm instruction. Can anybody bum it down for pls Thanx in advance
Replies
3
Views
4,886
The title pretty much sums it up, but to elaborate I am using a PanelView Plus 700 and Machine Edition. I want to have a numeric entry screen...
Replies
18
Views
9,392
So I'm using a 1769-L35E. I'm trying to move two INTS through Masked Move Instructions to create a DINT together. I'm fairly new to this so...
Replies
14
Views
6,778
Back
Top Bottom