{"id":87,"date":"2021-04-17T09:49:13","date_gmt":"2021-04-17T09:49:13","guid":{"rendered":"http:\/\/lamiyarahman.com\/?p=87"},"modified":"2023-03-17T14:47:02","modified_gmt":"2023-03-17T14:47:02","slug":"ransomware-attack-via-pen-drive-usb-flash-drive","status":"publish","type":"post","link":"https:\/\/lamiyarahman.com\/index.php\/2021\/04\/17\/ransomware-attack-via-pen-drive-usb-flash-drive\/","title":{"rendered":"Ransomware attack via pen drive (USB flash drive)"},"content":{"rendered":"\n<p class=\"has-primary-color has-text-color has-small-font-size\"><strong>Motivation: <\/strong>Md Mashihoor Rahman&nbsp;(IT Security Analyst)<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">Last 7th April I came to know about a ransomware attack at a well known company in Dhaka, Bangladesh. The attack occurred through a pen drive (USB flash drive).<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">On 6th April one of the graphics designers of that company took the pen drive to a local printing shop to get a job done. Till then there was an AI file to print out. But he said the AI file didn\u2019t open in that printing shop. Also, he said when he opened the pen drive folder in that shop, he found a readme file already was in that USB. So, he came back to office and connected that pen drive to his work computer where he had his 16 years of work to input his desire AI file again for printing.<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">When he inserted the USB flash drive, the computer gave an notification of virus detection but he ignored it. And that was his big mistake. The whole company had a paid antivirus for one year but it was also expired but nobody did not give attention on it. After opening the pen drive he noticed that all his computers file had get a .urnb extension and could not open any file with a readme.txt file. So, he tried to solve it by downloading an antivirus, reinstalling the window again but nothing could help him. It is really obvious that he had no clue what was happening and what it needs to get solved. Even he did not let the IT department know about this problem. On the next day (7th April) he told everybody about this. So, then the company consulted with a security professional but could not find any way to solve it and they lots every data of that computer.<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\"><strong>Lose:<\/strong> No financial loses. But the company lost his 16 years of works and designs.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong><span style=\"text-decoration: underline;\">Ransomware Details:<\/span><\/strong><\/h5>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\"><strong>Family<\/strong> &#8211; STOP\/DJVU ransomware<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\"><strong>Extension<\/strong> &#8211; .urnb<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">The URNB ransomware is a malicious program that encrypts the personal documents found on the victim\u2019s computer with the \u201c.urnb\u201d extension, then displays a message which offers to decrypt the data if payment in Bitcoin is made. The instructions are placed on the victim\u2019s desktop in the \u201c_readme.txt\u201d file.<\/p>\n\n\n\n<p class=\"has-text-color has-small-font-size\" style=\"color:#458edf\"><a href=\"https:\/\/malwaretips.com\/blogs\/remove-urnb-virus\/#:~:text=URNB%20is%20a%20file%2Dencrypting,exchange%20for%20access%20to%20data.\">Click here to know more about it<\/a>.<\/p>\n\n\n\n<p class=\"has-text-color has-small-font-size\" style=\"color:#4eb2ec\"><\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong><span style=\"text-decoration: underline;\">Recommendation:<\/span><\/strong><\/h5>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">10 Easy Steps on How to Fix Ransomware<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">Take note to only follow ALL these steps if you already lost access to your computer and cannot bypass the ransom note that is being displayed on your screen. If you still have access, you may directly proceed to step #7.<\/p>\n\n\n\n<ul>\n<li>Step #1: Restart Your Computer.<\/li>\n\n\n\n<li>Step #2: Press the F8 key while your computer is booting up.<\/li>\n\n\n\n<li>Step #3: Use the arrow keys to select the Safe Mode option on the screen.<\/li>\n\n\n\n<li>Step #4: Type rstrui.exe using the text cursor that appears on the screen<\/li>\n\n\n\n<li>Step #5: Press Enter.<\/li>\n\n\n\n<li>Step #6: In the Windows System Restore screen, choose a date and restore your computer to this point.<\/li>\n\n\n\n<li>Step #7: Using another device, download a reputable software tool that has the capacity to disable and delete ransomware attacks from your computer.<\/li>\n\n\n\n<li>Step #8: Copy the software installer file and install it on the ransomware-infected device.<\/li>\n\n\n\n<li>Step #9: Run a full scan.<\/li>\n\n\n\n<li>Step #10: Select all infections detected by the ransomware and delete them from your computer.<\/li>\n<\/ul>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">If you have a back copy of all your files, you can just conveniently copy them to the now ransomware-free device. But in an unfortunate event that you failed to make a backup copy, there are still few other options you can try to explore.<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">One is by using a software tool that can recover deleted files in your computer. During a ransomware attack, your actual files will be deleted by the malware and will be replaced by an encrypted replica. That gives you a chance to retrieve lost data by using a data recovery software.<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">Another tool you can use are online decryption tools that are being offered for free. Though a decryption tool cannot promise its users complete retrieval of all the ransomware-locked data, it will still give you a chance to decrypt at least some of the encrypted files.<\/p>\n\n\n\n<p class=\"has-primary-color has-text-color has-small-font-size\">Do not wait until a ransomware threat hits you. Protect your computer from the hazards and troubles ransomware attacks can cause. Be knowledgeable not only on how to fix ransomware vulnerabilities but also about how you can combat these malicious malwares in order to ensure the safety of your home and your business from cybercriminals.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Motivation: Md Mashihoor Rahman&nbsp;(IT Security Analyst) Last 7th April I came to know about a ransomware attack at a well known company in Dhaka, Bangladesh. The attack occurred through a pen drive (USB flash drive). On 6th April one of the graphics designers of that company took the pen drive to a local printing shop [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":213,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[6,5,7],"_links":{"self":[{"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/posts\/87"}],"collection":[{"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/comments?post=87"}],"version-history":[{"count":8,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/posts\/87\/revisions"}],"predecessor-version":[{"id":170,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/posts\/87\/revisions\/170"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/media\/213"}],"wp:attachment":[{"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/media?parent=87"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/categories?post=87"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lamiyarahman.com\/index.php\/wp-json\/wp\/v2\/tags?post=87"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}