{"id":109,"date":"2016-11-17T19:40:24","date_gmt":"2016-11-18T01:40:24","guid":{"rendered":"http:\/\/pcmdx.net\/blog\/?p=109"},"modified":"2016-11-17T20:12:25","modified_gmt":"2016-11-18T02:12:25","slug":"ransomware-being-distributed-as-fake-adobe-flash-player-update","status":"publish","type":"post","link":"http:\/\/pcmdx.net\/blog\/2016\/11\/17\/ransomware-being-distributed-as-fake-adobe-flash-player-update\/","title":{"rendered":"Ransomware being distributed as fake Adobe Flash Player Update"},"content":{"rendered":"<p>Ransomware is some of the most destructive malware in the cyber world.<\/p>\n<p><a href=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/cyber-security-1784985_640.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-119 aligncenter\" src=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/cyber-security-1784985_640-300x218.png\" alt=\"cyber-security-1784985_640\" width=\"300\" height=\"218\" srcset=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/cyber-security-1784985_640-300x218.png 300w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/cyber-security-1784985_640.png 640w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>For those not familiar with it, ransomware is software that will encrypt all of your documents, photos, music, and other types of files, then demands a ransom in order to get them decrypted. \u00a0Normally there&#8217;s a time limit in getting sending the ransom.<\/p>\n<p>A complete description of how ransomware works can be found in this <a href=\"http:\/\/Ransomware: Time to Pay Attention or Pay Big Bucks\" target=\"_blank\">PCMDX Blog post<\/a>.<\/p>\n<p>The bad guys are always looking a new ways to take advantage of computer users, <a href=\"http:\/\/www.bleepingcomputer.com\/news\/security\/locky-ransomware-being-distributed-through-fake-flash-player-update-sites\/\" target=\"_blank\">but this latest attack is worth taking a look at<\/a> because it&#8217;s one of the more legitimate looking attacks.<\/p>\n<p>In the past, we&#8217;ve warned you to look at the page for grammar and spelling errors, as well as phrases that don&#8217;t sound right, before clicking on any links. \u00a0The majority of the attacks originate in other countries where English is not the native language. \u00a0Because of that, the bad guys sometimes resort to <a href=\"https:\/\/translate.google.com\/\" target=\"_blank\">Google Translate<\/a> to write their web pages and programs. \u00a0Google Translate can sometimes have some flaws in how it translates, especially when it comes to technical terms.<\/p>\n<p>The latest ransomware attack is a perfect example of this. \u00a0You may click on a link that takes you to a page like this:<\/p>\n<div id=\"attachment_112\" style=\"width: 1060px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update_test.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-112\" class=\"wp-image-112 size-full\" src=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update_test.png\" alt=\"fake-flash-player-update_test\" width=\"1050\" height=\"736\" srcset=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update_test.png 1050w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update_test-300x210.png 300w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update_test-768x538.png 768w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update_test-1024x718.png 1024w\" sizes=\"auto, (max-width: 1050px) 100vw, 1050px\" \/><\/a><p id=\"caption-attachment-112\" class=\"wp-caption-text\">Fake Adobe Flash Player update page. (click for larger image)<\/p><\/div>\n<p>&nbsp;<\/p>\n<p>For the most part, this page\u00a0<em>looks<\/em> legitimate to most users. \u00a0But there are two obvious errors, and one not so obvious, that should warn you immediately that it&#8217;s fake, and possibly a threat.<\/p>\n<p>First, look at the instructions for &#8220;1.&#8221;. \u00a0You&#8217;ll see it instructs you to locate a file <em>&#8220;named like&#8221;<\/em>. \u00a0An obvious grammar error.<\/p>\n<p>Second, look at the URL (the web site). \u00a0<em>http:\/\/ fleshupdate. com<\/em> &#8230;flesh is not flash. \u00a0The not-so-obvious error is the phrase that reads &#8220;Your Flash Player may be out of date&#8221;. \u00a0Adobe products will not use the term &#8220;may&#8221;. \u00a0It&#8217;s either out of date or it&#8217;s not.<\/p>\n<div id=\"attachment_111\" style=\"width: 970px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-111\" class=\"wp-image-111\" src=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update-1024x718.png\" alt=\"Fake Adobe Flash Player update page with errors highlighted.\" width=\"960\" height=\"673\" srcset=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update-1024x718.png 1024w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update-300x210.png 300w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update-768x538.png 768w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/fake-flash-player-update.png 1050w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/a><p id=\"caption-attachment-111\" class=\"wp-caption-text\">Fake Adobe Flash Player update page with errors highlighted. (click for larger image)<\/p><\/div>\n<p>&nbsp;<\/p>\n<p>The Adobe Flash Player update page is https:\/\/get.adobe.com\/flashplayer\/<\/p>\n<p>The &#8220;https&#8221; means that it&#8217;s coming from a secure site.<\/p>\n<p>You&#8217;ll notice there&#8217;s much more information on the update page.<\/p>\n<div id=\"attachment_113\" style=\"width: 970px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/real_-flash-player-update_test.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-113\" class=\"wp-image-113\" src=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/real_-flash-player-update_test-1024x614.png\" alt=\"real_-flash-player-update_test\" width=\"960\" height=\"576\" srcset=\"http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/real_-flash-player-update_test-1024x614.png 1024w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/real_-flash-player-update_test-300x180.png 300w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/real_-flash-player-update_test-768x461.png 768w, http:\/\/pcmdx.net\/blog\/wp-content\/uploads\/2016\/11\/real_-flash-player-update_test.png 1172w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/a><p id=\"caption-attachment-113\" class=\"wp-caption-text\">Authentic Adobe Flash Player update page (click for larger image)<\/p><\/div>\n<p>&nbsp;<\/p>\n<p>For clients who have PCMDX do their IT support, <strong>you&#8217;ll never see the Adobe Flash Player update page<\/strong>, as we have it set to update in the background. \u00a0If you do see an update page, it&#8217;s absolutely fake, and you should not click on any links.<\/p>\n<p>Please share this information with everyone who uses your computers. \u00a0Once ransomware infects your system, there&#8217;s no reversing it unless you pay the ransom, which is rather costly, both in money and time. \u00a0Since ransomware is constantly evolving, most anti-virus products will not protect you from the damage.<\/p>\n<p>The best way to prevent getting struck by ransomware is to follow these guidelines:<\/p>\n<ul>\n<li>Never open attachments from unknown senders or known senders where the message is vague. \u00a0If in doubt, contact the sender to verify they sent it.<\/li>\n<li>Always keep you system up-to-date and patched<\/li>\n<li>Although anti-virus products may not protect against ransomware, they do protect against other malware, so always have your AV product installed and up-to-date.<\/li>\n<li>BACK UP YOUR DATA. \u00a0We recommend a three step backup program, which includes imaging, data, and off-site. \u00a0The three combined are optimal, but have at least one.<\/li>\n<\/ul>\n<p>PCMDX can assist you with all of these items. \u00a0We specialize in providing cybersecurity and computer support for Small-Medium Businesses that have under 15 PCs and don&#8217;t have the budget for a full time IT person, but want IT level support.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware is some of the most destructive malware in the cyber world. For those not familiar with it, ransomware is software that will encrypt all of your documents, photos, music, and other types of files, then demands a ransom in order to get them decrypted. \u00a0Normally there&#8217;s a time limit in getting sending the ransom. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":119,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,33],"tags":[45,47,46],"class_list":["post-109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-protection","category-ransomware","tag-fake-flash-player-update","tag-flesh-com","tag-ransomware"],"_links":{"self":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts\/109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/comments?post=109"}],"version-history":[{"count":2,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts\/109\/revisions"}],"predecessor-version":[{"id":121,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/posts\/109\/revisions\/121"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/media\/119"}],"wp:attachment":[{"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/media?parent=109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/categories?post=109"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/pcmdx.net\/blog\/wp-json\/wp\/v2\/tags?post=109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}