Protect yourself from ransomware

It’s still big business for crooks, most of whom have switched from the “Nigerian Prince” letters because it’s a far easier way of generating money.


An employee gets an official-looking email about an invoice or a spreadsheet. They click on the link. Boom: all your data is encrypted, and you have to pay 2 Bitcoin (about $1,500.00) to get it back (and sometimes you don’t.) You lose business, and the ultimate cost ends up being much higher.

There are two main lines of defense against ransomware: Backup and Education

1 – Backup

If you’re not backing up your files, you’re vulnerable to data loss, which can cost you big time.  Many people back up their files manually to an external drive. And that’s good, but there are problems with this system.

  • It’s hard to remember what files have been modified on any given day
  • It’s easy to forget to do your backup
  • A local disk is susceptible to theft or damage, or can fill up.
  • You can actually back up corrupted files if you’re not aware of when the infection took place. The nasty thing with many ransomware viruses is that they start to encrypt your files, and only give you the popup warning after the process is complete.

I recommend a cloud-based, dynamic backup system; I use Carbonite™ (and I’m not a paid shill for the company.) For the roughly 11¢ per day that the service costs me, I do whatever I need to on my computer and sleep well at night, knowing that if there’s a disaster of any sort – ransomware, hard drive crashes, fire, theft, you name it – I can get my critical data back. I once had a hard drive crash without backup, and it cost me over 3 grand to have a forensic data specialist retrieve my files (a ripoff, Seagate would have done it for half the price, but that’s another story.)

2 – Education

Educate yourself, and educate your friends, family, and employees. People click on things without thinking, and that’s never been good computing practice. It’s more important than ever to be careful about links contained in emails.

Have a look at this selection of emails that I received just this week:

Subject: Payment Information

Good afternoon. Thank you for sending the bill.
Unfortunately, you have forgotten to specify insurance payments.
So, we cannot accept the payment without them.
All details are in the attachment.

Subject: E-Mailed Invoices Invoice_6F839240

Please find attached your latest purchase invoice.
Any queries with either the quantity or price MUST
be notified immediately to the department below.
Yours sincerely, Sales Ledger Department
Tel: +44 (0) 4215 189 115

Subject: Urgent

Our accountant informed me that in the bill you processed, the invalid account number had been specified.
Please be guided by instructions in the attachment to fix it up.

Subject: Urgent Alert

We have detected a suspicious money ATM withdrawal from your card.
For your security, we have temporarily blocked the card.
All the details are in the attachment. Please open it when possible.

Subject: Delivery status

Dear Client! Our delivery department could not accept your operation due to a problem with your current account.
In order to avoid falling into arrears and getting charged, please fill out the document in the attachment as soon as possible and send it to us.

Subject: Invoice for 893547 21/11/2016

This email confirms that your goods have been dispatched. Please find attached your Invoice in PDF format. Please note this document will only be sent in electronic form.

Subject: Attention Required

Our HR Department told us they haven’t received the receipt you’d promised to send them.
Fines may apply from the third party. We are sending you the details in the attachment.

Please check it out when possible.

Subject: E-Mailed Invoices Invoice_CE576080

Please find attached your latest purchase invoice.
Any queries with either the quantity or price MUST
be notified immediately to the department below.
Yours sincerely, Sales Ledger Department
Tel: +44 (0) 5458 175 571

Subject: Please Pay Attention

Greetings! Informing you that the contractor requires including VAT in the service receipt.
Sending the new invoice and payment details in the attached file.
Please open and study it as soon as possible – we need your decision.

Subject: Insufficient funds

Dear info,
Your bill payment was rejected due to insufficient funds on your account.
Payment details are given in the attachment.

Subject: Important Information

Dear info, your payment was not processed due to the problem with credentials.
Payment details are in the attached document.
Please check it out as soon as possible.

Subject: Please Pay Attention
Dear info, we have received your payment but the amount was not full.
Probably, this occurred due to taxes we take from the amount.
All the details are in the attachment – please check it out.

Subject: Please note

Your tax bill debt due date is today. Please fulfill the debt.
All the information and payment instructions can be found in the attached document.

Subject: Urgent

Dear Client! We have to inform you that payments for contractors’ services were insufficient.
Thus, we are sending the report and the amount details in the attachment.

Subject: Order #9406386

Dear info, sending the receipt for the order #9406386.
You made it last week. Please check it out as soon as possible.
The receipt with all info is in the attached file.

Every single one of these came with zip file as an attachment. And every single one would have downloaded ransomware to the computer of anyone who was careless enough to open the file.

There are some red flags here:

  • My company address is “”, and most of these emails start out as “Dear info.”
  • The English in many of these emails is unnatural or grammatically wrong.

And yet people will still open these emails, and still click the attachments. If businesses take data security seriously, every employee will be given training on how to recognize data threats.

Please be careful out there.

Order to Appear in Court

Nothing to see here, folks, just move along. Another scam email from fraudsters trying to get me to download malware to my computer.

This time the Javascript code wants to go out to,, and (all of which are invalid top-level domains), and then download and install other nasty stuff to my computer.

Here’s the email that this came attached to:

To: [edited]
Subject: Notice of appearance in Court #00928994

From: “District Court” <>

Notice to Appear,
You have to appear in the Court on the July 27.
Please, prepare all the documents relating to the case and bring them to Court on the specified date.
Note: The case may be heard by the judge in your absence if you do not come.
You can review complete details of the Court Notice in the attachment.
Jimmie Cowan,
Clerk of Court.
That "notice to appear" attachment is actually a JavaScript file

By looking at the text elements in quotes (things like “ironm”, “ttp:/”, “.Ru”, etc. it’s pretty easy to see that the whole purpose of this script is to concatenate instructions which will lead your computer to some Russian website and infest your machine with code from Hell. I’m not skilled in Javascript (or, more accurately, it would take me more time than it’s worth to decrypt this script,) so suffice it to say you don’t want this on your machine.

The email looks like it’s from FedEx. Some poor computer-illiterate secretary, or your grandmother, or cousin, or someone who just used FedEx would probably think it was legitimate, download the file, unzip it, double-click on it, and Bob’s your uncle.


Attachments from people you don’t know, particularly .zip or .rar, are to be assiduously avoided. Trash them at once.

Please be vigilant and take good care of yourself and your loved ones.

Practice Safe Computing!

This can’t be stressed enough, or repeated often enough. Just got an email today in my business account that looked like this:

Dear Sir/Madam,

The attached payment advice is issued at the request of our customer.

The advice is for your reference only.

Yours faithfully,
Global Payments and Cash Management


This is an auto-generated email, please DO NOT REPLY. Any replies to this email will be disregarded.

Security tips

1. Install virus detection software and personal firewall on your
computer. This software needs to be updated regularly to ensure you
have the latest protection.
2. To prevent viruses or other unwanted problems, do not open
attachments from unknown or non-trustworthy sources.
3. If you discover any unusual activity, please contact the remitter of
this payment as soon as possible.

This e-mail is confidential. It may also be legally privileged.
If you are not the addressee you may not copy, forward, disclose
or use any part of it. If you have received this message in error,
please delete it and all copies from your system and notify the
sender immediately by return e-mail.

Internet communications cannot be guaranteed to be timely,
secure, error or virus-free. The sender does not accept liability
for any errors or omissions.

Unfortunately, far too many people will be stung by a generic sounding email like this. “Wow, someone sent me money!” will be the initial response, and they’ll happily unzip and execute the attached “payment notice.”

Unfortunately that attached file is not a payment notice, but an executable file (a program) which will infect your computer with malware, adware, spyware, and heaven knows what else; turn your machine into part of a robotic network (a botnet) for spreading spam and viruses, search for passwords and sensitive financial data, encrypt all your files and demand a ransom to unlock them (this is a particularly nasty one), or any number of other unholy things.



If WordPress supported blinking text, I’d use that obnoxious tag too, just to make sure I had your attention.

Be especially wary of any file that ends in “.exe”. This is one of the basic rules of safe computing, but far too many people don’t know about it. One of the worst things Microsoft ever did was to suppress the display of file extensions by default, assuming people didn’t care or wouldn’t understand what they are for. As a result, far too many people are simply ignorant of the dangers inherent in clicking email attachments that could be programs. All they would see in the above message would be “ttcopy.”

Notice the ironic security warning in the body of the email itself: “To prevent viruses or other unwanted problems, do not open
attachments from unknown or non-trustworthy sources.” This is misdirection at its finest; people will be grateful for the warning, if they even bother to read it, and happily execute the malicious payload.


