Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: JayCoin on May 04, 2016, 01:19:55 AM



Title: Ransomware Cerber Decryptor - Follow the coins
Post by: JayCoin on May 04, 2016, 01:19:55 AM
A local small business was infected with the ransomware, Cerber Decryptor.  I sent the coins for them and they were able to decrypt their files.  The address the coins were sent to was 14rKSWF7qQquUWHfmEHzCod71jB4SsVS6B

Beware if you receive coins that originate from this address as they are from a criminal activity.  If anyone can eventually identify these people or person, please turn them in to authorities.

Thanks



Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: ebliever on May 04, 2016, 01:33:04 AM
Have you reported this to authorities? I'm not familiar with any specifics, but hopefully there is somebody out there - either law enforcement or white hat hackers - who is compiling and maintaining a list of addresses like this to be monitored on an ongoing basis. I'd suggest looking into that.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: JayCoin on May 04, 2016, 01:41:05 AM
Have you reported this to authorities? I'm not familiar with any specifics, but hopefully there is somebody out there - either law enforcement or white hat hackers - who is compiling and maintaining a list of addresses like this to be monitored on an ongoing basis. I'd suggest looking into that.

I have not as I was not the victim of the crime.  I suggested that the small business report it to authorities, but I doubt local law enforcement will be able to do much about it.  They may pass it along to the fed, but a $600 crime will probably not land high on their radar.

I will check to see if anyone is compiling a list of transactions involved in ransomware crime.

Thanks


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: 7788bitcoin on May 04, 2016, 02:28:53 AM
The coins has been moved to another address 

I just we all need to backup our important data/files in case we accidentally got hit by these ransomwares...


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: DannyHamilton on May 04, 2016, 02:59:07 AM
A local small business was infected with the ransomware, Cerber Decryptor.  I sent the coins for them
- snip -

Have you reported this to authorities?
- snip -
I have not as I was not the victim of the crime.
- snip -

If you happen to be in the U.S., you may want to be aware that others have been arrested for supplying bitcoins for ransomware payment and failing to file a Suspicious Activity Report (SAR) (https://www.fincen.gov/whatsnew/html/sar_faqs.html) with the Financial Crimes Enforcement Network (FinCEN) (https://www.fincen.gov/)


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: Wendigo on May 04, 2016, 06:51:11 AM
Perhaps you can report the ransomware incident to Blockhain crime experts like Elliptic but if the theft was really for just $600 I don't think it will be worth it because whoever is going to investigate this will ask for more money than that in fees probably. The business owners should still report it to the police though even if it was an extortion for a small amount of money.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: unamis76 on May 04, 2016, 07:18:48 AM
Beware if you receive coins that originate from this address as they are from a criminal activity.

People who might receive funds originating from this address might have no relation to these criminals and what they do... We all eventually have coins originating from less legal activities, like we have fiat coins and bills originating from non-legit activity.

It would also be interesting to submit files related to these viruses to antivirus companies, if they can be found among decryption warnings... (not sure if this variant is reversed yet)


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: DimensionZ on May 04, 2016, 07:30:41 AM
That is really bad and I don't condone online extortions but I think the police won't catch these criminals because $600 is too small of a sum for them to initiate any serious investigation. Maybe if some Bitcoin vigilantes help you track the transaction back to the criminals you could possibly locate their whereabouts but this is a really difficult task to do.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: SebastianJu on May 04, 2016, 08:34:53 PM
It's not really possible to get your coins back. Those are pros. They know how to vanish with the coins without traces.

You can't prove anything when they are moved some steps.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: Chris! on May 05, 2016, 01:52:09 AM
I know a small business owner that didn't pay the ransom. The hackers only gave them 48h to send 1BTC which at the time was worth about $300CAD. They didn't send any for 2 reasons: they didn't have any Bitcoins / couldn't get any and they had heard from others that had paid that their files were never released anyways. Hopefully these people slop up at some point.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: tobacco123 on May 05, 2016, 02:34:16 AM
These are negative publications of bitcoin, a disgrace to the bitcoin community. I hope people stop feeding them.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: Kakmakr on May 05, 2016, 06:09:50 AM
These are negative publications of bitcoin, a disgrace to the bitcoin community. I hope people stop feeding them.

The media just highlights these events because it has something to do with Bitcoin. Before Bitcoin these people used wire transfers and other payment methods and it hardly made the news. Also be aware that people can post any address on the internet and claim it has had something to do with crime. If they do not post evidence showing that the criminal asked for funds being send to that address, it is still just a normal Bitcoin address.

If this is a real address linked to Ransomware, it would serve no purpose. These people push those coins through anonymous mixer services and you will not be able to follow it. In some countries you might be able to subpoena these services to give up the information, but the chances of success is very slim. 


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: pedrog on May 05, 2016, 10:57:18 AM
I've recently examined a machine that got hit with Cerber Ransonware and was able to retrieve successfully a lot of files with data recovery software.


If you're lucky the files you need may still be intact.


Title: Re: Ransomware Cerber Decryptor - Follow the coins
Post by: ebliever on May 05, 2016, 12:34:26 PM
Coindesk has an article today that may be very relevant for the OP:

http://www.coindesk.com/anthony-murgios-lawyer-argues-for-change-of-law-during-regulatory-panel/