{"id":83422,"date":"2016-09-14T15:06:32","date_gmt":"2016-09-14T09:36:32","guid":{"rendered":"https:\/\/blogs.quickheal.com\/?p=83422"},"modified":"2016-09-14T15:20:42","modified_gmt":"2016-09-14T09:50:42","slug":"alert-ransomware-is-being-spread-through-the-ammyy-admin-website","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/alert-ransomware-is-being-spread-through-the-ammyy-admin-website\/","title":{"rendered":"Alert! Ransomware is Being Spread through the Ammyy Admin Website"},"content":{"rendered":"<p>This is a precautionary advisory for users who frequently visit the website of the popular remote desktop sharing software called Ammyy Admin.<\/p>\n<p>Quick Heal Labs has observed that a new variant of the <strong>Cerber3 Ransomware<\/strong> is being spread through the Ammyy Admin software on the official Ammyy Admin website. This news, however, is not surprising as this website has been found to host malware on several other instances. In a previous case, the website was found to spread the notorious <strong>Cryptowall 4.0 Ransomware<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-83423\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2016\/09\/Ammyy.png\" alt=\"ammyy\" width=\"711\" height=\"380\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/09\/Ammyy.png 1224w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/09\/Ammyy-300x160.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/09\/Ammyy-768x410.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/09\/Ammyy-1024x546.png 1024w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/09\/Ammyy-789x421.png 789w\" sizes=\"(max-width: 711px) 100vw, 711px\" \/><\/p>\n<p style=\"text-align: center;\">Fig 1 Ammyy Admin official website<\/p>\n<p>The Quick Heal Threat Research and Response Team recently observed increased cases of Cerber ransomware infections wherein the victims had downloaded and run the Ammyy Admin software from the original website. And our analysis of the malware found these observations to be true.<\/p>\n<p>A technical analysis of the ransomware is available in this downloadable PDF.<\/p>\n<p><a href=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2016\/09\/CERBER_RANSOMWARE.pdf\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-82869 alignleft\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2016\/05\/PDF-icon.png\" alt=\"PDF icon\" width=\"76\" height=\"77\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/05\/PDF-icon.png 256w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/05\/PDF-icon-150x150.png 150w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/05\/PDF-icon-70x70.png 70w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/05\/PDF-icon-80x81.png 80w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2016\/05\/PDF-icon-45x45.png 45w\" sizes=\"(max-width: 76px) 100vw, 76px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>How Quick Heal helps<br \/>\n<\/strong><a href=\"https:\/\/www.quickheal.co.in\/home-users\/quick-heal-total-security\" target=\"_blank\">Quick Heal Web Security<\/a> feature proactively detects and blocks websites on the basis of their malicious reputation and inconsistency in delivering actual applications.<\/p>\n<p><strong>How to Stay Safe from the Cerber Ransomware?<br \/>\n<\/strong>\u2022 Avoid visiting the Ammyy Admin website.<br \/>\n\u2022 Remove the Ammyy Admin software if you have it on your computer.<br \/>\n\u2022 Do not respond to unknown or unwanted emails that urge you to click on links or download attachments, no matter how urgent such emails might sound.<br \/>\n\u2022 Run an antivirus software that detects and blocks infected websites and emails with malicious content.<br \/>\n\u2022 Take regular backups of your important files. Remember to disconnect the Internet when you are backing up on a hard drive. Unplug the drive before you go online again.<br \/>\n\u2022 Apply all recommended security updates (patches) to your Operating System, programs like Adobe, Java, Internet Browsers, etc. These updates fix security weaknesses in these programs and prevent malware from exploiting them.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #666666;\">ACKNOWLEDGMENT<\/span><\/p>\n<p>Subject Matter Experts<br \/>\n\u2022 Shantanu Vichare<br \/>\n\u2022 Dipali Zure<br \/>\n&#8211; Threat Research and Response Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a precautionary advisory for users who frequently visit the website of the popular remote desktop sharing software called Ammyy Admin. Quick Heal Labs has observed that a new variant of the Cerber3 Ransomware is being spread through the Ammyy Admin software on the official Ammyy Admin website. This news, however, is not surprising [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":83426,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[965,910,5],"tags":[1357,50],"class_list":["post-83422","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-adware","category-ransomware","category-security","tag-ammyy-admin","tag-ransomware"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/83422"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=83422"}],"version-history":[{"count":7,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/83422\/revisions"}],"predecessor-version":[{"id":83433,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/83422\/revisions\/83433"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/83426"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=83422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=83422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=83422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}