This morning I saw various reports of a new type of Ransomware, masquerading as a fake Microsoft warning that your copy of windows is invalid. I had a quick check and was unsurprised to note that ThreatSTOP subscribers were already protected.
Although to be honest, when I say we block it, we stop you being tempted to pay €100 and probably having your credit card details nicked in the process. We may also stop machines from getting infected but that is less certain as there are various infection paths. However we are sure that we block the website where you have to pay - www.buylicens.com. This domain resolves to the IP address 22.214.171.124 which is in the Ukraine and also in a couple of our feeds - Spamhaus and the Russian Business Network. Hence users who either blocked Eastern Europe, the Ukraine specifically or use our Advanced block list wuld be protected.