Skip to main content

Ransomware: What is it, how it worked and how you can prevent and detect it

What is Ransomware?
Well from wikipedia we learnt that Ransomware is a type of malicious software that carries out the cryptoviral extortion attack from cryptovirology that blocks access to data until a ransom is paid and display a message requesting payment to unlock it. more of this you can read it throught here.

Where did ransomware originate?
The first documented case appearead in 2005 in the US, but quickly spread around the world

How does it affect a computer?
the software is normally contained within an attachment to an email that masquerades as something innocent. Once we opened it, it encrypts the hard drive, making it impossible to access or retrieve anything stored on there - such as work document, photographs, music, etc.

What are the steps to prevent the ransomware from attacking your computers?
1. enable automatic update in windows
2. create a backup of your important files
3. install a good antivirus software
4. install anti-ransomware products

How to prevent wannacry ransomware?
1. install the windows security patch MS170-010
2. disable SMB v1
3. do blocking for ports 139/445 and 3389

Is there any preventive monitoring software so we can detect ransomware?
Yes, there is.
products such as ExtraHop would be one of the one products that can detect ransomware since 2013 (if i'm not mistaken).
quote from ExtraHop website:
"WannaCry is propagating quickly around the globe ExtraHop customers should download the update ransomware bundle"

ExtraHop provide many Solution Bundles, on of the solution bundle is to detect ransomware; This bundle was updated on may 12, 2017 to detect Wannacrypt0r, wanna decryptor malware.
it will detect the *.WNCRY file extension and @Please_ReadMe@.txt ransom note. not only that the updated bundles also looks for unusual CIFS/SMB write activity indicative of any ransomware strain.

there are forums in ExtraHop community that provides this solutions

for other security preventive measurements; ExtraHop has "wire data for security"

youtube link for extrahop regarding ransomware and security:
https://www.youtube.com/watch?v=HnDoBq22dTs&t=87s
https://www.youtube.com/watch?v=VSM3DKGH82E&t=28s

that's all for now, hopes this helps

thanks to information provided by:
- en.wikipedia.com
- www.detik.com
- www.trishtech.com
- www.telegraph.co.uk
- www.extrahop.com
- www.youtube.com


Comments

Popular posts from this blog

Menginstall Nginx, MySQL, PHP on Ubuntu Bionic Beaver (18.04 LTS)

TAHAP I - INSTALL NGINX ns@ubuntu:~$ sudo apt install nginx TEST INSTALLASI NGINX ns@ubuntu:~$ curl http://ip_localhost TAHAP II - INSTALL MYSQL ans@ubuntu:~$ sudo apt install mysql-server ans@ubuntu:~$ sudo mysql_secure_installation Set password untuk mySql secure connection ans@ubuntu:~$ sudo mysql mysql> SELECT user,authentication_string,plugin,host FROM mysql.user; mysql>ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; dimana 'password' di set sesuai keperluan lalu cek lagi, mysql> SELECT user,authentication_string,plugin,host FROM mysql.user; TAHAP III - INSTALL PHP ans@ubuntu:~$ sudo apt install php-fpm php-mysql ubah cgi.fix_pathinfo dari 1 menjadi 0 di file php.ini ans@ubuntu:~$ sudo nano /etc/php/7.2/fpm/php.ini cgi.fix_pathinfo=0 restart service php: ans@ubuntu:~$ sudo systemctl restart php7.2-fpm KONFIG AGAR NGINX MENGGUNAKAN PHP PROCESSOR edit file def

Darkstat - Nework Traffic Analyzer atau Monitor Jaringan

Darkstat - Nework Traffic Analyzer atau Monitor Jaringan Apa itu Darkstat? Darkstat adalah pengumpul statistik jaringan. Secara efektif, ini adalah paket sniffer yang berjalan sebagai proses latar belakang pada Kabel / DSL router, mengumpulkan segala macam statistik berguna tapi menarik, Dan melayani mereka melalui HTTP. Fitur Darkstat Grafik lalu lintas Melacak lalu lintas per host. Melacak lalu lintas per port TCP dan UDP untuk setiap host. Embedded web-server dengan deflate compression. Asynchronous reverse DNS resolution menggunakan proses child. Kecil. Portable. Single-threaded. Efisien. Instalasi Darkstat di Ubuntu ~$ sudo Apt-get install darkstat Ini akan menyelesaikan instalasi. Setelah Anda menyelesaikan instalasi, Anda perlu mengedit file yang terletak di /etc/darkstat/init.cfg START_DARKSTAT = no menjadi START_DARKSTAT = iya Start darkstat  # / Etc / init.d / darkstat start Ini akan memulai proses darkstat Arahkan browser Anda di http:

Mount ISO image file on HP-UX

There are 2 ways to mount iso file in hp-ux 1) using LVM method (to copy ISO into a logical volume) is the same as for older HP-UX releases: 1. Find out the size of the ISO image: # du -k /data/myImage.iso NOTE: The size will be in Kb. 2. Create a logical volume for the ISO image: # lvcreate -L -n iso /dev/vg00 NOTE: The name of the logical volume will be /dev/vg00/iso 3. Copy the ISO file to the raw logical volume: # dd if=/data/myImage.iso of=/dev/vg00/riso bs=64k 4. Create a temporary directory and mount the /dev/vg00/iso volume # mkdir /iso_image # mount /dev/vg00/iso /iso_image NOTE: For HP-UX 11.11 you must install the latest CDFS patches: PHCO_25841 Add Rock Ridge extension to mount_cdfs(1M) PHKL_26269 Rock Ridge extension for ISO-9660 PHKL_34153 CDFS cumulative patch 2) Available in HP-UX 11.31 0909: ISOIMAGE-ENH. Provides a new DLKM module fspd. Required to mount, read and umount the ISO image file. The comm