Malware Threat Detection
ArchivedMalware Threat Detection provides a comprehensive package to detect any malware infection in just a few simple steps. A new variant of Dharma Ransomware has been discovered, where a .cmb extension is appended to encrypted drives.
Dharma Ransomware attacks are carried out by malicious actors scanning for devices running Remote Desktop Protocol Services (RDP), primarily TCP port 3389, and brute-forcing the password to the device. The ransomware is then installed manually by the attacker and configured to execute automatically when the user logs in to Windows, encrypting files created subsequent to the last execution.
Once a device is infected, files are encrypted and a .cmb extension is appended following the format "[original file name].id-[id].[email].cmb", where [email] is the attacker's email address which the victim is urged to contact, to recover encrypted data.
It provides a comprehensive package to detect any malware infection in just a few simple steps.
The list of IoCs required to run Malware Threat Detection is as follows:
Malware Threat Detection detects the following malware:
Release Details
Installation
To install the Malware Threat Detection:
- Download the .pak from the Download link above.
- Add the required Malware Threat Detection server as a device in LogPoint.
- Create a processing policy.
- Assign the policy to the device.
- Add the dashboards.
Log Source Requirements
-
Windows Server/Integrity Scanner
- It detects malicious file installation and malware-infected hosts.
-
Mail Server
- It detects any emails sent to the malicious address.
-
Firewall
- It detects the connection to and from malicious listed sources.
-
Web Server/Proxy/Firewall
- It detects the connection to malicious domains and URLs.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Please sign in to leave a comment.