Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Malware Threat Detection

Archived

Malware Threat Detection provides a comprehensive package to detect any malware infection in just a few simple steps. A new variant of Dharma Ransomware has been discovered, where a .cmb extension is appended to encrypted drives. 

Dharma Ransomware attacks are carried out by malicious actors scanning for devices running Remote Desktop Protocol Services (RDP), primarily TCP port 3389, and brute-forcing the password to the device. The ransomware is then installed manually by the attacker and configured to execute automatically when the user logs in to Windows, encrypting files created subsequent to the last execution.  

Once a device is infected, files are encrypted and a .cmb extension is appended following the format "[original file name].id-[id].[email].cmb", where [email] is the attacker's email address which the victim is urged to contact, to recover encrypted data.

It provides a comprehensive package to detect any malware infection in just a few simple steps.

The list of IoCs required to run Malware Threat Detection is as follows:


Malware Threat Detection detects the following malware:

Release Details

Version: 3.1.0
Release date: August 15, 2018
Supported On: Logpoint v6.0.0 and later
SHA 256: 678ce5fa55c99f523dfe0a8ec0af71e3b5a2f310998d8d28bc7e7145b0cf94d5
Download

Installation

To install the Malware Threat Detection:

  1. Download the .pak from the Download link above.
  2. Add the required Malware Threat Detection server as a device in LogPoint.
  3. Create a processing policy.
  4. Assign the policy to the device.
  5. Add the dashboards.

Log Source Requirements

  • Windows Server/Integrity Scanner
    • It detects malicious file installation and malware-infected hosts.
  • Mail Server
    • It detects any emails sent to the malicious address.
  • Firewall
    • It detects the connection to and from malicious listed sources.
  • Web Server/Proxy/Firewall
    • It detects the connection to malicious domains and URLs. 

Support

If you have any questions or require assistance, create a support ticket.

Comments

Please sign in to leave a comment.

Follow

Related articles

  • BitDefender
  • Ransomware Analytics
  • Malwarebytes
  • Universal REST API Fetcher
  • Microsoft ATA
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.