CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. 漏洞列表
  3. 正文

Backdoors and trojan horses 2017-08-16 10:45:05 Mamba Ransomware Detected (Pre-Reboot)

2017年8月19日 6407点热度 0人点赞 0条评论

漏洞类别:Backdoors and trojan horses

漏洞等级:

漏洞信息

Mamba is an ransomware, which post infection overwrites the existing Master Boot Record on a Windows installation, with a custom MBR and encrypts the hard drive leveraging an open source full disk encryption utility called DiskCryptor. It is unclear if the malware contains a propagation mechanism. However, it seems that a malware group exploit a network and after they gain access to an organizations network they use the psexec utility to execute the ransomware in the network.

QID Detection Logic:
This authenticated detection works by checking for the presence of a few files such as %SYSTEMDRIVE%\DC22\dcinst.exe, %SYSTEMDRIVE%\DC22\log_file.txt, %SYSTEMDRIVE%\xampp\http\dcinst.exe, %SYSTEMDRIVE%\xampp\http\log_file.txt that are found on an infected pre-reboot system.

漏洞危害

Systems infected by this ransomware will have their files encrypted and rendered unusable until they pay a price to an anonymous party.

解决方案

To Protect your systems:
- Use the Windows AppLocker feature to disable the execution of PSExec.exe.
- Disable WMI
- Disable SMBv1
- Make sure systems are running up to date anti-malware.
- Block ADMIN$ access via GPO.
- Maintain good back-ups so that if an infection occurs, you can restore your data.

Cleaning up Infected systems:
- Contact your Anti-Malware vendor to remove the infection.

0daybank

标签: 暂无
最后更新:2022年12月28日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me