Skip to main content

Questions tagged [ransomware]

Ransomware is a lethal kind of Malware that Encrypts your harddrive(s) and holds them hostage, providing the decryption key if you pay the hostage-taker(s) money (well-known variants are the FBI Virus and the Police Virus).

16 votes
4 answers
4k views

I'm seeing more and more cloud service providers advertising what would be "Immutable backups" and calling alternatives "Legacy backups". (see Immutable backup on search engines) ...
user9203881's user avatar
0 votes
0 answers
384 views

I've recently got into cyber security and really got into malware, more specifically, ransomware. While studying some of the strongest ransomware ever (example: WannaCrypt, CryptoLocker, etc...) I've ...
JoshuaKasa's user avatar
0 votes
1 answer
219 views

I read this answer Ransomware encryption keys and understood how wannacry works. But I still have a question: as I understand, the hacker will put the hacker's RSA public key in the malware, the ...
Thanh's user avatar
  • 1
0 votes
0 answers
150 views

Here I have a malware sample that calls RegQueryValueEx quite frequently, without any time interruption. And as we can see, the result is quite often "BUFFER OVERFLOW". In another topic I ...
Questions123's user avatar
0 votes
2 answers
347 views

Following on to questions like Sandbox for attachment accessment and How do I safely inspect a suspicious email attachment?. Why don't we sandbox email clients company-wide? I must be missing ...
Danny Schoemann's user avatar
0 votes
0 answers
431 views

Here's what happened: I was transferring a quite large number of small files (.CSV, .PNG above all) from an old USB stick that never gave me any problem from one (allegedly safe) laptop (win10, win ...
user9875321__'s user avatar
0 votes
1 answer
225 views

Does anyone know why some ransomware families (e.g. Cuba but also Phobos if I am not mistaken) pad the file header to get to 1024 bytes? I mean what would be a reason for the ransomware developer to ...
Questions123's user avatar
0 votes
0 answers
795 views

I have been researching the Wannacry ransomware, and have seen an example of the kill switch within Ghidra. What baffles me is, why did they implement the kill switch as a web domain instead of any ...
Feddy1919's user avatar
1 vote
1 answer
2k views

I've got an emergency on my PC. I remotely connected to it using Remote Desktop Connection a couple of days ago and I worked on my PC for a while and logged off. Later, when I went to log back on, I ...
ThrownRedstone's user avatar
0 votes
2 answers
203 views

If the cybercriminal succeeded in gaining a foothold in the company's network, why are the whole network and other computers infected with ransomware except the one on which he gained a foothold?
pegasus's user avatar
2 votes
1 answer
196 views

Say a ransomware encrypts your database but hides the fact (by secretly decrypting everything you ask for). Then your backups become rubbish once the attacker deletes the key. What are good measures ...
JF Meier's user avatar
  • 173
14 votes
1 answer
4k views

I wondered what to do if there is a currently ongoing ransomware execution on my computer. Assuming that I'm "spotting" it while it is encrypting my files, should I power my computer off? I ...
Luhko's user avatar
  • 161
1 vote
0 answers
660 views

I want to hook certain API calls, e.g. CreateFile (or NtCreateFile if I hook ntdll.dll), but there are some issues. I can use several methods to achieve this goal, e.g. DLL injection, Inline hooking ...
Moooz's user avatar
  • 55
0 votes
1 answer
295 views

I have a question about how ransomware works. According to the authors of this paper: https://www.cise.ufl.edu/~traynor/papers/scaife-icdcs16.pdf (page 2 - 3) , class C is: ransomware reads the ...
Pieter Jansen's user avatar
4 votes
1 answer
1k views

On my Windows 10 PC after about 30 minutes of being turned on I always get a powershell window that immediately hides and consumes a lot of RAM. So I went to the powershell directory: "C:\Windows\...
Willy's user avatar
  • 41

15 30 50 per page
1
2 3 4 5
20