{"id":462,"date":"2017-04-10T17:15:00","date_gmt":"2017-04-10T22:15:00","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=462"},"modified":"2017-04-10T18:46:02","modified_gmt":"2017-04-10T23:46:02","slug":"ransomware-identification-and-response","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/security\/ransomware-identification-and-response\/","title":{"rendered":"Ransomware: Identification and Response"},"content":{"rendered":"<p>By now, ransomware is an unfortunate fact of life. \u00a0Anyone who&#8217;s been working in IT for some time has very likely brushed up\u00a0against it at some point during their career&#8211;and while it&#8217;s a stunning encounter in the outset, it&#8217;s the\u00a0<em>response\u00a0<\/em>to that encounter\u00a0that\u00a0makes all the difference.<\/p>\n<p><em>Before we go any further, I want to make this very clear: <strong>if your data is important to you, it is very wise\u00a0<span style=\"text-decoration: underline;\">not<\/span>\u00a0to attempt recovery\/response on your own. \u00a0Bring your machine to a professional instead! <\/strong>\u00a0If you have nothing to lose, however,\u00a0below\u00a0are some guidelines to follow to attempt recovery in the aftermath of\u00a0an attack.<\/em><\/p>\n<p>It&#8217;s useful to comprehend the steps\u00a0most ransomware specimens take to attacking\/encrypting data on a machine to help facilitate a response to their attacks. This is absolutely not meant to be a comprehensive article on the subject (far more detailed analyses have been written by experts such as Lawrence Abrams at his excellent\u00a0<a href=\"http:\/\/www.BleepingComputer.com\">BleepingComputer.com<\/a>), but here are a\u00a0few common points that apply to most every ransomware in the wild today:<\/p>\n<ul>\n<li>Most of them limit the types of files they encrypt to\u00a0those which are most likely to contain critical user data&#8211;stuff like photos\/pictures, documents, videos, databases, etc.<\/li>\n<li>System\/program\/non-user data directories (X:\\Windows, Program Files, Program Data, %APPDATA%, etc.) are explicitly excluded from encryption to prevent system stability issues post-infection and improve efficiency<\/li>\n<li>Encryption normally begins silently in the early morning hours while the user is less likely to be in front of the machine.<\/li>\n<\/ul>\n<p>The above items are done in the interest of efficiency to ensure the ransomware is able to complete its encryption job without the user noticing. \u00a0Typically,\u00a0after the completion of the encryption, the ransomware will then remove itself from the system&#8211;leaving only a ransom note with payment instructions, as that&#8217;s all the attackers care about at this point after all.<\/p>\n<p>Although most of them apply the same strategy (and many are, in fact, even blood-related), the first step to properly responding to a ransomware attack is to take a sample and attempt a positive ID of the malware. \u00a0This can be accomplished by using services such as\u00a0<a href=\"https:\/\/id-ransomware.malwarehunterteam.com\/\">ID Ransomware<\/a> (by MalwareHunterTeam\/Demonslay335), which is a free online resource that attempts to identify a ransomware infection based on either a ransom note or sample encrypted file. \u00a0However, it&#8217;s very important that\u00a0<em>you do not obtain the file while running on the infected OS<\/em>. \u00a0Doing so provides the ransomware precious additional time to complete its destruction of the existing data if it has not already completed. \u00a0If you\u00a0<em>must\u00a0<\/em>collect the file in the host infected OS,\u00a0<em>only do so\u00a0<strong>after\u00a0<\/strong>you obtain a forensic image of the data<\/em>.<\/p>\n<p>Once an ID has (hopefully) been completed, the next step is to respond and attempt recovery (if necessary\/desired)&#8211;assuming no backups are present and that does not exist as a (much simpler) option. \u00a0This involves several steps, but\u00a0it roughly goes something like this:<\/p>\n<ol>\n<li>Obtain a\u00a0<em>forensic image\u00a0<\/em>of\u00a0all affected storage devices\/machines and store it safely away from the machine.<\/li>\n<li>Boot to a portable environment and manually inspect the parameters of the system, including:\n<ol>\n<li>Boot processes, services, tasks, and other items frequently leveraged by\u00a0malware as loading points<\/li>\n<li>The locations of any files which are infected, malware, or related to the ransomware infection<\/li>\n<li>The <em>System Volume Information<\/em> repository contents and the Volume Shadow Copy parameters\/settings (to ensure that Shadow Copies and System Restore are turned\u00a0<em>on<\/em> and that sufficient space is configured to allow for the storage of Shadow Copies)<\/li>\n<li>The health of\u00a0any affected storage devices<\/li>\n<\/ol>\n<\/li>\n<li>If necessary, suspend\/disable any components which are related to the malware\/ransomware infection next.<\/li>\n<li>Once this is completed, reboot into the host OS (Safe Mode if possible) and, if a decrypter has been identified for your particular ransomware infection, obtain it and attempt decryption of the data.<\/li>\n<li>If a decrypter has\u00a0<em>not\u00a0<\/em>been identified, the only remaining solution is usually to attempt to <a href=\"https:\/\/www.bleepingcomputer.com\/virus-removal\/cryptowall-ransomware-information#shadow\">dig into the Volume Shadow Copy Storage<\/a> in hopes of previous versions of the affected data still being present.\n<ul>\n<li>Ransomware specimens often attempt to purge shadow copies of files post-encryption to prevent recovery of the files using shadow copy storage. \u00a0However, the methods used to do this are often heavy and time-consuming (typically it&#8217;s a vssadmin command that&#8217;s used to accomplish this). \u00a0Many times the process will not have completely finished by the time the user notices the damage. \u00a0That&#8217;s why sometimes digging into the VSS storage can be a successful solution to recovering data following a ransomware attack.<\/li>\n<li>There are multiple tools available which can accomplish Shadow Copy file restoration, but the best is probably <a href=\"http:\/\/www.shadowexplorer.com\/downloads.html\">ShadowExplorer<\/a>.<\/li>\n<\/ul>\n<\/li>\n<li>If shadow copies do not exist, the last-ditch effort to retrieve some remaining data is typically to perform a\u00a0<em>file carving\u00a0<\/em>operation on the entire hard drive. \u00a0Tools such as <a href=\"http:\/\/www.cgsecurity.org\/wiki\/PhotoRec\">PhotoRec<\/a> can be used to accomplish this. \u00a0File Carving identifies files based on their headers and <em>not<\/em> based on filesystem information\/structural data (MFT\/FAT\/etc). \u00a0As a result, it can sometimes turn up lost files even following a ransomware attack.\n<ul>\n<li>Most ransomware specimens wipe both free space and the sectors on the disk affiliated with previous\/clean versions of encrypted files once encryption is complete, so this process is usually fruitless. \u00a0But, as a last resort, it&#8217;s worth a shot.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>If all else fails, backups are the final option. \u00a0If no backups exist, the user must consider paying the ransom in hopes of recovering their data&#8211;though authorities and experts will invariably tell you\u00a0<em>not\u00a0<\/em>to do this, as it encourages ransomware as a viable business venture and, therefore, the attackers win. \u00a0However, most ransomware gangs\u00a0<em>will\u00a0<\/em>in fact restore data following successful receipt of payment&#8211;and sometimes it is the only option.<\/p>\n<p>Once recovery has (hopefully) been completed, any remaining ransom notes can be automatically removed using <a href=\"https:\/\/www.bleepingcomputer.com\/forums\/t\/617257\/ransomnotecleaner-remove-ransom-notes-left-behind\/\">Demonslay335&#8217;s RansomNoteCleaner tool here<\/a>.<\/p>\n<p><em>For specific help on a ransomware infection, check out BleepingComputer&#8217;s free support forum <a href=\"https:\/\/www.bleepingcomputer.com\/forums\/f\/239\/ransomware-help-tech-support\/\">here<\/a>. \u00a0Remember, though&#8211;if your data is important to you, let an expert handle it! \u00a0<strong>Don&#8217;t\u00a0<\/strong>attempt a DIY recovery!<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By now, ransomware is an unfortunate fact of life. \u00a0Anyone who&#8217;s been working in IT for some time has very likely brushed up\u00a0against it at some point during their career&#8211;and while it&#8217;s a stunning encounter in the outset, it&#8217;s the\u00a0response\u00a0to &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/security\/ransomware-identification-and-response\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[11,209,143],"class_list":["post-462","post","type-post","status-publish","format-standard","hentry","category-security","tag-malware","tag-ransomware","tag-recovery-2"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=462"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/462\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}