$WIFE’s laptop hit by Locky… “I just opened this file” Hopefully, IDS/AV reacted and minor impact…
-
-
-
-
Replying to @xme @bartblaze
What made it stop at <100? AV? Broken malware? Your/her intervention?
2 replies 0 retweets 0 likes -
Replying to @martijn_grooten @bartblaze
I’m still investigating… maybe a blog post will follow. It started to encrypt, av detected and my IDS (callback)
1 reply 0 retweets 0 likes -
Replying to @xme @bartblaze
Thanks. I'm curious! I believe lots of AV is pretty good at mitigating the risk of ransomware, but it's not often tested.
2 replies 1 retweet 0 likes -
Replying to @martijn_grooten @bartblaze
Also switched immediately off the network… Did a memory dump, time for some volatility fun :)
2 replies 2 retweets 3 likes -
Replying to @xme @martijn_grooten
Nice :) Have fun, let us know if you find anything useful. (malfind is handy usually)
1 reply 0 retweets 0 likes -
Careful of malfind. It can be a false positive minefield.
1 reply 0 retweets 0 likes
True. That's why you need to manually verify its findings as well. I prefer using memdump myself usually.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.