Ad Widget

Collapse

monitor file access - ransomware detection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • xanadu
    Member
    • Sep 2014
    • 62

    #1

    monitor file access - ransomware detection

    In the hunt in detecting cryptolocker alike malware I'm looking for a way to detect abnormal file access behaviour.

    I already placed one dummy.docx file where I check modification access and it's checksum, but this is only within one directory and hasn't proved to be effective as we had a cryptolocker inside another directory.

    Is there a way where we can enable zabbix to monitor abnormal file access / changes which are in automated way?

    All ideas are welcome!
  • xanadu
    Member
    • Sep 2014
    • 62

    #2
    Is there anything we could do with running sysinternals process explorer and using it virustotal.com functionality?

    Comment

    • ServicedeskITS
      Junior Member
      • Jun 2016
      • 5

      #3
      I think using Zabbix for this is not ideal.
      Coz when it happens you are too late.

      Best thing as far as i know is to use File System Resource Manager on Windows Server
      This will prevent files from being changed to a different extension and hopefully also for the file from being infected as well.

      Comment

      • Wasur
        Junior Member
        • Mar 2017
        • 1

        #4
        Originally posted by ServicedeskITS
        I think using Zabbix for this is not ideal.
        Coz when it happens you are too late.

        Best thing as far as i know is to use File System Resource Manager on Windows Server
        This will prevent files from being changed to a different extension and hopefully also for the file from being infected as well.
        Thank you! Very helpful
        http://manual-removal.com/crypt0l0cker-2017/
        Last edited by Wasur; 13-03-2017, 21:54.

        Comment

        Working...