Exam 1 Current Events Flashcards

1
Q

Baby’s Death: What happened?

A

-Health records inaccessible
-Wireless tracking system for tracking staff was down
-In Labor + Delivery Unit, staff cut off from heart monitors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Baby’s Death: Why? // Who?

A

Ransomware // Unknown. Potentially Ryuk gang (Russia)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Hive Ransomware: How it works

A

Uses multiple mechanisms to compromise corporate networks, making it harder for defenders to mitigate.

It noted that these include phishing emails with malicious attachments to gain initial access and the hijacking of Remote Desktop Protocol (RDP) to move laterally.

Then it drops a hive.bat script into the directory, which enforces an execution timeout delay of one second in order to perform clean-up after the encryption is finished

A second file, shadow.bat, is dropped into the directory to delete shadow copies, including disc backup copies or snapshots, without notifying the victim and then deletes the shadow.bat file.

The ransom note, dropped into every impacted directory, warns that if encrypted files are modified, renamed or deleted, they can’t be recovered. In the spirit of modern ransomware operations, which are highly professionalized, there’s also a live chat link to a ‘sales department,’ accessible through a TOR browser, for further communication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Ross Sim Hack: How? // Why?

A

Porting a number — Switching carriers

Vishing / Social Engineering / Whaling / Impersonation / Spear Phishing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly