Guest Lecture 6 Flashcards
1
Q
What are the four stages of malware analysis?
A
In order of increased difficult and resource cost:
Fully automated analysis -> Static property analysis -> Interactive behaviour analysis -> Manual code revising
2
Q
Which ransomware family is “REvil aka Sodinokibi”
A
REvil operate as a ransomware-as-a-service (RaaS).
3
Q
What does ransomware notes usually contain?
A
- The instructions on how to pay the ransom and get the key to decrypt your files are contained in the ransomware note that can be found in each folder
- It also provides a trial decryption so the victim can be sure that when they pay for a decryption key it is able to decrypt the files.
4
Q
Name prevention tactics for Ransomware attacks
A
- Remote Backup
- Timely Patching
- Fulti Factor Autentication (MFA)
- Cybersecurity Awareness
- Follow CIS (Center for Internet Security) benchmarks