{"id":652,"date":"2016-05-05T20:27:00","date_gmt":"2016-05-05T20:27:00","guid":{"rendered":"https:\/\/itgroove.net\/kinglou\/?p=652"},"modified":"2023-02-24T21:39:35","modified_gmt":"2023-02-24T21:39:35","slug":"cerber-ransomware-encounter-nasty-piece-of-work-beware","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/","title":{"rendered":"Cerber Ransomware Encounter! Nasty piece of work BEWARE."},"content":{"rendered":"<p align=\"left\">I ran into the Cerber variant of Ransomware lately and it is nasty. This one is relatively new having surfaced in March 2016, but thankfully I have only seen it once in the wild\u2026so far.<\/p>\n<p align=\"left\">This one is particularly nasty for the following reasons:<\/p>\n<ul>\n<li>\n<div align=\"left\">Runs offline and doesn\u2019t need to be online to fetch encryption keys<\/div>\n<\/li>\n<li>\n<div align=\"left\">Encrypted files are fully renamed and given a new file extension<\/div>\n<\/li>\n<li>\n<div align=\"left\">Bypasses UAC!<\/div>\n<\/li>\n<li>\n<div align=\"left\">Edits some timestamps to blank and user owner making finding the source hard(er)<\/div>\n<\/li>\n<li>\n<div align=\"left\">No recovery process other than backups! (so far)<\/div>\n<\/li>\n<\/ul>\n<p align=\"left\">Full detailed write up <a href=\"https:\/\/blog.malwarebytes.org\/threat-analysis\/2016\/03\/cerber-ransomware-new-but-mature\/\">HERE<\/a><\/p>\n<p align=\"left\">What I experienced was files getting renamed with a .cerber extension, crazy file names and accompanying files with # DECRYPT MY FILES #.html. The user&#8217;s desktop got decimated then it started to go to mapped drives even moving to other folders that the user didn\u2019t have mapped on the file share somehow. It weirdly only targeted files that had been modified in the past day. While this kind of makes sense as these would be the files recently used so probably valuable to offer as ransom, but odd as it made it easier to pinpoint files and restore. Since it encrypts the files and completely renames them it does present issues with large amounts of files as finding what is actually gone was tiresome.<\/p>\n<p align=\"left\"><em><strong>***this was my experience and I may of got lucky with it only targeting recent files***<\/strong><\/em><\/p>\n<p align=\"left\">To pinpoint the source we disconnected everyone from the mapped file shares and searched everyone&#8217;s local PC&#8217;s for *.cerber files. This thankfully only brought up one PC so we threw that one off a bridge.<\/p>\n<p align=\"left\">We then had to restore from backups or from shadow copies if you have them, there is no recovery method other than paying and the FBI does not recommend that.<\/p>\n<p align=\"left\">Trend Micro detects it as below:<\/p>\n<p align=\"left\"><a href=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"padding-top: 0px;padding-left: 0px;padding-right: 0px\" title=\"clip_image001\" src=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png\" alt=\"Ransomware\" width=\"572\" height=\"217\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">Malwareybtes of course also grabs it and they also recommend you use their Antiexplot program <a href=\"https:\/\/www.malwarebytes.org\/antiexploit\/\">HERE<\/a>. I installed it on PC&#8217;s in trial just as a precaution before I let them back onto the network.<\/p>\n<p align=\"left\">Since we use Trend Micro WFBS at a lot of clients here are a few more tips to cover your bases.<\/p>\n<p align=\"left\">Update Trend WFBS to SP3! SP3 enables the Behavior Monitoring features that protect from Ransomware by default now.<\/p>\n<p align=\"left\"><a href=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image002.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"padding-top: 0px;padding-left: 0px;padding-right: 0px\" title=\"clip_image002\" src=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image002_thumb.png\" alt=\"Ransomware\" width=\"739\" height=\"448\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">Beef up you notification under <strong><em>Preferences<\/em><\/strong> for <strong><em>Behavior Monitoring<\/em><\/strong>. Change it to something lower within minutes as Ransomware will infect fast so you want to catch it before it gets too far.<\/p>\n<p align=\"left\"><a href=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image003.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"padding-top: 0px;padding-left: 0px;padding-right: 0px\" title=\"clip_image003\" src=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image003_thumb.png\" alt=\"Ransomware\" width=\"740\" height=\"256\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">Change the actual alert to be more descriptive and get people&#8217;s attention.<\/p>\n<p align=\"left\"><a href=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image004.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"padding-top: 0px;padding-left: 0px;margin: 0px;padding-right: 0px\" title=\"clip_image004\" src=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image004_thumb.png\" alt=\"Ransomware\" width=\"234\" height=\"82\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">Example:<\/p>\n<p align=\"left\"><a href=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image005.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"padding-top: 0px;padding-left: 0px;padding-right: 0px\" title=\"clip_image005\" src=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image005_thumb.png\" alt=\"Ransomware\" width=\"748\" height=\"360\" border=\"0\" \/><\/a><\/p>\n<p align=\"left\">As always there will be lots of different variants so your mileage may vary.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I ran into the Cerber variant of Ransomware lately and it is nasty. This one is relatively new having surfaced in March 2016, but thankfully I have only seen it once in the wild\u2026so far. This one is particularly nasty for the following reasons: Runs offline and doesn\u2019t need to be online to fetch encryption &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[664],"tags":[203,685,691,697,715,733,150,751],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cerber Ransomware Encounter! Nasty piece of work BEWARE. - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cerber Ransomware Encounter! Nasty piece of work BEWARE. - Archive\" \/>\n<meta property=\"og:description\" content=\"I ran into the Cerber variant of Ransomware lately and it is nasty. This one is relatively new having surfaced in March 2016, but thankfully I have only seen it once in the wild\u2026so far. This one is particularly nasty for the following reasons: Runs offline and doesn\u2019t need to be online to fetch encryption &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2016-05-05T20:27:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:39:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/\",\"name\":\"Cerber Ransomware Encounter! Nasty piece of work BEWARE. - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png\",\"datePublished\":\"2016-05-05T20:27:00+00:00\",\"dateModified\":\"2023-02-24T21:39:35+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#primaryimage\",\"url\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png\",\"contentUrl\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png\",\"width\":572,\"height\":217},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cerber Ransomware Encounter! Nasty piece of work BEWARE.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cerber Ransomware Encounter! Nasty piece of work BEWARE. - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/","og_locale":"en_US","og_type":"article","og_title":"Cerber Ransomware Encounter! Nasty piece of work BEWARE. - Archive","og_description":"I ran into the Cerber variant of Ransomware lately and it is nasty. This one is relatively new having surfaced in March 2016, but thankfully I have only seen it once in the wild\u2026so far. This one is particularly nasty for the following reasons: Runs offline and doesn\u2019t need to be online to fetch encryption &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/","og_site_name":"Archive","article_published_time":"2016-05-05T20:27:00+00:00","article_modified_time":"2023-02-24T21:39:35+00:00","og_image":[{"url":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png"}],"author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/","url":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/","name":"Cerber Ransomware Encounter! Nasty piece of work BEWARE. - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"primaryImageOfPage":{"@id":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#primaryimage"},"image":{"@id":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#primaryimage"},"thumbnailUrl":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png","datePublished":"2016-05-05T20:27:00+00:00","dateModified":"2023-02-24T21:39:35+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#primaryimage","url":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png","contentUrl":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2016\/05\/clip_image001_thumb.png","width":572,"height":217},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2016\/05\/05\/cerber-ransomware-encounter-nasty-piece-of-work-beware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"Cerber Ransomware Encounter! Nasty piece of work BEWARE."}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/652"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=652"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/652\/revisions"}],"predecessor-version":[{"id":2750,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/652\/revisions\/2750"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=652"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=652"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=652"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}