This is the answer from, macafee support,
Issue : "Cryptolocker Ransomware".
We constantly try to make sure that our DATs have the latest definitions to make sure we have full coverage, but there are times when a new variant is released and we do not have the signature for that in artemis as well.
At this juncture, I would recommend applying the access protection rule from the following document, if they have not been setup as yet:
https://kc.mcafee.com/corporate/index?page=content&id=PD25203
I would also recommend putting in a user defined access protection rule as per the following parameters to see which process is creating that file:
File/Folder blocking rule
Name of Rule:malware create block
Processes to include: *
Processes to exclude: leave blank
File name to block:**\*.vvv(where vvv is the extension of the encrypted files)
Action to block:Create, Write.
I would also recommend setting up a block for the following Rule:
Access Protection->Anti Virus Maxiumum Protection->prevent svchost from running non-windows executables.
Please duplicate the current access protection policy, add these rules and assign to all machines.
Please review the access protection log to determine which process is creating this file.
If it is svchost, then a procmon capture during the file encryption will help us identify the offending dll.
In addition to that, is there a chance you could submit the file as a sample to us based on the instructions in the following KB?:
https://kc.mcafee.com/corporate/index?page=content&id=KB68030
Once done, you will receive an analysis ID.
Please share that with me for faster processing.
I would also recommend scanning the source machine with the following tool and submitting the collected samples to us:
www.mcafee.com/in/downloads/free-tools/getsusp.aspx
Regarding the recovery of the files, please accept my apologies, but that will not be possible.
The files were encrypted with 256 bit AES encryption which is unbreakable.
Also the key to decrypt the files itself is encrypted with 2048 bit RSA encryption, which again, is uncrackable.
I would recommend deleting the files to save disk space and if you have a backup available, restore them from there.
I would also recommend advising the firewall team to block the domain name and originating IP of the link that was clicked by the user.
I would recommend leveraging Host IPS to prevent the modification of the important files in your environment.
Regarding the detections you are seeing, these are in all probability ransomware remnants, typically the png, txt and html files left behind with instructions to pay the malware author.
Host IPS can be used to control how files with different extensions may be modified and used.For more information on Host IPS, please refer to the videos below and the documents attached:
https://kc.mcafee.com/corporate/index?page=content&id=PD25203, page 3 and 4.
https://www.youtube.com/watch?v=_R8M-OmMBBI
https://www.youtube.com/watch?v=q_fgPbXZOBM
https://www.youtube.com/watch?v=_TsPhtFa7AM
We look forward to your reply.
Best Regards,
Kranthi Kiran M
Support Engineer
Intel Security Business Support
How am I doing today? Share your feedback with my manager at
[email protected].
Kindly reply to all while responding at this communication