Questions tagged [ransomware]

7 questions
7
votes
3 answers

Is SMB safer than iSCSI for connection to a NAS?

Recently one of our customers undertook an IT network audit from another (third party) IT audit firm. The results were generally good, although they pointed out that we had used iSCSI client on Windows Server as a means of connecting to the NAS,…
hazymat
  • 390
  • 1
  • 9
  • 16
1
vote
1 answer

EXSi Arg Server attack

I have a very basic question. From what I have read, it seems these unpatched servers were directly attacked remotely through the internet via port 427. So unlike other ransomware attacks, the malware did not get into the network through phishing or…
1
vote
1 answer

ESXi Server has locked with .lock4 file suffix on all vmdk's after crash SAVE ME!

My ESXI server was running from a USB stick that got corrupted and as a result prevented my server from booting. I fixed this by reinstalling ESXI on a new memory stick and began re-adding all of my VMs. However when I try to start them up it is…
jim
  • 19
  • 2
0
votes
0 answers

How does pandora.x86 infect cloud servers?

We have a cloud server instance hosted at vultr. A previous instance at this provider has been infected by pandora.x86 a few weeks ago, causing 100% CPU load and over 1TB of traffic. (We believe it is this one, due to the name of the process running…
merlin
  • 2,093
  • 11
  • 39
  • 78
0
votes
1 answer

Windows defender ransomware protection and SQL Server

Our small company has organized several levels of virus protection for Windows servers, but there are always fears that this is not enough. Is it correct to configure Windows Defender Ransomware Proteсtion to directories with data and transaction…
0
votes
1 answer

AWS Glacier and Ransomware

I'm trying to understand the structure of how AWS Glacier works because I have a problem. Problem: I have a NAS that backs up to Glacier about once a week. About two weeks ago the NAS got infected with ransomeware so if I retrieved the data now I…
0
votes
3 answers

Any ideas how could I've been ransomware hacked?

A couple of days ago our clients reported our Solarwinds website was down. So I connected to check through remote desktop and there it was, a fullscreen html-like interface where you could only use the mouse to type using the interface…