Blog

Ranstop blocks DBGer ransomware

Test subject – DBGer ransomware

A new Satan variant was recently released, having quite a few updates. It’s called DBGer, named after the extension it adds to the encrypted files.

Satan has been around for quite some time, and it is very popular among cybercriminals, mostly because of their Ransomware-as-a-Service (RaaS) portal, which makes it easy to distribute the malware for anyone’s benefit. Earlier versions were pretty straightforward, classic ransomware strains if you will, but efficient. Targeting mostly home users, Satan spread across the Globe, quickly becoming notorious.

DBGer ransomware test facts

The malware developers probably thought it was time for an upgrade, as the new variants make use of the infamous EternalBlue SMB exploit (the same used by WannaCry), three other less known exploits, and Mimikatz, which is an opensource password dumping tool. All these suggest that the new Satan versions are targeting corporate users, as these spreading/hacking/brute-force techniques are useful only in bigger networks. Essentially, these are all automated tools to attack other PCs in the network, infecting as many as possible, maximizing chances for profit. Because of this, DBGer should not be taken lightly, because only one infected machine is needed to infect most, part of the same infrastructure.

DBGer is less picky regarding file extensions, as most ransomware attack only a few file types. With DBGer, everything is encrypted, regardless of their location, including files in the “ProgramData” and “Program Files” folders. Nothing is spared, shared network resources or other partitions are quickly compromised.

Currently, there are no tools available to decrypt files attacked by DBGer.

DBGer ransomware test results

TEMASOFT Ranstop detects DbGer ransomware easily once it starts encrypting files. Upon detection, the user is alerted, and the ransomware process is killed and quarantined. The affected files are automatically recovered so that the user doesn’t lose her critical documents.


Click here to watch TEMASOFT Ranstop blocking DBGer ransomware (video)!

Learn how to protect against ransomware!

About TEMASOFT Ranstop

TEMASOFT Ranstop is an anti-ransomware software that detects present and future ransomware, based on file access pattern analysis with a high degree of accuracy. At the same time, it protects user files so that they can be restored in case of malware attacks or accidental loss.

For more information, follow us on social media and subscribe to our newsletter.

This post was last modified on August 21, 2023 7:26 am

FM Team

Share
Published by
FM Team

Recent Posts

The Role of File Monitoring Solutions in Maintaining File Integrity

In the digital world, information is often stored and transferred through files. From the most…

May 12, 2023

Guide to Conducting an Efficient File Access Permissions Audit for Admins and Technology Managers

Introduction Data security is more important than ever in today's fast-paced digital world. One critical…

April 9, 2023

File Integrity Monitoring: What It Is and Why It Matters

Introduction: Cyber threats are a growing concern for businesses and individuals alike. With the increasing…

March 5, 2023

Monitoring Essential Microsoft IIS Server Configuration Files for Enhanced Security

Microsoft Internet Information Services (IIS) is a popular web server that is widely used to…

February 25, 2023

Tracking file changes helps admins solve server configuration problems

File tracking is an important aspect of server administration, and it can help administrators detect…

February 1, 2023

Three reasons why admins should use file monitoring solutions

File monitoring solutions are essential tools for administrators to manage and protect their organizations' data…

January 6, 2023