{"id":86996,"date":"2018-10-26T19:13:52","date_gmt":"2018-10-26T13:43:52","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=86996"},"modified":"2018-10-29T18:50:51","modified_gmt":"2018-10-29T13:20:51","slug":"ransomware-attacks-remote-access-rise-secure-system-now","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/ransomware-attacks-remote-access-rise-secure-system-now\/","title":{"rendered":"Ransomware attacks through Remote Access are on rise. Secure your system now!!"},"content":{"rendered":"<p>Once again ransomware attacks are on the rise and this can leave your systems vulnerable to critical data loss and breach. In fact, the recent outbreak of ransomware allows cyber criminals to easily gain access to your computer through <em>Remote Desktop<\/em> using <strong>brute-force technique<\/strong>, which is capable of cracking weak passwords.<\/p>\n<p>With this post, we wish to help you with essential steps and corrective measures you can take, to protect your computer(s) against ransomware and RDP brute-force attacks.<\/p>\n<p>However, before we get into the steps to follow, it can be helpful to get a brief understanding about RDP Brute-Force attacks first.<\/p>\n<p><strong>What is RDP Brute Force Attack? <\/strong><\/p>\n<p>A RDP brute-force attack is basically a kind of ransomware attack that makes use of Remote Desktop Protocol (RDP). Attackers scan a list of IPs to find the default <strong>RDP port 3389<\/strong> that is open for connection. Once the port is discovered, the attacker launches the brute-force attack.<\/p>\n<p>This is basically a trial &amp; error technique of User ID and password guessing, where the attacker tries a series of commonly used credentials, common word combinations and dictionary words to break through weak passwords. To make things easier for attackers, there are numerous tools readily available that can perform these RDP brute forcing and port scanning with ease.<\/p>\n<p>Once attackers gain access, all they have to do is to disable your system\u2019s antivirus (even if updated) and infect your system.<\/p>\n<p>Fortunately, <strong>Quick Heal products <\/strong>comes with a security feature that can protect your system against such brute-force attacks.<\/p>\n<p>We have already released an update to modify rule in Quick Heal\u2019s Firewall that automatically turns off your RDP connections for security reasons and you are sorted. This will discourage hackers from remotely accessing your system.<\/p>\n<p>With the update already released, there can be 2 possible case scenarios:<\/p>\n<p><strong>Case #1 I do not wish to use RDP <\/strong><\/p>\n<p>If you already have Quick product installed on your system, then you have absolutely nothing to worry about. Quick Heal\u2019s <strong><em>Firewall Protection Feature<\/em><\/strong> can effectively block RDP attempt.<\/p>\n<p>As we have already rolled out an update to disable RDP connection, if your Quick Heal product\u2019s virus database version is 25<sup>th<\/sup> October or later, be assured that you are already protected from RDP attacks.<\/p>\n<p><em>\u00a0<img loading=\"lazy\" decoding=\"async\" class=\" wp-image-86997 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-300x238.jpg\" alt=\"\" width=\"311\" height=\"247\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-300x238.jpg 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-768x610.jpg 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-491x390.jpg 491w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-789x626.jpg 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard.jpg 1053w\" sizes=\"(max-width: 311px) 100vw, 311px\" \/><\/em><\/p>\n<p><em>*In case of any queries, feel free to call us on our toll-free no. 1800-121-7377 and our support engineers would be glad to help you with the issue. You may also visit <\/em><a href=\"https:\/\/bit.ly\/QHChat\"><em>https:\/\/bit.ly\/QHChat<\/em><\/a><em> to chat with us online. <\/em><\/p>\n<p><strong>Case #2 I want to continue using RDP <\/strong><\/p>\n<p>Just in case, it is essential for you to continue using RDP, but at the same time you wish to ensure its security, then you can manually configure the Firewall Protection Feature to configure RDP connection with the help of following steps:<\/p>\n<p><strong>Open Quick Heal Dashboard =&gt; Select Internet and Network =&gt; Firewall Protection=&gt; Advanced Settings \u2013 Configure=&gt; Traffic Rules.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-86997\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-300x238.jpg\" alt=\"\" width=\"300\" height=\"238\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-300x238.jpg 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-768x610.jpg 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-491x390.jpg 491w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard-789x626.jpg 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Total-security-dashboard.jpg 1053w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-86998\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Firewall-Protection-300x245.png\" alt=\"\" width=\"300\" height=\"245\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Firewall-Protection-300x245.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Firewall-Protection-477x390.png 477w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Firewall-Protection.png 698w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>In the <strong>Traffic rule<\/strong> window, click on <strong>Add<\/strong> for adding an exception.<\/li>\n<li>Give any Name for the rule e.g. <strong>Remote Desktop<\/strong> and select <strong>Next<\/strong><\/li>\n<li>In the \u2018<strong>Local IP Address<\/strong>\u2019 screen, no changes are to be made, just click \u2018Next\u2019<\/li>\n<li>In the <strong>Local TCP\/UDP Port<\/strong> window enter the RDP port in the <strong>Specific port<\/strong> option and click Next. By default the RDP port is 3389. Mention the same if you have not changed it.<\/li>\n<li>In the <strong>Remote IP Address<\/strong> enter the IP address of the system from which you would want to accept RDP connections.\n<ul>\n<li>It is recommended to configure IP address from which RDP connections are to be allowed. However, if you do not wish to restrict access to specific IP address, select \u2018Any IP Address\u2019 and click Next.<\/li>\n<li>If you wish to restrict access to range of IP addresses, select \u2018IP Address Range\u2019 and specify IP address here. Eg. 192.168.0.1 to 192.168.0.255.<\/li>\n<\/ul>\n<\/li>\n<li>Select <strong>Next<\/strong> for the <strong>Remote TCP\/UDP port<\/strong><\/li>\n<li>Select an action to be taken as \u2018<strong>Allow\u2019<\/strong> in the last window and click finish.<\/li>\n<li>Now save the changes made by clicking on <strong>OK<\/strong><\/li>\n<li>Click on <strong>Save Changes<\/strong>.<\/li>\n<\/ul>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-86999 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Traffic-Rule-Exception-300x239.png\" alt=\"\" width=\"300\" height=\"239\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Traffic-Rule-Exception-300x239.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Traffic-Rule-Exception-768x611.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Traffic-Rule-Exception-490x390.png 490w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Traffic-Rule-Exception-789x628.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Traffic-Rule-Exception.png 1052w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><strong>\u00a0 \u00a0 Traffic Rule Window<\/strong>\u00a0 \u00a0\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-87000 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Exception-Name-300x234.png\" alt=\"\" width=\"300\" height=\"234\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Exception-Name-300x234.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Exception-Name-768x598.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Exception-Name-501x390.png 501w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Exception-Name-789x615.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Exception-Name.png 1050w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><strong>\u00a0 \u00a0<\/strong><strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0Add Name of Rule<\/strong><strong>\u00a0<\/strong><strong>\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-87001 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Local-IP-Address-300x232.png\" alt=\"\" width=\"300\" height=\"232\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-IP-Address-300x232.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-IP-Address-768x594.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-IP-Address-504x390.png 504w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-IP-Address-789x610.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-IP-Address.png 1047w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Local IP Address Screen\u00a0<\/strong><strong>\u00a0 \u00a0<\/strong><\/p>\n<p><strong><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-87002 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Local-TCP-UDP-Port-300x236.png\" alt=\"\" width=\"300\" height=\"236\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-TCP-UDP-Port-300x236.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-TCP-UDP-Port-768x604.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-TCP-UDP-Port-496x390.png 496w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-TCP-UDP-Port-789x620.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Local-TCP-UDP-Port.png 1046w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<\/strong><strong>\u00a0<\/strong><strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0Local TCP\/UDP Port Window\u00a0 <\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-87003 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Remote-IP-Address-300x236.png\" alt=\"\" width=\"300\" height=\"236\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-IP-Address-300x236.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-IP-Address-768x603.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-IP-Address-497x390.png 497w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-IP-Address-789x620.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-IP-Address.png 1048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>Remote IP Address Window<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-87004 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Remote-TCP-UDP-300x234.png\" alt=\"\" width=\"300\" height=\"234\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-TCP-UDP-300x234.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-TCP-UDP-768x599.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-TCP-UDP-500x390.png 500w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-TCP-UDP-789x616.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Remote-TCP-UDP.png 1048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><strong>\u00a0 \u00a0 \u00a0 \u00a0 <\/strong><strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0Remote TCP\/UDP Port<\/strong><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-87005 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/10\/Select-Action-Allow-300x235.png\" alt=\"\" width=\"300\" height=\"235\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Select-Action-Allow-300x235.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Select-Action-Allow-768x602.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Select-Action-Allow-497x390.png 497w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Select-Action-Allow-789x619.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/10\/Select-Action-Allow.png 1048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<\/strong><strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Select Action &#8211; Allow <\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>In addition to above mentioned steps, Quick Heal comes with few additional features that can secure your system from such attacks. These features include:<\/p>\n<ul>\n<li><strong>Anti-Ransomware<\/strong> &#8211; Behavior-based detection technology that detects and blocks threats such as Ransomware in real-time.<\/li>\n<li><strong>IDS\/IPS<\/strong> \u2013 Detects and blocks RDP brute-force attempts and IP of remote attacker for a defined period.<\/li>\n<li><strong>Virus Protection<\/strong> \u2013 Online service detects all known variants of the ransomware.<\/li>\n<li><strong>Back Up &amp; Restore<\/strong> \u2013 Helps you with regular automatic backup of your data for easy restoration whenever required.<\/li>\n<li><strong>Password Protection &#8211; <\/strong>Configuring password protection for your Quick Heal security software prevents unauthorized users from uninstalling or disabling your security system. You can do so by enabling <strong>Settings<\/strong> =&gt; <strong>Password Protection<\/strong>.<\/li>\n<\/ul>\n<h4><strong>ACKNOWLEDGEMENT<\/strong><\/h4>\n<p>Subject Matter Experts<\/p>\n<ul>\n<li>Amit Patel<\/li>\n<li>Vikas Tiwari<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Once again ransomware attacks are on the rise and this can leave your systems vulnerable to critical data loss and breach. In fact, the recent outbreak of ransomware allows cyber criminals to easily gain access to your computer through Remote Desktop using brute-force technique, which is capable of cracking weak passwords. With this post, we [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":87006,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[910,5,1395],"tags":[],"class_list":["post-86996","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","category-security","category-vulnerability"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/86996"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=86996"}],"version-history":[{"count":10,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/86996\/revisions"}],"predecessor-version":[{"id":87017,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/86996\/revisions\/87017"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/87006"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=86996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=86996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=86996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}