Staff
May 12, 2021
Technical Tip: How to use FortiAnalyzer to detect activities related the DarkSide Ransomware
- May 12, 2021
- 0 replies
- 5112 views
Description
This article describes how to use a custom Event Handler and Report in FortiAnalyzer to detect activities that may be related to the DarkSide Ransomware.
Scope
The custom Event Handler and Report provided can be used in FortiAnalyzer 6.4+
Solution
This article describes how to use a custom Event Handler and Report in FortiAnalyzer to detect activities that may be related to the DarkSide Ransomware.
For more information on the threat, see the FortiGuard Lab Threat Signal Report:
What is included in Fortinet_SOC-DarkSide-Detection.zip?
1) Outbreak_Alerts_Service_DarkSide_Detection_2.json
This event handler helps identify exploits detected by FortiGate, FortiClient and FortiSandbox. Therefore, these systems must be configured properly to block and log the events. The following table summarizes the products and the detection methods.
| FortiGate | IPS: Detects and block intrusions.
DNS Filter: Detects and blocks DNS traffic to known malicious domains associated with this attack |
| FortiClient | AV: FortiGuard AV real-time protection blocks ransomware file Botnet C&C: Detects and blocks traffic to known C&C domains |
| FortiSandbox | Detects file hashes detected in FortiSandbox logs |
2) Outbreak_Alerts_Service_DarkSide_Report_2.dat
A report to summarize findings on attack attempts, as detected by FortiGate, FortiClient and FortiSandbox. Please refer to the detection methods in the above table.
See the Solution section for instruction on how to load the event handler into a FortiAnalyzer unit.
Scope
The custom Event Handler and Report provided can be used in FortiAnalyzer 6.4+
Solution
All screen shots provided below for illustration purposes are taken from FortiAnalyzer 6.4.4. 1) Download the Fortinet_SOC-DarkSide-Detection.zip file (contains 2 files) 2) Unzip Fortinet_SOC-DarkSide-Detection.zip 3) Use Outbreak_Alerts_Service_DarkSide_Detection_2.json to import into Event Handlers a. Choose an ADOM (if ADOMs are enabled) b. Choose the FortiSOC module c. Select Event Handler List d. Select the Import option under "More" e. Select Outbreak_Alerts_Service_DarkSide_Detection_2.json Result: Outbreak_Alerts_Service_DarkSide_Detection_2.json is enabled and will be triggered if the appropriate logs are received after the event handler was imported 4) Use Outbreak_Alerts_Service_DarkSide_Report_2.dat to import into Reports a. Choose a Fabric ADOM (if ADOMs are enabled) b. Choose the Report module c. Select the Import option under "More" d. Select Outbreak_Alerts_Service_DarkSide_Report_2.datResult: 'Outbreak_Alerts_Service_DarkSide_Report_2' can be run anytime as determined by an admin user.


