Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7
Prevention & response

Ransomware response: isolate, preserve and choose a recovery route

No Ransomware checklist: control connections, preserve evidence, assess backups and RFC for SQL, NAS, RAID, ESXi and Hyper-V before recovery.

Updated: · Vietnam time (UTC+7)

Illustration of a disconnected NAS, evidence drive and data preservation checklist.
AI-generated illustration • Not evidence.
Guidance document

Guidance compiled from No.Ransomware.VN and CISA/NIST. Owners must adapt steps to actual systems and authorized scope.

Sources are No.Ransomware.VN response and Recovery content without standalone article publication dates. The displayed date is editing into independent guidance.

Technical assessment

Isolate connections under the response procedure to limit spread. Power-off decisions must consider ongoing damage and volatile evidence such as memory; record reasons and operators. Do not format, reset NAS, rebuild RAID or restore over sources before preservation.

  • NAS / RAID: record drive order, array metadata, device logs and configuration; analyze appropriate copies.
  • SQL: preserve MDF, NDF, LDF, backup chains and application logs; extracting a few tables does not prove whole-database consistency.
  • ESXi / Hyper-V: preserve virtual disks and entire snapshot/checkpoint chains; check dependencies before booting.
  • RFC — Ransomware Fast Check: record tested samples, methods, damage and limits; a sample percentage is not a guarantee for every file.

Review access paths, accounts and privileges. Select unaffected copies using an evidenced timeline. Restore in isolation, test applications and measure RPO/RTO before reconnecting. Log decisions so others can review them.

During an incident

First limit spread, preserve evidence and avoid overwrites. Do not rush to format, rebuild RAID/NAS, clean up or restore over originals.

0–15 minutes

Isolate

  • Disconnect LAN/Wi-Fi on suspected devices.
  • Suspend VPN, synchronization and suspected compromised accounts.
  • Do not delete files, reset NAS or reinitialize RAID.
15–60 minutes

Record

  • Capture ransom screens and error messages.
  • Record times, devices, accounts and unfamiliar extensions.
  • Preserve logs, ransom notes and small samples.
Within 1–4 hours

Assess

  • Scope affected servers, NAS, cloud and backups.
  • Create working copies before testing recovery tools.
  • Prioritize service restoration by business needs.

TUNGTEK Ransomware Recovery

Need a condition assessment before intervention?

Support for identification, impact assessment and an extraction approach appropriate to NAS, RAID, servers, Hyper-V/VMware and storage devices.

Incident ResponseForensicNASSQLESXiHyper-V
No.Ransomware.VN — Awareness and response resourcesContent from the source homepage and categories. Guidance passages have no separate publication dates; no invented historical dates are assigned.
CISA — #StopRansomware GuideGuidance on prevention, response and recovery.
NIST SP 800-86 — Forensics in incident response2006 · Foundational guidance on collecting, examining, analyzing and reporting digital evidence.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.

· Consolidated from No.Ransomware.VN, preserving technical content, images and provenance. Links, metadata and verification scope standardized.

Corrections policy
N
No.Ransomware.VN

TUNGTEK's ransomware awareness and prevention initiative. Original content is preserved and edited within Ransomware.VN.