Related Experiment Video
Updated: Oct 3, 2025

Analysis of Group IV Viral SSHHPS Using In Vitro and In Silico Methods
Published on: December 21, 2019
Ransomware: Analysing the Impact on Windows Active Directory Domain Services
Grant McDonald1, Pavlos Papadopoulos1, Nikolaos Pitropakis1
1Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK.
Ransomware attacks on Windows Server environments encrypt critical Active Directory files, causing dysfunction without stopping services. This research highlights the impact of malware on domain services, enhancing cyber situational awareness for organizations.
Area of Science:
- Cybersecurity
- Malware Analysis
- Network Security
Background:
- Ransomware is a growing cyber threat, highly profitable and targeting organizations for ransom payments.
- Organizations are prime targets due to the high cost of downtime and likelihood of paying ransoms.
- Limited research exists on ransomware's specific impact on Windows Server environments, especially Active Directory.
Purpose of the Study:
- To investigate the effects of ransomware on Windows Server domain services.
- To enhance cyber situational awareness for organizations using these environments.
- To analyze how crypto-ransomware variants interact with critical server processes.
Main Methods:
- Dynamic analysis of three distinct ransomware variants (WannaCry, TeslaCrypt, Jigsaw).
- Testing ransomware against multiple Windows Server domain services.
- Observing the impact on service processes and associated files.
Main Results:
- None of the tested ransomware variants terminated Windows Server domain service processes.
- All tested ransomware variants left the domain services technically untouched.
- Ransomware encryption of service-related files rendered the operational services dysfunctional.
Conclusions:
- Ransomware poses a significant threat to Windows Server environments by disrupting critical domain services through file encryption.
- Organizations must be aware that even if services appear operational, their functionality can be compromised.
- Further research is needed to develop effective countermeasures against ransomware targeting Active Directory and similar services.
Related Concept Videos
Distribution Reliability and Automation
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Viruses of Archaea
Legal Guidelines for Documentation
Microsoft Excel: Regression Analysis
To perform regression...
Viruses with RNA Genomes

