LockBit

You are a Digital Forensics and Incident Response (DFIR) analyst tasked with investigating a ransomware attack that has affected a company's system. The attack has resulted in file encryption, and the attackers are demanding payment for the decryption of the affected files. You have been given a memory dump of the affected system to analyze and provide answers to specific questions related to the attack.



Memory dump (password: infected): /root/Desktop/ChallengeFile/Lockbit.zip



This challenge prepared by @MMOX