Ransomware Attack

We have extracted the memory dump from the compromised machine. Find the evidence of the ransomware attack.

Memory Dump (pass: infected): C:\Users\LetsDefend\Desktop\Files\AnalysisSession1.7z

This challenge prepared by @RussianPanda


Writeups:

  • Let's Defend Ransomware Attack
  • Ransomware Attack Walk-Through
  • Sodinokibi Ransomware Vaka Analizi – LetsDefend Writeup
  • DFIR - Ransomware Attack
  • LetsDefend Ransomware Attack Write-up