REvil Ransomware

We have extracted the memory dump from the compromised machine. Find the evidence of the ransomware attack.

Memory Dump (pass: infected): C:\Users\LetsDefend\Desktop\Files\Ransomware-Analysis.zip



This challenge prepared by @Bohan Zhang


Walkthroughs:

  • DFIR - REvil Ransomware
  • LetsDefend’s DFIR Challenge: REvil Ransomware Walk-Through