REvil Ransomware (Redline)

REvil Ransomware (Redline)

Tags
forensic
ID matched
Created
Apr 30, 2023 06:15 AM
Last Updated
Last updated July 15, 2023
ย 
ย 

1. ์‚ฌ์ „ ์ค€๋น„

ย 

2. ํ’€์ด

Q1. What is the Operating System which the Redline image is being collected on?
  • System Information์—์„œ ์šด์˜์ฒด์ œ ํ™•์ธ
    • notion image
์ •๋‹ต
Windows 7 Professional 7601 Service Pack 1
ย 
Q2. What is the Logged in User while the Redline image is being collected?
  • System Information์—์„œ ์œ ์ € ์ •๋ณด ํ™•์ธ
    • notion image
์ •๋‹ต
SecurityNinja
ย 
Q3. What is the location of the ransomware on the filesystem?
  • File Download History์—์„œ ์ถœ์ฒ˜๊ฐ€ ์˜์‹ฌ์Šค๋Ÿฌ์šด ํŒŒ์ผ ํ™•์ธ
    • notion image
  • ํ•ด๋‹น ํŒŒ์ผ์„ ๋‹ค์šด๋ฐ›์€ ํด๋”์—์„œ ์ˆ˜์ƒํ•œ ํŒŒ์ผ ํ™•์ธ
    • notion image
  • ํ•ด๋‹น ํŒŒ์ผ์˜ ํ•ด์‰ฌ๊ฐ’์„ VirusTotal์—์„œ ๊ฒ€์ƒ‰
    • notion image
์ •๋‹ต
C:\Users\SecurityNinja\Downloads\bad day.exe
ย 
Q4. What is the MD5 of the ransomware?
  • Details ์ฐฝ์œผ๋กœ๋ถ€ํ„ฐ ํ•ด์‰ฌ๊ฐ’ ํ™•์ธ
    • notion image
์ •๋‹ต
94d087166651c0020a9e6cc2fdacdc0c
ย 
Q5. What is the extension for the encrypted file on the filesystem?
  • ๋ฐ”ํƒ•ํ™”๋ฉด ํด๋”๋กœ๋ถ€ํ„ฐ ์ˆ˜์ƒํ•œ ํ™•์žฅ์ž์˜ ํŒŒ์ผ ํ™•์ธ
    • notion image
์ •๋‹ต
993ixjlb
ย 
Q6. What is the onion website for paying the ransom?
  • ์ œ๊ณต๋œ ํŒŒ์ผ์˜ ๋žœ์„ฌ ๋…ธํŠธ์—์„œ ํ™•์ธ
    • notion image
์ •๋‹ต
http://aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion/4FE49B3286F992CB
ย 
Q7. What is the secondary website for paying the ransom?
  • ์ œ๊ณต๋œ ํŒŒ์ผ์˜ ๋žœ์„ฌ ๋…ธํŠธ์—์„œ ํ™•์ธ
    • notion image
์ •๋‹ต
http://decoder.re/4FE49B3286F992CB
ย 
Q8. What is the Child Command Line Process being executed after the ransomware being executed?
  • Processes์—์„œ ๋ช…๋ น์–ด ํ™•์ธ
    • notion image
์ •๋‹ต
netsh advfirewall firewall set rule group='Network Discovery' new enable=Yes
ย 
Q9. What is the Mitre ATT&CK Technique ID of this ransomware impact stage?
  • Mitre Att&ck Matrix์—์„œ Impact์˜ Data Encrypted for Impact ์„ ํƒ
    • notion image
      notion image
์ •๋‹ต
T1486
ย 
Q10. What is the name of the Ransomware?
์ •๋‹ต
REvil
ย 
ย 
ย 
ย 

์ฐธ๊ณ 

ย