Ransomeware Attack (Redline)

Ransomeware Attack (Redline)

Tags
forensic
ID matched
Created
Apr 30, 2023 05:28 AM
Last Updated
Last updated July 15, 2023
ย 
ย 
ย 

1. ์‚ฌ์ „ ์ค€๋น„

ย 

2. ํ’€์ด

Q1. Please you find the dropped dll, include the whole path including the dll file
  • Process ์ƒ์—์„œ ์ˆ˜์ƒํ•œ ํ”„๋กœ์„ธ์Šค ํฌ์ฐฉ
    • notion image
  • File System์—์„œ ํ•ด๋‹น ํŒŒ์ผ ์ •๋ณด ํ™•์ธํ•˜์—ฌ dll ๋ชฉ๋ก ํ™•์ธ
    • notion image
  • ์˜์‹ฌ ๋˜๋Š” MpsVc.dll์˜ ํ•ด์‰ฌ๊ฐ’์„ VirusTotal์—์„œ ๊ฒ€์ƒ‰
    • notion image
์ •๋‹ต
C:\Users\charles\AppData\Local\Temp\MpsVc.dll
ย 
Q2. What is the MD5 hash for the dll?
  • dll ํŒŒ์ผ์˜ Details ์ฐฝ์œผ๋กœ๋ถ€ํ„ฐ ํ•ด์‰ฌ๊ฐ’ ํ™•์ธ
    • notion image
์ •๋‹ต
040818b1b3c9b1bf8245f5bcb4eebbbc
ย 
Q3. What i s the name of ransomware note that got dropped?
  • ๋ฐ”ํƒ•ํ™”๋ฉด์˜ ํŒŒ์ผ ๋ชฉ๋ก ํ™•์ธ
    • notion image
์ •๋‹ต
2s6lc-readme
ย 
Q4. What is the URL that the initial payload was downloaded fro m? (Include the whole URL with the payload)
  • Prefetch์—์„œ ์ˆ˜์ƒํ•œ lsass.exe ํŒŒ์ผ ํ™•์ธ
    • notion image
  • File Download History์—์„œ ์ฃผ์†Œ ํ™•์ธ
    • notion image
์ •๋‹ต
http://192.168.75.129:8111/Documents/lsass
ย 
Q5. The ransomware drops the copy of the legitimate application into the Temp folder. Please provide the filename including the extension
  • FileSystem์—์„œ dll๊ณผ ๋™์ผํ•œ ์‹œ๊ฐ„์— ์ƒ์„ฑ๋œ ํŒŒ์ผ ํ™•์ธ
    • notion image
์ •๋‹ต
MsMpEng.exe
ย 
Q6. What is name of the ransomware?
์ •๋‹ต
sodinokibi
ย 
ย 
ย 
ย 

์ฐธ๊ณ