Get your files back FREE! This comprehensive guide walks you through removing ransomware and analyzing the attack. Learn from TryHackMe & Dunkle Materie's expertise (11 Minutes). Click the link in the description to enter our latest giveaway 👉 https://bit.ly/VietTube ✅
TryHackMe Room: Dunkle Materie
Investigate the Ransomware attack using ProcDOT.
https://tryhackme.com/r/room/dunklema...
00:00 Intro STOP Ransomware! FREE Removal Guide & Deep Analysis👍TryHackMe | Dunkle Materie
00:15 Run Proc
Select Log file.
Select Dump file.
Launch.
Refresh.
Two PIDs pawned from the malicious executable
8644, 7128
02:39 Where the ransomware initially got executed ?
c:\users\sales\appdata\local\temp\exploreer.exe
03:25 What are two C2 domains ?
mojobiden.com, paymenthacks.com
05:55 What are the IPs of the malicious domains ?
146.112.61.108, 206.188.197.206
06:25 User-agent used to transfer the encrypted data to the C2 channel
Firefox/89.0
07:20 Cloud security service that blocked the malicious domain
Cisco umbrella
07:33 The bitmap that the ransomware set up as a desktop wallpaper
ley9kpi9r.bmp
08:18 Find the PID
4892
08:50 The registry key path to the mounted drive
HKLM\SYSTEM\MountedDevices\\DosDevices\Z:
09:19 The name of the ransomware used in the attack
BlackMatter ransomware
👉What kind of video would you like to see next?
Ransomware Removal
Analyze Ransomware Attack
Free Ransomware Removal Guide
malware analysis
Ransomware Forensics with ProcDOT
How Ransomware Works (Technical)
Recover Files from Ransomware Attack
Dunkle Materie TryHackMe Room
Prevent Ransomware Infection (Security Tips)
Ransomware Removal 2024 (Current Year)
Data Recovery After Ransomware Attack
👉What did you think of this video?
#ransomware #ransomwareattack #datarecovery
#ransomwareanalysis #cybersecurityanalysis #incidentresponse
#tryhackme #dunklematerie #VietTu
#ransomwareremovalguide #freedatarecovery
👇For any Query message me on Facebook👇
Facebook Link :- https://FB.COM/K3Lvinmitnick
-----------------
Disclaimer: The content in this video is strictly for Education purposes only. Copyright Disclaimer Under Section 107 of the Copyright Act 1976, allowance is made for "fair use" for purposes such as criticism, comment, news reporting, teaching, scholarship, and research. This video is not forcing anything on you.
-----------------
🔔📢 Subscribe for more TIPs from VietKim → https://bit.ly/VietTube
🌐 Follow VietKim on https://FB.COM/K3Lvinmitnick
🌐 Visit https://bloggeroffer.blogspot.com/ to learn more ...
Watch video STOP Ransomware! FREE Removal Guide & Deep Analysis👍TryHackMe | Dunkle Materie online without registration, duration hours minute second in high quality. This video was added by user VietTube 04 June 2024, don't forget to share it with your friends and acquaintances, it has been viewed on our site 489 once and liked it 0 people.