> For the complete documentation index, see [llms.txt](https://faresbltagy.gitbook.io/footprintinglabs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faresbltagy.gitbook.io/footprintinglabs/cyberdefenders/revil-lab.md).

# REvil Lab

Q1) To begin your investigation, can you identify the filename of the note that the ransomware left behind?

```splunk-spl
event.code: 11 AND winlog.event_data.TargetFilename: "*\\Desktop\\*"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fnq4PxgV1cHsVijOF9UX6%2FScreenshot.png?alt=media&amp;token=1b850c97-3a5f-4f8b-8dba-7140ee99af8b" alt=""><figcaption></figcaption></figure>

Answer:  5uizv5660t-readme.txt

Q2) After identifying the ransom note, the next step is to pinpoint the source. What's the process ID of the ransomware that's likely involved

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FeWIJMqFlee3P1PJtOm7u%2FScreenshot(2).png?alt=media&amp;token=125623cb-52e7-4dfb-b055-6be129403dce" alt=""><figcaption></figcaption></figure>

Answer:  5348

Q3) Having determined the ransomware's process ID, the next logical step is to locate its origin. Where can we find the ransomware's executable file?

```splunk-spl
event.code: 1 and winlog.event_data.ProcessId: 5348
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FtAmITMmA7FgLNmsiRKiJ%2FScreenshot(3).png?alt=media&amp;token=e052ea01-c2f5-4147-867d-d54bd65c05b8" alt=""><figcaption></figcaption></figure>

Answer:  C:\Users\Administrator\Downloads\facebook assistant.exe

Q4) Now that you've pinpointed the ransomware's executable location, let's dig deeper. It's a common tactic for ransomware to disrupt system recovery methods. Can you identify the command that was used for this purpose?

```splunk-spl
event.code: 1 and winlog.event_data.ParentImage: "C:\Users\Administrator\Downloads\facebook assistant.exe"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FBJTg21c7xycqYHdlYNJh%2FScreenshot(4).png?alt=media&amp;token=9b7ed263-42d5-40ce-84b1-0a9bab502e66" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F9RbhnudBfoWcHsf55Zl5%2FScreenshot(5).png?alt=media&amp;token=26c17548-97bc-42cf-9748-d0217e0ce985" alt=""><figcaption></figcaption></figure>

Answer:  Get-WmiObject Win32\_Shadowcopy | ForEach-Object {$\_.Delete();}

Q5) As we trace the ransomware's steps, a deeper verification is needed. Can you provide the sha256 hash of the ransomware's executable to cross-check with known malicious signatures?

```splunk-spl
event.code: 1 and winlog.event_data.Image: "C:\Users\Administrator\Downloads\facebook assistant.exe"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FuXlt79BomGjoPFazCIGl%2FScreenshot(6).png?alt=media&amp;token=2b0367f2-36dc-42b6-80c8-ca51ceee4fae" alt=""><figcaption></figcaption></figure>

Answer:  B8D7FB4488C0556385498271AB9FFFDF0EB38BB2A330265D9852E3A6288092AA

Q6) One crucial piece remains. We need to identify the attacker's communication channel. Can you pinpoint the ransomware author's onion domain to receive the payments from the victims?

From <https://app.any.run/submissions>, I search by the sha256.

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FldUp6MVsiUMrMmu7O6Zg%2FScreenshot(7).png?alt=media&amp;token=254777b4-d6cf-4038-bae0-269c929a6319" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FFFs3mJ1zfPnqY5E8F5mu%2FScreenshot(8).png?alt=media&amp;token=2c4d54d8-07d7-40e2-b96c-fbbea643ee48" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F1ITjYjVXbYmRMfiB0KJh%2FScreenshot(9).png?alt=media&amp;token=0f03c8b6-7127-411e-903a-2ce2a01c6e7d" alt=""><figcaption></figcaption></figure>

Answer:  aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faresbltagy.gitbook.io/footprintinglabs/cyberdefenders/revil-lab.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
