↓ Skip to main content
  1. Writeups/
  2. CyberDefenders/

Brabbit

Description
#

A company employee was tricked into opening a malicious attachment disguised as a business email. The lure led to a ransomware deployment that encrypts files and corrupts the boot process. As the investigator, your goal is to reconstruct the infection chain, identify the malware family, and map the attacker’s behavior to key TTPs.

Check the challenge here.

Solution
#

The challenge archive contains the malicious email message and encoded malware sample. The investigation starts with the phishing lure, moves into malware family identification and execution behavior, and then traces persistence, C2 traffic, and destructive impact.


Q1: The phishing email used to deliver the malicious attachment showed several indicators of a potential social engineering attempt. What is the suspicious email address that sent the attachment?

I pasted the email header into MxToolbox and checked the sender metadata. The suspicious source address was clearly exposed in the result:

MxToolbox sender analysis

Flag: theceojamessmith@Drurnbo.com


Q2: The ransomware was identified as part of a known malware family. What is the family name of the ransomware identified during the investigation?

I extracted the base64-encoded attachment and converted it into a Windows executable:

cat mal.base64 | base64 -d > mal.exe
file mal.exe
# Result: mal.exe: PE32 executable for MS Windows 5.01 (console), Intel i386, 5 sections

I then scanned the binary in VirusTotal. The family name was visible in the file metadata and related intel:

VirusTotal malware family identification

Flag: BadRabbit


Q3: Upon execution, the ransomware dropped a file onto the compromised system to initiate its payload. What is the name of the first file dropped by the ransomware?

The execution chain is described in the Checkpoint investigation. The dropper file that initiates the attack is explicitly named there.

Flag: infpub.dat


Q4: Inside the dropped file, the malware contained hardcoded artifacts, including usernames and passwords. What is the only person’s username found within the dropped file?

The investigation from above reveals the usernames used by the dropper.

Flag: alex


Q5: After execution, the ransomware communicated with a C2 server. What MITRE ATT&CK sub-technique describes the ransomware’s use of web protocols for sending and receiving data?

VirusTotal’s ATT&CK section under the Command and Control tactic showed the relevant Application Layer Protocol technique. I also verified it on the official MITRE ATT&CK site: T1071.001.

MITRE ATT&CK C2 technique

Flag: T1071.001


Q6: Persistence mechanisms are a hallmark of sophisticated ransomware. What is the MITRE ATT&CK sub-technique ID associated with the ransomware’s persistence technique?

Using the same ATT&CK mapping in VirusTotal, the persistence behavior corresponded to a scheduled task technique.

MITRE ATT&CK persistence mapping

Flag: T1053.005


Q7: As part of its infection chain, the ransomware created specific tasks to ensure its continued operation. What are the names of the tasks created by the ransomware during execution?

The research into the attack chain (from Question 3) identifies the task names created by the ransomware to maintain persistence.

Flag: rhaegal, drogon


Q8: The malicious binary dispci.exe displayed a suspicious message upon execution, urging users to disable their defenses. What suspicious message was displayed in the console when executing this binary?

I looked up the malware’s execution behavior and found a screenshot from a Fortinet article showing the exact message presented by dispci.exe.

BadRabbit console warning

Flag: Disable your anti-virus and anti-malware programs


Q9: To modify the Master Boot Record (MBR) and encrypt the victim’s hard drive, the ransomware utilized a specific driver. What is the name of the driver used to encrypt the hard drive and modify the MBR?

The article from Question 3 reveals the driver used for the MBR modification and disk encryption.

Flag: DiskCryptor


Q10: Attribution is key to understanding the threat landscape. What is the name of the threat actor responsible for this ransomware campaign?

The campaign was later associated with a known threat actor in public reporting and ransomware analysis blogs. (link)

Flag: Sandworm


Q11: The ransomware rendered the system unbootable by corrupting critical system components. What is the MITRE ATT&CK ID for the technique used to corrupt the system firmware and prevent booting?

The official BadRabbit ATT&CK page lists the destructive firmware corruption tactic.

Flag: T1495


Note

I used AI to check spelling and enhance phrasing of this writeup. No AI was used while solving the challenge.

References
#

Vlad Șteopoaie
Author
Vlad Șteopoaie
A.K.A. h3pha