Description#
A company employee was tricked into opening a malicious attachment disguised as a business email. The lure led to a ransomware deployment that encrypts files and corrupts the boot process. As the investigator, your goal is to reconstruct the infection chain, identify the malware family, and map the attacker’s behavior to key TTPs.
Check the challenge here.
Solution#
The challenge archive contains the malicious email message and encoded malware sample. The investigation starts with the phishing lure, moves into malware family identification and execution behavior, and then traces persistence, C2 traffic, and destructive impact.
Q1: The phishing email used to deliver the malicious attachment showed several indicators of a potential social engineering attempt. What is the suspicious email address that sent the attachment?
I pasted the email header into MxToolbox and checked the sender metadata. The suspicious source address was clearly exposed in the result:

Flag: theceojamessmith@Drurnbo.com
Q2: The ransomware was identified as part of a known malware family. What is the family name of the ransomware identified during the investigation?
I extracted the base64-encoded attachment and converted it into a Windows executable:
cat mal.base64 | base64 -d > mal.exe
file mal.exe
# Result: mal.exe: PE32 executable for MS Windows 5.01 (console), Intel i386, 5 sectionsI then scanned the binary in VirusTotal. The family name was visible in the file metadata and related intel:

Flag: BadRabbit
Q3: Upon execution, the ransomware dropped a file onto the compromised system to initiate its payload. What is the name of the first file dropped by the ransomware?
The execution chain is described in the Checkpoint investigation. The dropper file that initiates the attack is explicitly named there.
Flag: infpub.dat
Q4: Inside the dropped file, the malware contained hardcoded artifacts, including usernames and passwords. What is the only person’s username found within the dropped file?
The investigation from above reveals the usernames used by the dropper.
Flag: alex
Q5: After execution, the ransomware communicated with a C2 server. What MITRE ATT&CK sub-technique describes the ransomware’s use of web protocols for sending and receiving data?
VirusTotal’s ATT&CK section under the Command and Control tactic showed the relevant Application Layer Protocol technique. I also verified it on the official MITRE ATT&CK site: T1071.001.

Flag: T1071.001
Q6: Persistence mechanisms are a hallmark of sophisticated ransomware. What is the MITRE ATT&CK sub-technique ID associated with the ransomware’s persistence technique?
Using the same ATT&CK mapping in VirusTotal, the persistence behavior corresponded to a scheduled task technique.

Flag: T1053.005
Q7: As part of its infection chain, the ransomware created specific tasks to ensure its continued operation. What are the names of the tasks created by the ransomware during execution?
The research into the attack chain (from Question 3) identifies the task names created by the ransomware to maintain persistence.
Flag: rhaegal, drogon
Q8: The malicious binary
dispci.exedisplayed a suspicious message upon execution, urging users to disable their defenses. What suspicious message was displayed in the console when executing this binary?
I looked up the malware’s execution behavior and found a screenshot from a Fortinet article showing the exact message presented by dispci.exe.

Flag: Disable your anti-virus and anti-malware programs
Q9: To modify the Master Boot Record (MBR) and encrypt the victim’s hard drive, the ransomware utilized a specific driver. What is the name of the driver used to encrypt the hard drive and modify the MBR?
The article from Question 3 reveals the driver used for the MBR modification and disk encryption.
Flag: DiskCryptor
Q10: Attribution is key to understanding the threat landscape. What is the name of the threat actor responsible for this ransomware campaign?
The campaign was later associated with a known threat actor in public reporting and ransomware analysis blogs. (link)
Flag: Sandworm
Q11: The ransomware rendered the system unbootable by corrupting critical system components. What is the MITRE ATT&CK ID for the technique used to corrupt the system firmware and prevent booting?
The official BadRabbit ATT&CK page lists the destructive firmware corruption tactic.
Flag: T1495
I used AI to check spelling and enhance phrasing of this writeup. No AI was used while solving the challenge.

