Contents

Splunk vs. REvil Ransomware

   Oct 15, 2024     0 min read

REvil

  • Revil is a type of ransomware known for its aggressive tactics, mainly encrypting victims data and demanding large ransoms for decryption keys.

  • Affected user reports their desktop background changed to something that includes a ransom note. Investigate using the Splunk SIEM containing Sysmon event logs.

Q1 Identify the filename of the note that the ransomware left behind?

Splunk

Q2 Pinpoint the source, what’s the PID of the ransomware thats likely involved?

Splunk

  • 5348
  • Why?