ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 285 - CAS-004 discussion

Report
Export

A pharmaceutical company was recently compromised by ransomware. Given the following EDR output from the process investigation:

On which of the following devices and processes did the ransomware originate?

A.
cpt-ws018, powershell.exe
Answers
A.
cpt-ws018, powershell.exe
B.
cpt-ws026, DearCry.exe
Answers
B.
cpt-ws026, DearCry.exe
C.
cpt-ws002, NO-AV.exe
Answers
C.
cpt-ws002, NO-AV.exe
D.
cpt-ws026, NO-AV.exe
Answers
D.
cpt-ws026, NO-AV.exe
E.
cpt-ws002, DearCry.exe
Answers
E.
cpt-ws002, DearCry.exe
Suggested answer: D

Explanation:

The EDR output shows the process tree of the ransomware infection. The root node is NO-AV.exe, which is a malicious executable that disables antivirus software and downloads the DearCry ransomware. The NO-AV.exe process was launched on cpt-ws026 by a user named John. The DearCry.exe process was then launched on cpt-ws026 by NO-AV.exe and propagated to other devices via SMB. Therefore, the ransomware originated from cpt-ws026 and NO-AV.exe. Verified

Reference:

https://www.microsoft.com/security/blog/2021/03/12/analyzing-dearcry-ransomware-the-first-attack-to-exploit-exchange-server-vulnerabilities/

https://www.crowdstrike.com/blog/dearcry-ransomware-analysis/

asked 02/10/2024
M Kumar
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first