Case 37B955 · Malware & intel · L4 Advanced
How the locker kills recovery
Practise as: Incident drill
Live alertYour sandbox run of a ransomware sample shows every shadow copy gone before encryption, yet no vssadmin, wmic or PowerShell child process ever started.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- vssadmin, wmic and PowerShell deletion spawn child processes (4688/Sysmon 1); WMI COM or VSS API calls run in-process, no child
- No child process means in-process WMI (Win32_ShadowCopy) or VSS API deletion, a sign of a mature locker evading command-line rules
- Confirm statically: imports/strings for Win32_ShadowCopy or IVssBackupComponents; also bcdedit recovery off and wbadmin catalog deletion
- Recovery-inhibit method plus note, extension, kill lists and config cluster the family; compare to vendor reports and YARA rules
- Deletion usually lands just before encryption; anchor the timeline there and look earlier for staging, exfil and tool drops
If the interviewer pushes back
- The sample resizes shadow storage instead of deleting copies. Why would it, and how would you detect that?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.