Open cardosec

Case 37B955 · Malware & intel · L4 Advanced

How the locker kills recovery

Practise as: Incident drill

Live alertYour sandbox run of a ransomware sample shows every shadow copy gone before encryption, yet no vssadmin, wmic or PowerShell child process ever started.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. vssadmin, wmic and PowerShell deletion spawn child processes (4688/Sysmon 1); WMI COM or VSS API calls run in-process, no child
  2. No child process means in-process WMI (Win32_ShadowCopy) or VSS API deletion, a sign of a mature locker evading command-line rules
  3. Confirm statically: imports/strings for Win32_ShadowCopy or IVssBackupComponents; also bcdedit recovery off and wbadmin catalog deletion
  4. Recovery-inhibit method plus note, extension, kill lists and config cluster the family; compare to vendor reports and YARA rules
  5. Deletion usually lands just before encryption; anchor the timeline there and look earlier for staging, exfil and tool drops

If the interviewer pushes back

  • The sample resizes shadow storage instead of deleting copies. Why would it, and how would you detect that?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.