Forum Discussion

kevinh's avatar
kevinh
Bronze III
19 hours ago

Ransomware: Darkside - Question 9

In terms of determining the name of the service that is installed after the ransomware was executed, there doesn't seem to be any service installation activities observed from the endpoint. Wondering if I should be focusing on a different code, slightly irrelevant towards service creation activities.

 

when searching for file creation for possible service names "api-ms-win-service-management-l1-1-0.dll" is also showcased to not work.

 

Wondering about what different area should I be looking into instead

1 Reply

  • When parsing for the service names during execution I am also struggling to find a meaningful link as well

     

    Which includes parsing for the eventID itself