We will analyze ransomware in this exercise. Ransomware can cause havoc in a network, and we have seen plenty of examples in the recent past. Ransomware such as WannaCry, Petya, and Locky have caused immense disruption in the world. Additionally, these days, PyLocky ransomware is a hot favorite for attackers. Some ransomware generally rolls out keys to the server on their initial run, and that's the point where we, the network forensic guys, come into the picture.
Intercepting malware for fun and profit
PyLocky ransomware decryption using PCAP data
Recently, Cisco has launched the PyLocky decryptor (https://github.com/Cisco-Talos/pylocky_decryptor), which searches through the PCAP to decrypt files on the system. PyLocky...