VMware Ransomware Infection Analysis

Job ID: 40137278

Budget: $30 – $250 SGD

Inside an isolated VMware lab I need a thorough, repeatable analysis of a live ransomware sample. The sole objective is to reveal how the malware first lands, escalates, and persists so I can tighten my organisation’s preventive controls and monitoring rules.

While reverse-engineering you are free to use IDA, Ghidra, x64dbg, Wireshark, ProcMon, or any other tooling you prefer, as long as the findings are clearly documented and can be reproduced in a fresh VM snapshot.

Deliverables (all required):
• Technical report that narrates the complete infection chain—initial dropper, files created, registry or scheduled-task changes, command-and-control traffic, and encryption trigger.
• IOC spreadsheet with file hashes, mutexes, URLs, IPs, and any relevant YARA signatures.
• Mitigation section mapping the observed techniques to concrete hardening steps (e.g., Group Policy tweaks, firewall rules, EDR detections).
• VM rollback instructions so I can safely re-run the sample if needed.

Acceptance criteria:
The report must be detailed enough for a security team to reproduce the behaviour in VMware and immediately translate the insights into endpoint or network prevention rules.

If you have prior ransomware reverse-engineering experience and can hand over the first draft within a week, let’s get started.