VMware Ransomware Infection Analysis
Budget: $30 – $250 SGD
Inside an isolated VMware lab I need a thorough, repeatable analysis of a live ransomware sample. The sole objective is to reveal how the malware first lands, escalates, and persists so I can tighten my organisation’s preventive controls and monitoring rules.
While reverse-engineering you are free to use IDA, Ghidra, x64dbg, Wireshark, ProcMon, or any other tooling you prefer, as long as the findings are clearly documented and can be reproduced in a fresh VM snapshot.
Deliverables (all required):
• Technical report that narrates the complete infection chain—initial dropper, files created, registry or scheduled-task changes, command-and-control traffic, and encryption trigger.
• IOC spreadsheet with file hashes, mutexes, URLs, IPs, and any relevant YARA signatures.
• Mitigation section mapping the observed techniques to concrete hardening steps (e.g., Group Policy tweaks, firewall rules, EDR detections).
• VM rollback instructions so I can safely re-run the sample if needed.
Acceptance criteria:
The report must be detailed enough for a security team to reproduce the behaviour in VMware and immediately translate the insights into endpoint or network prevention rules.
If you have prior ransomware reverse-engineering experience and can hand over the first draft within a week, let’s get started.
While reverse-engineering you are free to use IDA, Ghidra, x64dbg, Wireshark, ProcMon, or any other tooling you prefer, as long as the findings are clearly documented and can be reproduced in a fresh VM snapshot.
Deliverables (all required):
• Technical report that narrates the complete infection chain—initial dropper, files created, registry or scheduled-task changes, command-and-control traffic, and encryption trigger.
• IOC spreadsheet with file hashes, mutexes, URLs, IPs, and any relevant YARA signatures.
• Mitigation section mapping the observed techniques to concrete hardening steps (e.g., Group Policy tweaks, firewall rules, EDR detections).
• VM rollback instructions so I can safely re-run the sample if needed.
Acceptance criteria:
The report must be detailed enough for a security team to reproduce the behaviour in VMware and immediately translate the insights into endpoint or network prevention rules.
If you have prior ransomware reverse-engineering experience and can hand over the first draft within a week, let’s get started.
Related categories:
Linux
Health & Medicine
Cisco
VMware
Network Administration
Documentation
Network Security
Reverse Engineering