Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Retracted

Premium room

Investigate the case of the missing ransomware.

easy

60 min

14,243

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

A Mother's Plea

"Thanks for coming. I know you are busy with your new job, but I did not know who else to turn to."

"So I downloaded and ran an installer for an antivirus program I needed. After a while, I noticed I could no longer open any of my files. And then I saw that my wallpaper was different and contained a terrifying message telling me to pay if I wanted to get my files back. I panicked and got out of the room to call you. But when I came back, everything was back to normal."

"Except for one message telling me to check my Bitcoin wallet. But I don't even know what a Bitcoin is!"

"Can you help me check if my computer is now fine?"

Connecting to the Machine

Start the lab machine in split-screen view by clicking on the green "Start Lab Machine" button on the upper right section of this task. If the is not visible, use the blue "Show Split View" button at the top-right of the page. Alternatively, you can connect to the  using the credentials below via "Remote Desktop".

THM key
Usernamesophie
Passwordfluffy1960
IPMACHINE_IP
"Oh, the password doesn't work? Wait, I have it written somewhere. Uhmm... Try this:"
THM key
Usernamesophie
Passwordfluffy19601234!
IPMACHINE_IP
Answer the questions below
I'll handle it,  Mom.