
the tools that real hackers use
Source: YouTube · John Hammond · published Mar 6, 2025 · 32:45
Inc ransomware was deployed via RDP from a domain controller, exploiting lack of EDR on the connecting host to gain full network access 2:30. Attackers used batch scripts to erase volume shadow copies, clear Windows credentials, and remove RDP history to conceal their activities 8:00-10:00. The ransomware executable (win.exe) and its ZIP archive share the same SHA-256 hash, indicating a self-clobbering tactic to hide the payload 23:20. An NS.exe tool was used to scan networks and mount shared drives, demonstrating lateral movement capabilities 26:50. The ransom note, displayed on the victim’s desktop, threatens to publish data on the dark web and includes a Twitter/X account, showing active threat actor communication 29:30.
Proactive threat hunting and EDR solutions are essential for detecting and responding to such attacks by analyzing forensic artifacts like jump lists, registry keys, and event logs.
Sources:
- 2:30 Discussion of RDP access and domain controller compromise.
- 8:00-10:00 Analysis of batch scripts used to delete backups and credentials.
- 23:20 Hash comparison between win.exe and windows.zip, confirming ransomware origin.
- 26:50 NS.exe functionality for network scanning and shared drive mounting.
- 29:30 Ransom note content and threat actor communication via Twitter/X.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
some hackers were trying to compromise an entire network by deploying ransomware now I know that's a pretty general statement in today's day and age that's common and happening all the time but let me tell you a story and give you some background context I'll be working out of my windows 11 virtual machine and I've got a folder on my desktop called investigation and I want to tell you about a recent case that we got to work part of our security Operation Center at my day job Huntress let me show you the incident report here now this is a case of ransomware so it's pretty clear hey the huntress agent has been tasked to isolate this host take that computer away from other computers on the network it's been quarantined and isolated so the incident wouldn't spread to other devices now of cours…