Dashboard
Play ๐ฎ
Daily7
All Games
Account ๐
Sign Up
Login
Compete ๐
Global Leaderboard
Resources ๐
Blue Team Glossary
Dark mode
Light mode
Login and start playing
Leaving so soon?
×
You really want to log out? We were having so much fun!
Home
โบ
Glossary
โบ
Forensic Artifacts
โบ
ransom-note
ransom-note
Forensic Artifacts
Definition
A ransom note is the **message an attacker leaves for a victim after deploying ransomware**. It tells the victim what happened to their files or systems, how to pay the ransom, and what will supposedly happen if they donโt comply. The note is often placed in every affected folder (as a text file like `README.txt`) or displayed as a pop-up when the system boots. Some ransomware also changes the desktop wallpaper to the ransom note for extra visibility. A typical ransom note includes: * **Notification of encryption** โ โYour files have been encrypted.โ * **Payment demand** โ Usually in cryptocurrency (Bitcoin, Monero). * **Instructions** โ How to buy cryptocurrency, where to send it, how to contact the attacker. * **Threats** โ Loss of data, public data leaks (in **double extortion** cases), or higher ransom if the victim delays payment. * **Proof of decryption** โ Sometimes the attacker offers to decrypt one file for free to โproveโ they can restore data. Example (simplified): ``` All your files have been encrypted. Send 2 BTC to the address below to receive your decryption tool. If payment is not made within 5 days, your files will be permanently lost. ``` In an investigation, ransom notes are important clues: * **Attribution** โ Wording, formatting, and contact methods often match specific ransomware families or groups. * **Indicators of compromise (IOCs)** โ Email addresses, URLs, or cryptocurrency wallets in the note can be used to track other victims or campaigns. * **Timeline evidence** โ File timestamps for when notes were dropped can reveal when encryption occurred. Real-world examples: * **WannaCry (2017)** โ Displayed a red-and-white pop-up with a countdown clock. * **LockBit** โ Uses a templated text file with contact instructions and a link to its leak site. * **REvil (Sodinokibi)** โ Provided victims with a Tor link to a chat portal for negotiation. Further reading: * CISA StopRansomware โ [https://www.cisa.gov/stopransomware](https://www.cisa.gov/stopransomware) * Coveware Ransomware Trends โ [https://www.coveware.com/blog](https://www.coveware.com/blog) * MalwareBytes Ransomware Overview โ [https://www.malwarebytes.com/ransomware](https://www.malwarebytes.com/ransomware)
Explore More Terms
pipe
amcache
Status Code
powershell
DLP
Welcome back!
×
Sign in with Google
Sign in with Microsoft
OR SIGN IN WITH EMAIL
Remember me
Login
Continue as Guest
$ Loading KC7 Investigation Interface...