August 14, 2026
Compromised Windows Server 2022 (simulation)
Image Source: https://cfreds.nist.gov/all/BenjaminDonnachie/CompromisedWindowsServer2022simulation

By Courting Cyber
7 min read
Scenario: Simulated UK-based small office network running from Sept 2023 to Feb 2024. The administrator opened RDP to facilitate working from home. As part of the scenario, on 12th Feb 2024 discovered the server was no longer responding with 'Red Petya' ransomware displayed on the screen. Forensic experts were engaged, the disk decrypted and a forensic image taken in EnCase E01 format (also known as Expert Witness Format). All information contained within the image (including but not limited to usernames and IP addresses) is synthetic.
Introduction
A simulated UK based small Office network was running from September 2023 to February 2024. The administrator of the office allowed RDP traffic between the office network and their home in order to facilitate working from home. On 12th February 2024, it was discovered that the server was no longer responding and 'Red Petya' ransomware was displayed on the screen. Courting Cyber was engaged to investigate this incident.
On 05th February 2024 10:55:56 UTC a remote attacker successfully logged on to the host "WIN-NI9FBK23SLO" using the "Administrator" account. Later, on the same date, at 23:00 UTC , a successful Remote Desktop Protocol (RDP) logon from attacker infrastructure was observed, after which the attacker established interactive access to the server. This highly privileged account then allowed the attacker to import their tools, perform internal reconnaissance, deploy persistence mechanisms, move laterally and deploy ransomware on other hosts on the network on 09th February 2024.
After gaining access to the environment, another account, "admin", was created and added to the Domain Admins group, essentially giving it administrative privileges through out the domain. This newly created account was used to carry out the malicious activities.
On the host "WIN-NI9FBK23SLO" an archive was created, which contained files from the "C:\shares" folder on the compromised host. The creation of the archive may have been preparation to exfiltrate the information from the network. However, no network logs were available for analysis to confirm whether exfiltration occurred.
On 09th February 2024 22:52 UTC the scheduled task, "Enterpries backup", which executes the Petya ransomware, was executed on six remote hosts (Desktop-001 through Desktop-006).
Recommendations
· Disable the following accounts:
- Administrator
- Admin (SID ending -2611)
· Remove and Scheduled Task "Enterpries backup"
· Block the following IP addresses:
- 185[.]229[.]66[.]183
- 185[.]239[.]106[.]67
- 36[.]133[.]110[.]87
· Review proxy, firewall, VPN and IDS logs for historical communication with these addresses.
· Perform password resets for:
- Administrator
- Domain Admin accounts
- Service accounts
- Accounts used on compromised hosts
· Review and reduce reliance on NTLM authentication. Where operationally feasible, transition systems and services to Kerberos authentication and implement Microsoft's NTLM auditing controls to identify legacy dependencies.
· Review locations where credentials may have been stored:
- Spreadsheets
- Password documents
- Browser credentials stores
- Saved RDP credentials
· Investigate domain wide activity for the "Administrator" and "admin" accounts
· Review the following log sources to determine whether data exfiltration may have occurred:
- Firewall
- Netflow
- Proxy
- EDR
· Review the contents of share.zip and determine:
- Business sensitivity
- Credential exposure
- Client/customer information
- Intellectual property
- Regulatory implications
· Strict control over when Administrator accounts are used should be developed. Measures such as the following should be implemented:
- Separate administrative accounts
- Tiered administration
- Privileged Access Workstations
- Just Enough Administration
· Multi Factor Authentication (MFA) should be implemented for:
- RDP access
- Administrative accounts
- Privileged remote management
- VPN Access
· Detections should be created for:
- New admin account creation
- Domain Admin group modifications
- PsExec execution
- Nmap execution
- External FTP connections
- Excessive failed logons followed by successful ones
Findings
On 04th February 2024 23:37:38 UTC a brute-force attack originated from the host "kali" at IP "36[.]133[.]110[.]87". A brute-force attack occurs when an adversary repeatedly tries many password combinations until the correct one is found. After numerous failed NTLM authentication attempts against the "Administrator" account, a successful authentication occurred on 05th February 2024 10:55:56 UTC. The source IP "36[.]133[.]110[.]87" geolocates to China and is owned by China Mobile Communications Group Co., Ltd. Reputation checks across Open Source Intelligence (OSINT) sources did not reveal any known malicious associations. The IP is categorised as ASN Type: ISP, suggesting it is an ISP-managed network rather than cloud, VPN, or hosting infrastructure.
Numerous successful remote logins were observed on multiple occasions from the IP "195[.]21[.]1[.]97", and host "ADMIN-WFH" using the "Administrator" account. The first, from the available logs, occurred on 05th February 2024 08:52:02 UTC. Examination of the IP address using OSINT sources did not reveal known malicious activity associated with it. Furthermore, these were confirmed as legitimate administrative activity.
On 05th February 2024 22:43:02 UTC the first login attempt from the IP "185[.]229[.]66[.]183" with hostname "kali" was observed. After several failed attempts, the attacker eventually logged in successfully for the first time from this IP on 05th February 2024 22:55:18 UTC using the "Administrator" account. Throughout this incident RDP sessions were associated with the logins by the threat actor, the first of which was observed on this date at 23:00 UTC.
The source IP "185[.]229[.]66[.]183" geolocates to Finland and is owned by PSERVERS Enterprise Network. Reputation checks across OSINT sources did not reveal any known malicious associations. The IP is categorised as ASN Type: Hosting, indicating it is associated with datacentre or hosting infrastructure rather than a traditional residential or enterprise Internet Service Provider. Hosting infrastructure can be leveraged for anonymisation, VPN services, or attacker-operated systems.
On 05th February 2024 23:02:22 UTC, following another login by the "Administrator" account from IP "185[.]229[.]66[.]183", the account "A Admin" (SID ending with 2611) was added to the Local Administrators group on the host. Prior to this, that account was newly created on the host. The malicious activity that was observed on the host originated from this newly created account, SID ending with 2611. This account was also observed in the logs as "admin". Approximately three minutes after being created and added to the Local Administrators group, the first login for the "admin" account was observed from the remote host "kali" with IP "185[.]229[.]66[.]183".
At 23:13 UTC on the same date, Sysinternals Suite was downloaded. Sysinternals is a collection of Microsoft utilities used by IT professionals, system administrators, and cybersecurity analysts to troubleshoot, monitor, diagnose, and investigate Windows systems. These tools can also be abused by threat actors. The "Sysinternalssuite.zip" file was then deleted at 23:14 UTC.
At 23:23 UTC another login was observed from the remote host "kali" using the "Administrator" account. Then at 23:24 UTC the account "A Admin" (SID ending with 2611) was added to the Global Domain Admins Group. Members of this group are administrators across all domain-joined systems by default and can manage users, computers, group policies, servers, and many core domain functions. In a compromise, attackers frequently add a controlled account to Domain Admins because it effectively grants them enterprise-wide administrative access.
At 23:28 UTC the file "C:\Users\admin\Desktop\share.zip" was created. "share.zip" was 694.7MB in size and contained files from the "C:\shares" folder on the compromised host. The files within this directory appear to be work product and contain files which house sensitive information. "share.zip" was deleted on 06th February 2024 22:14 UTC.
On 5th February 2024 23:41 the nmap setup binary was written to "\Downloads\nmap-7.93-setup.exe". Nmap (Network Mapper) is an open-source network scanning and security auditing tool used to discover devices, identify open ports, detect running services, and gather information about hosts on a network. This tool may be used legitimately by administrators but is also used by threat actors to perform reconnaissance within a compromised environment. Examination of Microsoft Edge's browsing history found that Bing search was used to find Nmap for download.
Zenmap is the official graphical user interface for the nmap scanner. It often contains files which indicate the type of activity that occurred on the host. Examination of the "C:\Users\admin.zenmap\target_list.txt" found that scans were run against "10.44.0.12/16; 10.44.24.1/24" IP range. The results were written to .xml files located "C:\Users\admin\Desktop\maps". The results within the file "202402071016 Intense scan on 10.44.24.1_24.xml" indicate that the scans found other hosts within the network, which were subsequently attacked.
On 06th February 2024 at 19:52 UTC and 19:53 UTC, the accounts "Administrator" and "admin" logged in for the first time from the IP address "31[.]220[.]85[.]162", respectively. The source IP "31[.]220[.]85[.]162" geolocates to France and is attributed to Contabo GmbH (AS51167), a legitimate hosting and VPS provider. The IP address is classified as Data Center/Web Hosting/Transit infrastructure rather than a residential or enterprise ISP network. While historical abuse reports exist for the IP, no current adverse reputation indicators were identified.
On 06th February 2024 20:13:40 UTC "rename.exe" was written to the host at "C:\Users\admin\Desktop". Static and dynamic analysis of the binary found that it is the Petya ransomware executable. Petya is a ransomware strain that was first identified in 2016. It usually encrypts the computer's entire disk. At 21:09 UTC on the same day, zenmap.exe was executed.
A scheduled task named "Enterpries backup" was created by the attacker-controlled account "BRANCHOFFICE\admin" on 06th February 2024 21:49:21 UTC. The task was configured to execute PsExec.exe with stored credentials (admin / letmein) and deploy "rename.exe" to six remote hosts (Desktop-001 through Desktop-006). PsExec is a light-weight tool that lets the user execute processes on other systems, complete with full interactivity for console applications, without having to manually install client software. The scheduled task being used to invoke this tool demonstrates intent to perform automated remote execution within the environment. The targeted hosts were found in the zenmap scans that were discussed previously.
On 07th February 2024 16:57 UTC, the admin account interacted with an FTP resource located at "ftp://kali@185.239.106.67/branchoffice.example.com". The naming convention of the remote directory suggests it may have been created to store data associated with the compromised environment. Along with the staged files within the "share.zip" archive, this suggests that files could have been exfiltrated from the environment. However, network-based logs would need to be analysed for this to be confirmed.
On 09th February 2024 22:52 UTC the scheduled task, "Enterpries backup", which executes the Petya ransomware was run. Approximately sixty-six minutes later, the attacker logged in for the final time from the host "kali" at IP "31[.]220[.]85[.]162".
Evidence List
[Embedded content: 9be4ff914179957028f54dfa9167a38c]
Incident Timeline
[Embedded content: abe3c3c6829c197cf89b6c78a82e741e]
Indicators of Compromise (IOCs)