Skip to main content
PaperCut RCE to Bl00dy Ransomware operation cover
IntermediateSIEMXDRFirewallPRO

PaperCut RCE to Bl00dy Ransomware

Bl00dy ransomware actors exploited an unauthenticated access-control flaw (CVE-2023-27350) on an internet-facing PaperCut MF/NG print-management server, ran code as the application service account, staged a TrueBot loader and a Cobalt Strike beacon, installed Atera and AnyDesk for hands-on remote access, moved laterally over RDP, tunnelled the file share out through a Tor helper, and deployed the Bl00dy encryptor fleet-wide. Reconstruct the intrusion from SIEM, endpoint XDR, and perimeter firewall telemetry and classify the key ATT&CK techniques.

1h
8 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Find the foothold

30

Before anything else moved, someone reached the public print server without ever logging in and made it run code. Identify the external address behind the unauthenticated requests that took over the application.

Hint available
3

Classify the initial access

15

No credential was phished and no endpoint was infected. The attacker abused the internet-facing application itself. Map the initial breach to its MITRE ATT&CK technique.

Hint available
4

Recover the loader hash

35

From the foothold the attacker pulled a payload that unpacked a command-and-control loader to disk. Pin down its file-level indicator so it can be hunted fleet-wide. Provide the SHA-256 of the loader DLL.

Hint available
5

Trace the loader C2

30

The loader called home. Correlate the host beacon with the name resolution and the perimeter egress, and identify the command-and-control domain it reached.

Hint available
6

Classify the remote-access tooling

20

Rather than rely only on its malware, the crew installed legitimate management software to keep hands-on control. Identify the MITRE ATT&CK technique that covers this.

Hint available
7

Trace the data theft

35

Before encrypting anything, the attacker tunnelled data out for leverage. Correlate the host activity with the perimeter egress and identify the external endpoint that received the stolen file share.

Hint available
8

Classify the impact

20

Roughly ninety minutes after the initial exploit, files across several servers were encrypted. Classify the final objective with its MITRE ATT&CK technique.

Hint available

8 tasks · 185 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all