logo

My Ransomware Post-Mortem

ID: aa8bb9b2-c531-5d25-b020-2ea1c35109b1

STIX ID: report--aa8bb9b2-c531-5d25-b020-2ea1c35109b1

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-01-09

Date Updated: 2026-04-27

Author: BHIS

...
...

A practitioner recounts an Osiris ransomware infection caused by a phishing email with a macro-enabled Excel attachment that encrypted files on one workstation but did not spread across the SOHO network. The impact was limited due to reliable backups and segmented network shares; the report highlights root causes (user enabled macros, insufficient user training), lessons learned, and remediation advice (test backups, restrict macros/execute-from-%Temp%, enforce least-privilege file shares, user education).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.