Huntress SOC analysts investigated two endpoints minimally impacted by ransomware, where initial access was gained through TeamViewer remote connections. Log analysis from TeamViewer's connections_incoming.txt revealed both endpoints were accessed from the same source machine (WIN-8GPEJ3VGB8U) on December 21, 2023. The threat actor deployed a DOS batch file that executed a LockBit 3.0 DLL via rundll32.exe. On one endpoint, installed security software quarantined the ransomware files before significant damage occurred. The incident highlights the risk of legacy or poorly managed TeamViewer installations and the importance of maintaining a complete application inventory as part of basic security hygiene. IOCs including the attacker's endpoint name and DLL SHA256 hash are provided.