Lazy String Decryption Tips With IDA PRO and Shade Ransomware Unpacked!
Update: 2019-01-07
Description
We use x64dbg debugger to unpack troldesh / shade ransomware then we use IDA PRO to quickly decrypt strings and resolve dynamic imports. Expand for details...
Original packed sample:
b1f13a9ef3da3c9bd2cfd0fcfd7368b48346a6995a91dd0edca12557773a7763
https://cape.contextis.com/analysis/28279/#
Ransom note:
https://pastebin.com/ghYY0xQE
Any.Run:
https://app.any.run/tasks/e1cd0797-c4d2-4a5c-aedf-20330a79fe3f
ID-Ransomware:
https://id-ransomware.malwarehunterteam.com/index.php
Talos FIRST (shared code identification):
https://www.talosintelligence.com/first
Build your own FREE malware analysis VM:
https://oalabs.openanalysis.net/2018/07/16/oalabs_malware_analysis_virtual_machine/
Michael's Ransomware Analysis YouTube channel:
https://www.youtube.com/channel/UCDbWhUnMdhxi2bo-oZQ1m3Q
Feedback, questions, and suggestions are always welcome : )
Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw
As always check out our tools, tutorials, and more content over at https://www.openanalysis.net
#IDAPro #Tutorial #ReverseEngineering
Original packed sample:
b1f13a9ef3da3c9bd2cfd0fcfd7368b48346a6995a91dd0edca12557773a7763
https://cape.contextis.com/analysis/28279/#
Ransom note:
https://pastebin.com/ghYY0xQE
Any.Run:
https://app.any.run/tasks/e1cd0797-c4d2-4a5c-aedf-20330a79fe3f
ID-Ransomware:
https://id-ransomware.malwarehunterteam.com/index.php
Talos FIRST (shared code identification):
https://www.talosintelligence.com/first
Build your own FREE malware analysis VM:
https://oalabs.openanalysis.net/2018/07/16/oalabs_malware_analysis_virtual_machine/
Michael's Ransomware Analysis YouTube channel:
https://www.youtube.com/channel/UCDbWhUnMdhxi2bo-oZQ1m3Q
Feedback, questions, and suggestions are always welcome : )
Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw
As always check out our tools, tutorials, and more content over at https://www.openanalysis.net
#IDAPro #Tutorial #ReverseEngineering
Comments
In Channel























