DiscoverOALabsLazy String Decryption Tips With IDA PRO and Shade Ransomware Unpacked!
Lazy String Decryption Tips With IDA PRO and Shade Ransomware Unpacked!

Lazy String Decryption Tips With IDA PRO and Shade Ransomware Unpacked!

Update: 2019-01-07
Share

Description

We use x64dbg debugger to unpack troldesh / shade ransomware then we use IDA PRO to quickly decrypt strings and resolve dynamic imports. Expand for details...

Original packed sample:
b1f13a9ef3da3c9bd2cfd0fcfd7368b48346a6995a91dd0edca12557773a7763
https://cape.contextis.com/analysis/28279/#

Ransom note:
https://pastebin.com/ghYY0xQE

Any.Run:
https://app.any.run/tasks/e1cd0797-c4d2-4a5c-aedf-20330a79fe3f

ID-Ransomware:
https://id-ransomware.malwarehunterteam.com/index.php

Talos FIRST (shared code identification):
https://www.talosintelligence.com/first

Build your own FREE malware analysis VM:
https://oalabs.openanalysis.net/2018/07/16/oalabs_malware_analysis_virtual_machine/

Michael's Ransomware Analysis YouTube channel:
https://www.youtube.com/channel/UCDbWhUnMdhxi2bo-oZQ1m3Q

Feedback, questions, and suggestions are always welcome : )

Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw

As always check out our tools, tutorials, and more content over at https://www.openanalysis.net

#IDAPro #Tutorial #ReverseEngineering
Comments 
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Lazy String Decryption Tips With IDA PRO and Shade Ransomware Unpacked!

Lazy String Decryption Tips With IDA PRO and Shade Ransomware Unpacked!

OALabs