DiscoverOALabsUnpacking Princess Locker and Fixing Corrupted PE Header (OALabs x MalwareAnalysisForHedgehogs)
Unpacking Princess Locker and Fixing Corrupted PE Header (OALabs x MalwareAnalysisForHedgehogs)

Unpacking Princess Locker and Fixing Corrupted PE Header (OALabs x MalwareAnalysisForHedgehogs)

Update: 2018-04-08
Share

Description

Open Analysis Live teams up with MalwareAnalysisForHedgehogs to unpack Princess Locker ransomware. We show how to use x64dbg and hooks on VirtualAlloc to dump the unpacked payload then fix the corrupted PE header...

Many thanks to Karsten from MalwareAnalysisForHedgehogs!! Check out his channel for some awesome videos on unpacking and malware analysis!
https://www.youtube.com/channel/UCVFXrUwuWxNlm6UNZtBLJ-A

Packed:
SHA256: dc7ab2e7ed26554a11da51a184e95b01e685b1a2f99c7fc77d54d5966530bf60
https://malshare.com/sample.php?action=detail&hash=93cb0053e883fb262f9f795f327152f8

Unpacked:
SHA256: ec3a44babff75b7022fc7373bf779cac5a4243e8e81ce0e7a3fbb72558d4fca6
https://malshare.com/sample.php?action=detail&hash=49dbf3e4a78e87f87f0bfd90d9e42338

Corkami PE Poster:
https://github.com/corkami/pics/blob/master/binary/pe101/pe101.pdf

X64dbg
https://x64dbg.com/#start

PEBear
https://github.com/hasherezade/releases/releases/tag/0.3.8

HxD hex editor
https://mh-nexus.de/en/hxd/

Feedback, questions, and suggestions are always welcome : )

Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw

As always check out our tools, tutorials, and more content over at http://www.openanalysis.net
Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Unpacking Princess Locker and Fixing Corrupted PE Header (OALabs x MalwareAnalysisForHedgehogs)

Unpacking Princess Locker and Fixing Corrupted PE Header (OALabs x MalwareAnalysisForHedgehogs)

OALabs