Unpacking Princess Locker and Fixing Corrupted PE Header (OALabs x MalwareAnalysisForHedgehogs)
Update: 2018-04-08
Description
Open Analysis Live teams up with MalwareAnalysisForHedgehogs to unpack Princess Locker ransomware. We show how to use x64dbg and hooks on VirtualAlloc to dump the unpacked payload then fix the corrupted PE header...
Many thanks to Karsten from MalwareAnalysisForHedgehogs!! Check out his channel for some awesome videos on unpacking and malware analysis!
https://www.youtube.com/channel/UCVFXrUwuWxNlm6UNZtBLJ-A
Packed:
SHA256: dc7ab2e7ed26554a11da51a184e95b01e685b1a2f99c7fc77d54d5966530bf60
https://malshare.com/sample.php?action=detail&hash=93cb0053e883fb262f9f795f327152f8
Unpacked:
SHA256: ec3a44babff75b7022fc7373bf779cac5a4243e8e81ce0e7a3fbb72558d4fca6
https://malshare.com/sample.php?action=detail&hash=49dbf3e4a78e87f87f0bfd90d9e42338
Corkami PE Poster:
https://github.com/corkami/pics/blob/master/binary/pe101/pe101.pdf
X64dbg
https://x64dbg.com/#start
PEBear
https://github.com/hasherezade/releases/releases/tag/0.3.8
HxD hex editor
https://mh-nexus.de/en/hxd/
Feedback, questions, and suggestions are always welcome : )
Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw
As always check out our tools, tutorials, and more content over at http://www.openanalysis.net
Many thanks to Karsten from MalwareAnalysisForHedgehogs!! Check out his channel for some awesome videos on unpacking and malware analysis!
https://www.youtube.com/channel/UCVFXrUwuWxNlm6UNZtBLJ-A
Packed:
SHA256: dc7ab2e7ed26554a11da51a184e95b01e685b1a2f99c7fc77d54d5966530bf60
https://malshare.com/sample.php?action=detail&hash=93cb0053e883fb262f9f795f327152f8
Unpacked:
SHA256: ec3a44babff75b7022fc7373bf779cac5a4243e8e81ce0e7a3fbb72558d4fca6
https://malshare.com/sample.php?action=detail&hash=49dbf3e4a78e87f87f0bfd90d9e42338
Corkami PE Poster:
https://github.com/corkami/pics/blob/master/binary/pe101/pe101.pdf
X64dbg
https://x64dbg.com/#start
PEBear
https://github.com/hasherezade/releases/releases/tag/0.3.8
HxD hex editor
https://mh-nexus.de/en/hxd/
Feedback, questions, and suggestions are always welcome : )
Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw
As always check out our tools, tutorials, and more content over at http://www.openanalysis.net
Comments
In Channel























