Analyzing Ransomware - Beginner Static Analysis

แชร์
ฝัง
  • เผยแพร่เมื่อ 1 ส.ค. 2024
  • Today we will do some basic static analysis on a ransomware sample.
    P.S. Sorry about the volume, I've hopefully fixed it in newer videos.
    Sample: www.hybrid-analysis.com/sampl...
    VirtualBox: www.virtualbox.org/
    DIE: ntinfo.biz/
    PEStudio: www.winitor.com/
    More information on the sample analyzed: www.bleepingcomputer.com/news...
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 37

  • @sahilgupta7499
    @sahilgupta7499 5 ปีที่แล้ว +2

    I came across these videos just at the right time when I was not able to find the much content over it. Looking forward to more uploads on this from you. Thanks for doing this.

  • @stephen7715
    @stephen7715 5 ปีที่แล้ว +6

    This man is a legend. We need more people like you. Thanks for the help man.

    • @mailtoleki666
      @mailtoleki666 5 ปีที่แล้ว +1

      Yep he is awesome. he helped me too bro

  • @Atykifobia
    @Atykifobia 3 ปีที่แล้ว

    Fantastic, exactly what I was looking for as a curious beginner. Thank you!

  • @4SecuriTI2
    @4SecuriTI2 5 ปีที่แล้ว

    Thanks for sharing. Excellent work!

  • @mailtoleki666
    @mailtoleki666 5 ปีที่แล้ว

    You are awesome man. Thank you for cracking the keys.

  • @OALABS
    @OALABS 5 ปีที่แล้ว +8

    Hey this is great! Subscribed! Hope you make more of these : )

    • @OALABS
      @OALABS 5 ปีที่แล้ว +1

      Also blob analyzer looks rad! Looking forward to you releasing it!!

  • @coyzor
    @coyzor 5 ปีที่แล้ว

    Thank you

  • @AlejandroSanchezz
    @AlejandroSanchezz 5 ปีที่แล้ว

    Thanks for sharing

    • @4SecuriTI2
      @4SecuriTI2 5 ปีที่แล้ว

      Esa herramienta para verificar la clave publica se ve muy útil.

  • @kirillstarodubtsev6125
    @kirillstarodubtsev6125 4 ปีที่แล้ว

    Thanks!

  • @ahmedbellil5161
    @ahmedbellil5161 4 ปีที่แล้ว

    thanks

  • @kienmanowar
    @kienmanowar 5 ปีที่แล้ว +1

    Thanks for your video! Can you share the link about CryptoTester tool? I try GG but can not find...

    • @MassimilianoDalCero
      @MassimilianoDalCero 3 ปีที่แล้ว

      twitter.com/demonslay335/status/1225819538652061696

  • @gustavoaguilar3394
    @gustavoaguilar3394 9 หลายเดือนก่อน

    Hi Michael, how are your? I fine, I wanted to know if you have a sample malware static analysis report in PDF. docx. Thanks

  • @abdulkareemkudaisi25
    @abdulkareemkudaisi25 5 หลายเดือนก่อน

    Hi. Pls I was attacked by a virus with the .itrz file extension. Can u help me out?

  • @berrahayat1645
    @berrahayat1645 5 ปีที่แล้ว

    I need Axcrypt decrypt. Please help me

    • @Demonslay335
      @Demonslay335  5 ปีที่แล้ว

      That one uses a legit third-party encryption program that is secure. No way to break it. Restore from backups.

  • @kunalpatel7482
    @kunalpatel7482 4 ปีที่แล้ว

    Hello sir my files are converted into . Lalo extension please give me a tool to decrypt those files please.

    • @Demonslay335
      @Demonslay335  4 ปีที่แล้ว

      Do not spam me. I replied to your other comment on another video. Read. It.

  • @ark9083
    @ark9083 4 ปีที่แล้ว

    sir help me how i can recoverd my pics it mean alot to me , the fucking file is .btoss plz help me any body plz

  • @kannthu
    @kannthu 5 ปีที่แล้ว

    Hey, isn't it dangerous to test malware on virtual machine? In some cases malware can escape virtual machine, so better question is " is there safe way to test malware"?

    • @Demonslay335
      @Demonslay335  5 ปีที่แล้ว +3

      It's certainly "safe-er" than running on your own system. There are technically some VM escape exploits out there, but they are usually patched pretty quick. Also, I have honestly never ran into a malware using one so far; I tend to focus on the "simpler" ones. There are steps for hardening your VM a bit more out there. Ideally, it probably would be argued that you should analyse on separate hardware entirely, but I'm no expert on that subject. :)

    • @MalwareAnalysisForHedgehogs
      @MalwareAnalysisForHedgehogs 5 ปีที่แล้ว +5

      If you have a host machine using a different operating system than the VM you are pretty safe, e.g. you might have a linux distro for your host machine and Windows for your VM. I have never encountered malware so far that is multipartite AND can escape from a VM to infect the OS of the host and it would probably not be worth it making.
      Apart from that, a dedicated machine to analyse malware on it, is ideal.

  • @BrunoMedeiros-lh6bm
    @BrunoMedeiros-lh6bm 3 ปีที่แล้ว

    I need your help please i need contact you

  • @ark9083
    @ark9083 4 ปีที่แล้ว

    .btos ransomware