Unpacking GlobeImposter Ransomware With x32dbg

Published: 11 December 2017
on channel: OALabs
15,799
316

Open Analysis Live! In this tutorial we unpack a new version of GlobeImposter ransomeware using the X32bg / X64dbg debugger.

-----
OALABS DISCORD
  / discord  

OALABS PATREON
  / oalabs  

OALABS TIP JAR
https://ko-fi.com/oalabs

OALABS GITHUB
https://github.com/OALabs

UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/

-----

Original packed sample:
https://malshare.com/sample.php?actio...

Malware Traffic Analysis sample:
http://www.malware-traffic-analysis.n...

The x64bdg debugger:
https://x64dbg.com/#start

The unpacked sample:
https://malshare.com/sample.php?actio...

OAPivot the chrome plugin for IOC searching:
https://chrome.google.com/webstore/de...

Great blog on unpacking an earlier version of GlobeImposter:
http://www.vkremez.com/2017/08/lets-l...

Video explaining some anti-debugging tricks:
   • How To Defeat Anti-VM and Anti-Debug ...  

Anti-debugging cheat sheet (PDF):
http://anti-reversing.com/Downloads/A...

*Special hat-tip to Alex for recommending x64dbg and showing me some tricks:   / nullandnull  

Feedback, questions, and suggestions are always welcome : )

Sergei   / herrcore  
Sean   / seanmw  

As always check out our tools, tutorials, and more content over at http://www.openanalysis.net


Watch video Unpacking GlobeImposter Ransomware With x32dbg online without registration, duration hours minute second in high quality. This video was added by user OALabs 11 December 2017, don't forget to share it with your friends and acquaintances, it has been viewed on our site 15,799 once and liked it 316 people.