Open Analysis Live! In this tutorial we unpack a new version of GlobeImposter ransomeware using the X32bg / X64dbg debugger.
-----
OALABS DISCORD
/ discord
OALABS PATREON
/ oalabs
OALABS TIP JAR
https://ko-fi.com/oalabs
OALABS GITHUB
https://github.com/OALabs
UNPACME - AUTOMATED MALWARE UNPACKING
https://www.unpac.me/#/
-----
Original packed sample:
https://malshare.com/sample.php?actio...
Malware Traffic Analysis sample:
http://www.malware-traffic-analysis.n...
The x64bdg debugger:
https://x64dbg.com/#start
The unpacked sample:
https://malshare.com/sample.php?actio...
OAPivot the chrome plugin for IOC searching:
https://chrome.google.com/webstore/de...
Great blog on unpacking an earlier version of GlobeImposter:
http://www.vkremez.com/2017/08/lets-l...
Video explaining some anti-debugging tricks:
• How To Defeat Anti-VM and Anti-Debug ...
Anti-debugging cheat sheet (PDF):
http://anti-reversing.com/Downloads/A...
*Special hat-tip to Alex for recommending x64dbg and showing me some tricks: / nullandnull
Feedback, questions, and suggestions are always welcome : )
Sergei / herrcore
Sean / seanmw
As always check out our tools, tutorials, and more content over at http://www.openanalysis.net
Watch video Unpacking GlobeImposter Ransomware With x32dbg online without registration, duration hours minute second in high quality. This video was added by user OALabs 11 December 2017, don't forget to share it with your friends and acquaintances, it has been viewed on our site 15,799 once and liked it 316 people.