Home Artists Posts Import Register

Content

This is the second part in our analysis of RansomHouse ransomware loader. In this stream we rebuild a custom PE format used by the loader.

Sample

acf361296c9e1cf5b4ceff11e1790c57e6e1d753df9bef087aadad256dc5a123

No notes, just pure RE and chill 🍹👾

Files

Live Steam VOD: RansomHouse Part 2 - PE Rebuilding

Comments

Karsten Hahn

Using IMAGE_NT_HEADERS64 instead of IMAGE_NT_HEADERS would have fixed the misaligned access to the data directory