Home Artists Posts Import Register

Content

In this Twitch stream we unpack Pandora Ransomware and begin analyzing the control flow obfuscation used in the payload. The obfuscation is a type of control flow flattening that we begin to remove with a combination of IDA scripts and emulation with dumpulator.

Sample: 5b56c5d86347e164c6e571c86dbf5b1535eae6b979fede6ed66b01e79ea33b7b 

Research notes are available with code: Pandora Ransomware 

Files

Live Stream VOD: Pandora Ransomware Unpacking and Control Flow Deobfuscation Part 1

This is "Live Stream VOD: Pandora Ransomware Unpacking and Control Flow Deobfuscation Part 1" by OALABS on Vimeo, the home for high quality videos and...

Comments

No comments found for this post.