Home Artists Posts Import Register
Patreon importer is back online! Tell your friends ✅

Content

Our final steam on Lockbit 3.0 ransomware! We complete our analysis of the third embedded binary. This is a tricky one, we need to use some debugging to decrypt the binary before we can begin our analysis...

Samples

Lockbit Ransomware: 80e8defa5377018b093b5b90de0f2957f7062144c83a09a56bba1fe4eda932ce

Embedded PE #1:

d641ad955ef4cff5f0239072b3990d47e17b9840e07fd5feea93c372147313c5

Embedded PE #2:

63c8efca0f52ebea1b3b2305e17580402f797a90611b3507fab6fffa7f700383

Embedded PE #3:

917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2

Embedded PE #3 (decrypted):

b1ae7316e73ceebb1b429dd707387bfd12fd489c2af0ed1083895195e7baf119

Notes:

Lockbit 3.0 - Analysis of The 3rd Embedded Binary 

Files

Live Stream VOD: Lockbit 3.0 Embedded Binaries Analysis - Part 5

This is "Live Stream VOD: Lockbit 3.0 Embedded Binaries Analysis - Part 5" by OALABS on Vimeo, the home for high quality videos and the people who love them.

Comments

Slava Skoroda

what is the link in notes?

oalabs

Sorry about that, the link was broken. Fixed now! https://research.openanalysis.net/lockbit/lockbit3/yara/triage/ransomware/2022/07/07/lockbit3.html#Analysis-of-The-3rd-PE