Attachments
(7.82 KiB) Downloaded 87 times
A forum for reverse engineering, OS internals and malware analysis
xors wrote:Locky uses .thor extension and 'EnhancedStoragePasswordConfig 147' as a parameter.Can you share the packed file / vt link?
lodo wrote:xors wrote:Locky uses .thor extension and 'EnhancedStoragePasswordConfig 147' as a parameter.Can you share the packed file / vt link?
Thanks.
Kick10 wrote:Who knows latest launch parameters?Should be text.
Kick10 wrote:Who knows latest launch parameters?In recent campaings, they use different parameters. For example 'aaa' + random number, 'ccc' + random number , 'text'