Multiple anti debugging tricks, etc...analyzes are welcome ;)
Attachments
infected
(608.61 KiB) Downloaded 49 times
(608.61 KiB) Downloaded 49 times
A forum for reverse engineering, OS internals and malware analysis
xors wrote:Hi again,If you wanted to know if he made it himself why don't you just bindiff the files.
I had a quick look at it. It looks like a ransomware from a cyber security challenge (Enisa Cyber Europe 2016?). Powershell script, kemel32.dll (a dll which is dropped to %appdata%) and the payload (ransomware?) in the attachment.