A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #30361  by xors
 Wed May 17, 2017 7:07 pm
Another one. It contains an interesting pdb path. "D:\Arena\Cryptor_AES-RSA_V13\Release\Encoder.pdb"

The configuration of the ransomware is stored in the resources.
Attachments
password:infected
(130.71 KiB) Downloaded 89 times