Live Stream VOD: Lockbit 3.0 Embedded Binaries Analysis - Part 5
🕑 Added 2022-08-03 06:36:40 +0000 UTCOur final steam on Lockbit 3.0 ransomware! We complete our analysis of the third embedded binary. This is a tricky one, we need to use some debugging to decrypt the binary before we can begin our analysis...
Samples
Lockbit Ransomware: 80e8defa5377018b093b5b90de0f2957f7062144c83a09a56bba1fe4eda932ce
Embedded PE #1:
d641ad955ef4cff5f0239072b3990d47e17b9840e07fd5feea93c372147313c5
Embedded PE #2:
63c8efca0f52ebea1b3b2305e17580402f797a90611b3507fab6fffa7f700383
Embedded PE #3:
917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2
Embedded PE #3 (decrypted):
b1ae7316e73ceebb1b429dd707387bfd12fd489c2af0ed1083895195e7baf119
Notes:
Lockbit 3.0 - Analysis of The 3rd Embedded Binary
Comments
Slava Skoroda
great, thanks!
OALABS
Sorry about that, the link was broken. Fixed now! https://research.openanalysis.net/lockbit/lockbit3/yara/triage/ransomware/2022/07/07/lockbit3.html#Analysis-of-The-3rd-PE
Slava Skoroda
what is the link in notes?