In this first part we unpack a .NET based ransomware that uses a DLL to inject its payload.
The ransomware was crypted by Codelux according to MalwareHunterTeam.
My malware analysis course for beginners: https://www.udemy.com/course/windows-...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
Sample: https://www.hybrid-analysis.com/sampl...
DnSpy: https://github.com/0xd4d/dnSpy/releases
De4Dot: https://github.com/0xd4d/de4dot
Process Explorer: https://technet.microsoft.com/en-us/s...