Extracting encrypted contents from Kronos Banking Trojan

Опубликовано: 15 Июнь 2026
на канале: cybercdh
9,125
425

Here I demonstrate to you how to identify and extract encrypted contents stashed away in the Resource section of malware. This is a common technique used by bad-guys to make analysis more difficult, as we are tasked with finding out how it's encrypted, how it's called in the code and how to extract it.

Here I show you some super-quick techniques to accomplish just that, using pestudio for initial analysis, using signsrch to identify encryption algorithms and using x64dbg to disassemble the binary.

Hopefully you've found this fun and interesting. If you did, please subscribe to my channel and follow me on   / cybercdh   for more.

Tools Used:
pestudio - https://www.winitor.com/
signsrch - http://aluigi.altervista.org/mytoolz.htm
x64dbg - https://x64dbg.com/#start
hxd - https://mh-nexus.de/en/hxd/

Sample discussed in this video:
MD5: 2a550956263a22991c34f076f3160b49