Jaff Ransomware - A quick technical analysis
Автор: cybercdh
Загружено: 2017-05-16
Просмотров: 16077
A very quick technical view of Jaff Ransomware, delivered as a malicious PDF which drops a .docm file to the users machine and then downloads the ransomware. Here, I show you how to get indicators from a behavioural standpoint and also how to rip apart the code to get all other network indicators from the sample.
Hash covered here is MD5: 2b2c0737949a56528b0834f642ff2635
Link to the bluecoat.py code here: https://github.com/m0atz/bluecoat
Key IOCs from this sample can be found here: https://pastebin.com/5LEivkSp
Follow me on twitter: / cybercdh and feel free to drop me your questions below.
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: