This analysis is solely reviewing and breaking down the C# code of the AESRTRansomware . Further analysis will be posted soon.

b6743906c49c1c7a36439a46de9aca88b6cd40f52af128b215f808a406a69598.exe.000a4f26_00076a12.png

Static Analysis

Hashes

md5 - 51d08f5a12c157b26ecf059779129b11

sha256 - b6743906c49c1c7a36439a46de9aca88b6cd40f52af128b215f808a406a69598

https://www.virustotal.com/gui/file/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745

<aside> 💡

Decryption Key - 678123

</aside>

Malware Language

C#

Reversing the Malware

After analysing the malware is programmed in c#, the tool dnSPY was used to extract the code. The Malware Includes four files whose detailed technical analysis is explained below -

encrypt.cs