Reverse Engineering Ransomware - A Guided Tour

No ratings

Presented at BSidesDFW 2018 by

This presentation ditches PowerPoint for a slide-less walk through the internals of malicious software. Using the GandCrab ransomware as an illustrative example, Dr. McGrew will demonstrate for attendees the approach, techniques, and thought processes that are involved in extracting the capabilities and design of malicious software in the absence of source code. Those who are getting started in reverse engineering are often frustrated by overwhelming complexity and a lack of direction/defined-processes. In this demonstration, Dr. McGrew will demonstrate techniques for planning "what to do first/next" and making progress in a large or complex binary. The purpose of the demonstration is to give attendees with no RE experience an exposure to the interesting puzzle-solving aspects of reverse engineering.