Skip to content

LAYALELMAMOUN/ReversingWannacry

 
 

Repository files navigation

ReversingWannacry

These are the scripts and Ghidra projects for my Reversing Wannacry series:

Extracting the Ghidra projects and the resources

Note that the Ghidra project and the files in the resources ZIP file will probably trigger your AV!

The Ghidra projects and the DLL are in an encrypted ZIP, protected by the password "ghidra".

Extracting the part of t.wnry

Simply run:

dd if=t.wnry of=encrypted_aes_key bs=1 skip=12 count=256
dd if=t.wnry of=large_chunk.bin skip=280 bs=1

Importing the Ghidra projects

The Ghidra projects are exported as ZIP files. You can simply drag them into the Ghidra project screen.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C++ 77.6%
  • Python 22.4%