View Single Post
  #6  
Old 06-24-2021, 02:22
CodeCracker CodeCracker is offline
Family
 
Join Date: Jun 2011
Posts: 333
Rept. Given: 19
Rept. Rcvd 270 Times in 84 Posts
Thanks Given: 13
Thanks Rcvd at 1,151 Times in 251 Posts
CodeCracker Reputation: 200-299 CodeCracker Reputation: 200-299 CodeCracker Reputation: 200-299
From my analyzes of the ransom globeimposter, this ramsoware uses RSA-2048 and AES-128, as far as I know there is no plain text attack of AES-128, and AES key is just some random bytes initialized at execution time; and the key will differ on each run.
So still don't know how the decryption is possible.
Reply With Quote