Reverse Engineering Mallox Ransomware - Malware Analysis @GuidedHacking
Reverse Engineering Mallox Ransomware - Malware Analysis  @GuidedHacking
Uploaded December 2022 | Updated September 2026, 2 weeks ago
$2000 Ransomware - let's take a look
Support us on GH: guidedhacking.com/register
Support us on Patreon: patreon.com/guidedhacking
Support us on YT: youtube.com/channel/UCCMi6F5Ac3kQDfffWXQGZDw/join

oin Fred HK from Guided Hacking as we dive deep into the analysis of Mallocs Ransomware. In this comprehensive walkthrough, we cover everything from language ID checks, gaining privileges, disabling protection, and encryption functions to C2 communications, and restoring system functions. This video is perfect for anyone interested in learning about the inner workings of ransomware and malware analysis.

Mallox Ransomware Analysis Article
guidedhacking.com/threads/mallox-ransomware-malware-analysis.20165

This 32bit Mallox ransomware, written in C++, is not obfuscated and its strings are easily readable, thus making analysis simpler.

Analyzing the malware with IDA Pro, the main function calls GetUserDefaultLangID to determine the victim's language ID. This is then compared to IDs of countries in the CIS, to prevent infection in these places, as the local law in Russia is more favorable towards the threat actors who do not distribute malware in the CIS.

Continuing malware analysis in IDA Pro, Mallox ransomware sets up the Active scheme of the victim's power supply to run optimally. It obtains privilege for its execution, and shuts down database services and disables Rancine, a tool that tries to prevent ransomware.

After removal, malware analysis can continue. The Ransomware encrypts HDD, creates a public key, and inserts it into a "HOW TO RECOVER" doc. Then, Mallox ransomware encrypts files and notifies the C2 of a locked target. Finally, the ransomware restores settings and exits.

00:00 - Introduction
00:16 - Language ID and CIS Country Check
01:07 - Gaining Privileges and Disabling Protection
02:00 - Disabling Services and Databases
03:22 - Editing Registry Keys and Shutdown Prevention
04:38 - Main Encryption Function
06:09 - How to Recover File and Key Replacement
07:15 - C2 Communications and Infection Information
08:20 - Target Info File and Decryption Process
09:07 - Restoring System Functions and Conclusion

Follow us on Facebook : bit.ly/2vvHfhk
Follow us on Twitter : bit.ly/3bC7J1i
Follow us on Twitch : bit.ly/39ywOZ2
Follow us on Reddit : bit.ly/3bvOB57
Follow us on GitHub : bit.ly/2HoNXIS
Follow us on Instagram : bit.ly/2SoDOlu
Reverse Engineering Mallox Ransomware - Malware AnalysisReverse engineering just got a whole lot easier! 🎮MASTER Video Game REVERSE ENGINEERING in 10 Minutes!Best SysInternals Tools for Malware AnalysisCheat Engine Debugging Assembly & Fixing Control Flow GraphsBYPASS Anti-Cheat with this one WIERD TRICK!Reverse Engineering Banking Trojan MalwareExploiting a Partial Return Address Overwrite - Exploit Dev 10Python Game Hacking Tutorial - Simple External CheatMaster Linux Fuzzing with AFL Fuzzerwhen the anticheat ships without virtualization....Anticheat Development Course - Dont Miss Out!
Guided Hacking |

Reverse Engineering Mallox Ransomware - Malware Analysis

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER