Can this double-SIMPLEBLOB footer behavior in an AES-256/RSA CryptoAPI ransomware indicate an exploitable key-management bug? [migrated]
I am analyzing an unknown ransomware that appends .BRKD.
Normal encrypted files have the structure:
[AES ciphertext]
[12-byte CryptoAPI SIMPLEBLOB header]
[256-byte RSA-wrapped session key]
[8-byte ciphertext length]
The header is consis… Continue reading Can this double-SIMPLEBLOB footer behavior in an AES-256/RSA CryptoAPI ransomware indicate an exploitable key-management bug? [migrated]
