Analysis Of Nokoyawa Ransomware
Digging into the details of Nokoyawa At first glance, the Nokoyawa binary is not packed and protected by ransomware authors. As seen below, we can observe plain-text strings indicating some of the features of this ransomware. Figure 1: Strings of Nokoyawa ransomware not obfuscated. Nokoyawa command line options Nokoyawa has hardcoded several command line possibilities for customized executions, as shown in Figure 1, namely: -help: Print the list of available commands -network: Encrypt all local, network drives including network shares -file filePath: Encrypt a single file -dir dirPath: Encrypt selected folder and sub-folders...