- Sample name / ID:
- Family (or "unknown"):
- SHA-256:
- File type / architecture:
- Date analyzed:
- One-paragraph description of what the sample does:
![Diagram][./artifacts/diagram.png]
- Key functions identified / named:
- Encryption routine located:
- File traversal / payload logic:
- Obfuscation / packing:
- Runtime behavior confirmed:
- Files encrypted / touched observed:
- Relevant memory observations (keys, buffers, IVs):
- Static assumptions validated / corrected:
- File / OS behavior:
- Crypto-related:
- Algorithms / modes used:
- Custom vs standard crypto:
- Hashes / KDFs (if any):
- Key generation method:
- Key size / strength:
- Scope (per-file, per-victim, global):
- Storage / lifetime:
- Order of operations documented:
- Relation to file traversal:
- Obvious flaws identified:
- Or explicitly: "No practical crypto weakness found"
Optional / Responsible POC:
- High-level pseudocode:
- Decryption feasibility statement: