Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Failed reconstructing one of the Emotet's payloads #33

Closed
hasherezade opened this issue Mar 9, 2019 · 1 comment
Closed

Failed reconstructing one of the Emotet's payloads #33

hasherezade opened this issue Mar 9, 2019 · 1 comment
Assignees

Comments

@hasherezade
Copy link
Owner

Test case

0a4962325cf05ea602081647da910866d0d747abbb5d3340dfa721cdd93e9ba5 - Emotet

Problem

Emotet has 2 payloads. One of them is reconstructed correctly, while another is not.
dumped
Both payloads are detected:
payloads
Header from the payload that is not reconstructed is corrupt (we can see i.e. invalid Machine Id):
invalid_hdr

@hasherezade
Copy link
Owner Author

After the changes, both payloads are reconstructed correctly.
Report:
rec1
Dumps:
rec2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant