Home Artists Posts Import Register
Patreon importer is back online! Tell your friends ✅

Content

In this live stream we take a different approach to analyzing the annoying string encryption in Zharkbot; dynamic analysis!

Sample

1aa0622a744ec4d28a561bac60ec5e907476587efbadfde546d2b145be4b8109 [UnpacMe]

Notes

Zharkbot Strings - Extracting strings from this downloader

Files

Tropical Live Stream VOD: Zharkbot Dynamic Analysis

Comments

m4n0w4r

Haha, the second time I load the explert.exe from tmp folder, and try to log the decrypted strings ...but not reveal the C2 address like your vid , bro :)). Try to figure out .... but dont know why :)). Nice vid!! Tks so much!

Karsten Hahn

The script for SSE patching is not available on pastebin anymore. Can you share it again?

oalabs

Ah shoot! Pastebin sucks! Luckily I was able to recover it from my IDB, uploaded here: https://gist.github.com/herrcore/2b8132b5e865a72d2006a3b34e155915