You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Its a starigtforward obfuscation. The function Tightness which takes the decimal value and return ASCII, which is (101) for letter 'e', and after deobfuscation and building the final URL, we can see proper clean code.
23
+
Its a starigtforward obfuscation. The function Tightness which takes the decimal value and return `ASCII`, which is (101) for letter 'e', and after `deobfuscation` and building the final URL, we can see proper clean code.
So we have a propblem here, while i am analysing the sample the content or the payload which need to get downloaded during the execution of the above vbs script is no more availble in the pastebin.... so how are we going to analyse it....!!!!
33
+
So we have a problem here, while I am analysing the sample the content or the payload which need to get downloaded during the execution of the above `vbs` script is no more available in the pastebin.... so how are we going to analyse it....!!!!
34
34
35
-
After seraching alot on internet, i was not getting the same file from any sandbox or from any Malware sample stores, So while I discussed the situation with my friend "[`Binary Panda`](https://binarypanda.me/)" who does similiar stunts with malware, so we both where trying to find the sample in different `sandboxes`. Meanwhile we saw in one of the popular sandbox we saw there is way to download pcap files for the sample which it has analyzed. That triggered a good idea!! Why cant we recreate the sample back from the pcap file!!!!
35
+
After seraching alot on internet, I was not getting the same file from any sandbox or from any Malware sample stores, So while I discussed the situation with my friend "[`Binary Panda`](https://binarypanda.me/)" who does similiar stunts with malware, so we both where trying to find the sample in different `sandboxes`. Meanwhile we saw in one of the popular sandbox we saw there is way to download pcap files for the sample which it has analyzed. That triggered a good idea!! Why cant we recreate the sample back from the pcap file!!!!
0 commit comments