Forum Discussion

GusC's avatar
GusC
Icon for Bronze III rankBronze III
2 months ago
Solved

Malware Analysis: Shlayer

I've done the first 2 questions but stuck on the 3rd - what is the XOR key? Is this found in the first or second stage 7z compressed file? and....the lab description mentions Cyberchef - is this ava...
  • IotS2024's avatar
    IotS2024
    2 months ago

    Mmmhh, i looked at the lab to help you. Noticed it was a hard one. Tried what was in my mind for the xor-key and it was right. This key only has 2 chars. A number and a letter. Try searching for ^ in ghidra.

    good luck :)