Forum Discussion
GusC
Bronze III
5 months agoMalware Analysis: Shlayer
I've done the first 2 questions but stuck on the 3rd - what is the XOR key? Is this found in the first or second stage 7z compressed file? and....the lab description mentions Cyberchef - is this ava...
- 5 months ago
Mmmhh, i looked at the lab to help you. Noticed it was a hard one. Tried what was in my mind for the xor-key and it was right. This key only has 2 chars. A number and a letter. Try searching for ^ in ghidra.
good luck :)
RobN
Bronze III
5 months agoHow did you find the obfuscated_data on this one? I can see that _host appears to take its data from zzz43...24cl but when I look at this in the _DATA section the data is given as undefined?
- GusC5 months ago
Bronze III
Hi Rob - there's a bit of Hex just under that. Put them in CyberChef
recipe "from hex\auto" then "reverse by char" then "xor" with the 2 digit key.