Forum Discussion
GusC
Bronze III
5 months agoMalware Analysis: Shlayer
I've done the first 2 questions but stuck on the 3rd - what is the XOR key? Is this found in the first or second stage 7z compressed file? and....the lab description mentions Cyberchef - is this ava...
- 5 months ago
Mmmhh, i looked at the lab to help you. Noticed it was a hard one. Tried what was in my mind for the xor-key and it was right. This key only has 2 chars. A number and a letter. Try searching for ^ in ghidra.
good luck :)
RobN
Bronze III
5 months agoSorted this now, I went on a tangent!
RobH
Bronze I
8 days agoHi Rob, I was wondering if you remembered enough about this to give me a hint? I feel like I'm checking everywhere for the hex beneath the zzz43...24cl portions, but I'm just not finding anything conclusive.
- RobN7 days ago
Bronze III
Hi RobH,
I'll check my notes later, see what I can find. I'll take another look at the lab too - looking at my answer I went the long way round to find it.
- RobN6 days ago
Bronze III
Hi Rob,
Unfortunately I wasn't able to find any notes for this lab but check what GusC wrote above, this should help you find it.