The base64 encoded EXE inside the crunchyroll sample expects the C2 to return a length and then bytecode to be executed @bartblaze
-
Show this thread
-
This is TinyLoader I believe
1 reply 0 retweets 1 likeShow this thread -
-
Maybe a bit of a stretch, the similarities throw me off a bit. Below is the section that brutes it's own xor key for the embedded codepic.twitter.com/ydpT2dPL7q
2 replies 1 retweet 4 likesShow this thread -
The decode concept is the same but code is pretty different. Decoded shellcode looks more like a meterpreter variant to me than TinyLoader.
2 replies 0 retweets 1 like -
Replying to @darienhuss @sysopfb and
E.g., in TinyLoader the XOR during key search happens directly to shellcode then reversed if wrong, in Crunchyroll it happens in a register.
2 replies 0 retweets 2 likes -
Interesting - I haven't looked at TinyLoader yet,
@sysopfb can you share the hash of that sample from your screenshot please? Thnx!1 reply 0 retweets 0 likes -
sure: 175661b3aba0195b1115af5286140f8251ed1299343687377becc5148ae903f3
1 reply 0 retweets 1 like
Awesome, thank you both!
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.