We added support for detecting executables ciphered with bitwise shift ciphers - ROR (shift right) and ROL (shift left) which was first reported from a sample from Mila's blog (contagiodump). Bitwise shifts are similar to multiple or division by 2's. This sample used a shift left of one position (rol 1) along with a 256byte XOR key.
Update: oledump.py Version 0.0.85
-
Fixing newlines in some plugins. oledump_V0_0_85.zip (http)MD5:
D972CE411B395EF77DBCE9A63059E8C1SHA256:
721C095F3126745A42720316A0B3AC1BCCB9DCDBBA9FF59F5FE...
17 hours ago