We added support for detecting executables ciphered with bitwise shift ciphers - ROR (shift right) and ROL (shift left) which was first reported from a sample from Mila's blog (contagiodump). Bitwise shifts are similar to multiple or division by 2's. This sample used a shift left of one position (rol 1) along with a 256byte XOR key.
Update: cs-parse-traffic.py Version 0.0.6
-
This is a bugfix version. cs-parse-traffic_V0_0_6.zip (http)MD5:
AED53E99D7BFF14EC45F573663A91780SHA256:
C73614FD69660C4D0E851414D86091E9E90DE9A92D58F9E6AC...
1 day ago